DDoS attacks on BGP sessions
DDoS or denial of access attack against BGP sessions is well known but not common in cyberspace. In June of last year, FIRST recorded 2 such cases where two of the organization’s BGP sessions were successfully attacked by a DDoS attack (TCP port 179) and both sessions were terminated. The IT security organization Shadowserver and the Shodan service have collected information about +300,000 BGP port 179 sessions that are at risk and could become a target for similar attacks. About 150 such BGP services exposed on the Internet have been found in Latvia. Simultaneous attacks on these services could lead to serious consequences and global “chaos on the Internet”.
Shadowserver unprotected BGP session information panel . Shadowserver notifications now also include two new free BGP session messages – available BGP service and open BGP service .