Skip to main content
Goline It Services Logo

News

  • GOLINE SA is excited to announce a new partnership with NetApp, a global leader in cloud data services and storage solutions. This collaboration aims to help organizations modernize their IT infrastructure, streamline data management, and enhance performance across cloud and hybrid environments. Modern Data Solutions for Businesses Through this partnership, GOLINE integrates advanced data management solutions, enabling businesses to securely store, manage, and access critical information across cloud, on-premises, or hybrid setups. Clients can benefit from: Flexible and scalable storage solutions to meet growing data needs Simplified management of cloud and on-premises environments Enterprise-grade security for sensitive and mission-critical data...
  • GOLINE SA is proud to announce a new strategic partnership with Omnissa, a global leader in digital workspace platforms and Horizon Cloud Service solutions. This collaboration marks a significant step forward in helping organizations embrace secure, flexible, and high-performance work environments. Why Choose Omnissa for Your Business? The platform enables virtual desktops, applications, and unified endpoint management. Organizations can deploy scalable workspaces across cloud, hybrid, or on-premises setups. Key benefits include: Easy access to desktops and apps on any device Centralized management for Windows, macOS, iOS, Android, and ChromeOS Strong security with access controls and multi-factor authentication Automated scaling to...
  • Goline is proud to announce a strategic partnership with Cloudflare, the world leader in web performance and security solutions. This collaboration aims to provide goline.ch customers with state-of-the-art protection against cyber threats while delivering lightning-fast website performance. Through this partnership, Goline integrates Cloudflare’s advanced services, including DDoS protection, CDN caching, DNS security, and edge computing, allowing businesses to secure and optimize their websites effortlessly. Users will benefit from improved page load speed, enhanced reliability, and robust defense against malicious attacks. This partnership with Cloudflare enables goline to offer unmatched security and performance solutions to clients. By leveraging Cloudflare’s cutting-edge technology,...

Back to RoutePulse Overview

RoutePulse — RPKI Validation & ASPA RFC 9234 Route-Leak Detection

RPKI Validation & ASPA RFC 9234 Route-Leak Detection

Route origin validation is no longer a nice-to-have. Major Tier-1 transit providers now drop RPKI-invalid prefixes by default, MANRS auditors require coverage scorecards, and route leaks remain the single most common cause of large-scale outages. RoutePulse delivers full RPKI validation built on ~830,000 Validated ROA Payloads (VRPs) ingested from Cloudflare or a self-hosted Routinator validator, refreshed every 30 minutes, with three-state classification (Valid / Invalid / NotFound) applied uniformly across every prefix the platform observes — RIB, flow telemetry, anomaly detector input, blackhole gate.

Since v4.20, RoutePulse goes beyond pure origin validation with a dedicated /rpki/aspa sub-page implementing ASPA — Autonomous System Provider Authorization (RFC 9234). ASPA gives each ASN a cryptographically-signed list of its authorized upstream providers; RoutePulse cross-checks every AS_PATH against the ASPA database (~1,200 provider pairs) and flags route leaks where a non-authorized AS appears in the upstream position. This is the first deployment-ready countermeasure for the entire class of “BGP optimizer mistake” and “fat-finger redistribute” incidents that have caused outages for Cloudflare, Facebook, and Rogers. Combined with origin validation, ROA lifecycle tracking, and expiring-ROA countdown badges, RoutePulse provides a complete RFC 6480 + RFC 8210 + RFC 9234 routing security stack.

830K
VRPs Loaded
30 min
Refresh Cycle
1,200
ASPA Pairs
9234
ASPA RFC Live

Continuous route origin validation at scale

~830K VRPs ingested from Cloudflare’s pre-aggregated feed or a private Routinator instance via RTR (RFC 8210). Every prefix in the live RIB, every flow record, and every anomaly under review is classified Valid (matching ROA confirming the announced origin), Invalid (conflicting ROA — potential hijack), or NotFound (no ROA exists). The invalid prefix list sorts by origin AS with one-click drill-down to the conflicting ROA, the active announcement, and the anomaly-detector confidence delta the invalid status contributes.

ASPA route-leak detection (RFC 9234)

The dedicated /rpki/aspa sub-page presents the provider-authorization graph: per-ASN list of declared upstreams, cross-AS_PATH compliance checks against every observed announcement, and an audit log of any path containing an unauthorized provider position. ASPA catches the route-leak class that origin validation cannot — your prefix announced legitimately by you, then re-announced upstream by an AS that has no authorization to be your provider. This is the cryptographic proof regulators (and post-incident-review committees) ask for after every “BGP optimizer” event.

ROA lifecycle & expiry countdown

A VRP diff engine compares snapshots across refresh cycles and emits NEW / REMOVED / MODIFIED badges on every change — operators see in real time when their ROAs gain coverage, lose it, or get re-keyed by the RIR. Expiring-ROA countdown badges turn amber 30 days out and red 7 days out, surfacing certificate renewal before coverage lapses. ROA optimizer suggestions identify prefixes that would benefit from a tighter MaxLen or a new ROA where none exists.

Platform-wide RPKI integration

RPKI status badges appear on every prefix and every AS reference across all 100+ pages — RIB browser, AS Explorer, flow analyzer, incident dossiers, peering health, external visibility. Anomaly detection confidence scoring escalates RPKI-invalid prefixes to higher severity automatically, and the 8-gate Conviction Engine treats RPKI status as an input feature for blackhole eligibility. Per-AS RPKI coverage scorecards calculate the percentage of originated prefixes with valid ROAs, giving operators a single number to drive their MANRS programme.

Key Capabilities

  • ~830,000 Validated ROA Payloads loaded from Cloudflare or self-hosted Routinator via RTR (RFC 8210); 30-minute auto-refresh cycle
  • Three-state validation per prefix: Valid (matching ROA), Invalid (conflicting ROA — hijack candidate), NotFound (no ROA exists)
  • ASPA RFC 9234 cryptographic route-leak detection live at /rpki/aspa sub-page (v4.20+) — ~1,200 ASPA provider pairs
  • AS_PATH cross-check against ASPA database catches unauthorized-upstream insertions (BGP-optimizer leaks, fat-finger redistribute)
  • Per-AS RPKI coverage scorecard — percentage of originated prefixes with valid ROAs, sortable, drillable
  • Invalid prefix list with origin-AS sort + one-click drill into conflicting ROA, active announcement, and detector confidence delta
  • VRP diff engine emitting NEW / REMOVED / MODIFIED colored badges on every refresh cycle
  • ROA expiry countdown — amber at 30 days, red at 7 days — proactive certificate renewal
  • ROA optimizer surface — prefixes where a tighter MaxLen or new ROA would improve posture
  • Cross-reference with IRR route objects (RIPE/RADB/APNIC/ARIN/AFRINIC) for RPKI vs IRR consistency analysis
  • RPKI badges woven across all 100+ pages; anomaly-detector confidence escalates RPKI-invalid prefixes automatically
  • 8-gate Conviction Engine v2 consumes RPKI status as a blackhole-eligibility feature alongside SPRT, Thompson Sampling, Conformal Prediction
  • MANRS-ready evidence: every claim cited to a specific VRP refresh timestamp, ROA, or ASPA pair (NIS2 / DORA-compatible)

Engineered and operated by the GOLINE SOC & Network Engineering team.

Explore all RoutePulse features →
69 / 100 SEO Score