%% You should probably cite draft-ietf-opsec-bgp-security instead of this I-D. @techreport{jdurand-bgp-security-01, number = {draft-jdurand-bgp-security-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-jdurand-bgp-security/01/}, author = {Jerome Durand and Ivan Pepelnjak and Gert Döring}, title = {{BGP operations and security}}, pagetotal = 21, year = 2012, month = jun, day = 19, abstract = {BGP (Border Gateway Protocol) is the protocol used in the internet to exchange routing information between network domains. This protocol does not directly include mechanisms that control that routes exchanged conform to the various rules defined by the Internet community. This document intends to summarize most common existing rules and help network administrators applying simply coherent BGP policies. First it recalls mechanisms that administrators can use to protect the BGP sessions, with TTL and MD5. Then the document describes the prefix filters that can be used, how some of them can be automated, and where they apply in the BGP network. Afterwards, applicability of other methods including BGP route flap dampening, limiting maximum prefixes per peering, AS-path filtering and community scrubbing is analyzed.}, }