RPKI Validation & ASPA RFC 9234 Route-Leak Detection
Route origin validation is no longer a nice-to-have. Major Tier-1 transit providers now drop RPKI-invalid prefixes by default, MANRS auditors require coverage scorecards, and route leaks remain the single most common cause of large-scale outages. RoutePulse delivers full RPKI validation built on ~830,000 Validated ROA Payloads (VRPs) ingested from Cloudflare or a self-hosted Routinator validator, refreshed every 30 minutes, with three-state classification (Valid / Invalid / NotFound) applied uniformly across every prefix the platform observes — RIB, flow telemetry, anomaly detector input, blackhole gate.
Since v4.20, RoutePulse goes beyond pure origin validation with a dedicated /rpki/aspa sub-page implementing ASPA — Autonomous System Provider Authorization (RFC 9234). ASPA gives each ASN a cryptographically-signed list of its authorized upstream providers; RoutePulse cross-checks every AS_PATH against the ASPA database (~1,200 provider pairs) and flags route leaks where a non-authorized AS appears in the upstream position. This is the first deployment-ready countermeasure for the entire class of “BGP optimizer mistake” and “fat-finger redistribute” incidents that have caused outages for Cloudflare, Facebook, and Rogers. Combined with origin validation, ROA lifecycle tracking, and expiring-ROA countdown badges, RoutePulse provides a complete RFC 6480 + RFC 8210 + RFC 9234 routing security stack.
Continuous route origin validation at scale
~830K VRPs ingested from Cloudflare’s pre-aggregated feed or a private Routinator instance via RTR (RFC 8210). Every prefix in the live RIB, every flow record, and every anomaly under review is classified Valid (matching ROA confirming the announced origin), Invalid (conflicting ROA — potential hijack), or NotFound (no ROA exists). The invalid prefix list sorts by origin AS with one-click drill-down to the conflicting ROA, the active announcement, and the anomaly-detector confidence delta the invalid status contributes.
ASPA route-leak detection (RFC 9234)
The dedicated /rpki/aspa sub-page presents the provider-authorization graph: per-ASN list of declared upstreams, cross-AS_PATH compliance checks against every observed announcement, and an audit log of any path containing an unauthorized provider position. ASPA catches the route-leak class that origin validation cannot — your prefix announced legitimately by you, then re-announced upstream by an AS that has no authorization to be your provider. This is the cryptographic proof regulators (and post-incident-review committees) ask for after every “BGP optimizer” event.
ROA lifecycle & expiry countdown
A VRP diff engine compares snapshots across refresh cycles and emits NEW / REMOVED / MODIFIED badges on every change — operators see in real time when their ROAs gain coverage, lose it, or get re-keyed by the RIR. Expiring-ROA countdown badges turn amber 30 days out and red 7 days out, surfacing certificate renewal before coverage lapses. ROA optimizer suggestions identify prefixes that would benefit from a tighter MaxLen or a new ROA where none exists.
Platform-wide RPKI integration
RPKI status badges appear on every prefix and every AS reference across all 100+ pages — RIB browser, AS Explorer, flow analyzer, incident dossiers, peering health, external visibility. Anomaly detection confidence scoring escalates RPKI-invalid prefixes to higher severity automatically, and the 8-gate Conviction Engine treats RPKI status as an input feature for blackhole eligibility. Per-AS RPKI coverage scorecards calculate the percentage of originated prefixes with valid ROAs, giving operators a single number to drive their MANRS programme.
Key Capabilities
- ~830,000 Validated ROA Payloads loaded from Cloudflare or self-hosted Routinator via RTR (RFC 8210); 30-minute auto-refresh cycle
- Three-state validation per prefix: Valid (matching ROA), Invalid (conflicting ROA — hijack candidate), NotFound (no ROA exists)
- ASPA RFC 9234 cryptographic route-leak detection live at
/rpki/aspasub-page (v4.20+) — ~1,200 ASPA provider pairs - AS_PATH cross-check against ASPA database catches unauthorized-upstream insertions (BGP-optimizer leaks, fat-finger redistribute)
- Per-AS RPKI coverage scorecard — percentage of originated prefixes with valid ROAs, sortable, drillable
- Invalid prefix list with origin-AS sort + one-click drill into conflicting ROA, active announcement, and detector confidence delta
- VRP diff engine emitting NEW / REMOVED / MODIFIED colored badges on every refresh cycle
- ROA expiry countdown — amber at 30 days, red at 7 days — proactive certificate renewal
- ROA optimizer surface — prefixes where a tighter MaxLen or new ROA would improve posture
- Cross-reference with IRR route objects (RIPE/RADB/APNIC/ARIN/AFRINIC) for RPKI vs IRR consistency analysis
- RPKI badges woven across all 100+ pages; anomaly-detector confidence escalates RPKI-invalid prefixes automatically
- 8-gate Conviction Engine v2 consumes RPKI status as a blackhole-eligibility feature alongside SPRT, Thompson Sampling, Conformal Prediction
- MANRS-ready evidence: every claim cited to a specific VRP refresh timestamp, ROA, or ASPA pair (NIS2 / DORA-compatible)
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →