BGP (Border Gateway Protocol) & Autonomous System Numbers (ASN): How the Global Internet Routes Packets & Prevents Route Hijacks
A masterclass on the Border Gateway Protocol (BGP-4) that holds the global internet together. Explore Autonomous Systems (ASNs), settlement-free peering at IXPs, BGP route hijacking, RPKI ROA security validation, and Anycast routing architecture.
The internet is not a single monolithic network managed by a central governing authority. Instead, it is a vast federation of over 75,000 independently operated networks—known in telecommunications as Autonomous Systems (AS). The invisible protocol that binds these thousands of competitive corporate entities, universities, and sovereign states into a single unified global network is the Border Gateway Protocol (BGP).
Every time you load a webpage, initiate an API request, or run a speed test on WRLDU, BGP determines the exact sequence of router hops your data packets will follow across continents. Yet BGP was originally designed in 1989 on a foundational assumption of complete mutual trust. In this technical deep dive, we examine how BGP-4 calculates routing paths, why BGP route hijacking can take down global services in seconds, and how modern cryptographic security frameworks like RPKI (Resource Public Key Infrastructure) and Anycast routing protect the global internet.
1. What Is an Autonomous System (AS) and an ASN?
An Autonomous System (AS) is a distinct network or collection of IP address prefixes controlled by a single administrative entity (such as an ISP, a cloud hyper-scaler like Google or AWS, or a financial institution) that presents a clearly defined routing policy to the outside world.
To participate in global routing, every Autonomous System is assigned a globally unique Autonomous System Number (ASN) by regional internet registries (such as ARIN in North America, RIPE NCC in Europe, or APNIC in Asia-Pacific):
- 16-bit ASNs (Legacy): Ranging from 1 to 65535 (e.g., AS15169 for Google, AS13335 for Cloudflare, AS8075 for Microsoft).
- 32-bit ASNs (Modern standard): Introduced in RFC 4893 to prevent number exhaustion, expanding the pool to over 4 billion available ASNs (e.g., AS396982).
You can instantly look up your own ISP's real-time Autonomous System Number, announced prefix blocks, and routing status using the WRLDU IP & ASN Intelligence Tool.
2. How BGP-4 Works: Path-Vector Routing & Decision Algorithms
Unlike internal routing protocols like OSPF or IS-IS (which calculate the shortest geometric path using Dijkstra's algorithm inside a private network), BGP is a path-vector protocol designed for policy-based inter-domain routing.
The AS-PATH Attribute
When an Autonomous System announces an IP prefix to its neighbors, it prepends its own ASN to the AS-PATH attribute list. As the route propagates through upstream carriers, each network adds its ASN to the front of the list. A typical AS-PATH looks like this:
# Typical AS-PATH for a European user reaching Google (AS15169):
Prefix: 142.250.190.0/24
AS-PATH: 3356 (Lumen Tier-1) → 1299 (Arelion) → 15169 (Google)
The primary rule of BGP loop prevention is simple: If a router receives a route advertisement that already contains its own ASN in the AS-PATH, it discards the packet immediately, preventing catastrophic infinite routing loops.
The BGP Best-Path Selection Hierarchy
When a BGP router receives multiple competing routes to the same IP destination, it executes a rigorous step-by-step tie-breaking sequence:
- Highest Weight (Cisco proprietary): Local to the router.
- Highest LOCAL_PREF: Preferred outbound path chosen by network administrators.
- Locally Originated Routes: Routes injected by the router itself.
- Shortest AS-PATH: Routes with fewer intermediary Autonomous System hops.
- Lowest Origin Code: IGP is preferred over EGP/Incomplete.
- Lowest Multi-Exit Discriminator (MED): Preferred inbound entrance into a neighbor's network.
- eBGP over iBGP: External peering paths are preferred over internal paths.
- Lowest Interior Metric: Shortest IGP cost to the BGP next-hop.
3. Interconnection Economics: Transit vs. Peering at IXPs
How do networks physically and commercially connect to trade traffic?
| Interconnection Model | Commercial Relationship | Traffic Scope & Routing Impact |
|---|---|---|
| IP Transit | Paid customer-to-provider contract (e.g., paying Tier-1 carriers like Lumen, Telia, NTT). | Provides reachability to the entire global routing table (the "Default-Free Zone"). |
| Settlement-Free Peering | Zero-dollar mutual agreement between two peers with roughly equal traffic ratios. | Restricted strictly to bilateral customer traffic; traffic to third parties is not forwarded. |
| Internet Exchange Points (IXPs) | Shared switching fabric (e.g., DE-CIX Frankfurt, AMS-IX Amsterdam, Equinix Ashburn). | Allows hundreds of networks to peer directly over a single physical optical cross-connect. |
When your ISP establishes direct peering with major cloud edge platforms at regional IXPs, your packets travel directly without bouncing through expensive, congested transit backbones. This direct peering is what creates ultra-low ping on the WRLDU Speed Test.
4. The Peril of BGP Route Hijacking & Accidental Route Leaks
Because classic BGP accepts whatever routing announcement a peer sends without cryptographic proof of ownership, malicious actors or misconfigured routers can announce IP addresses they do not own—a vulnerability known as BGP Hijacking.
Infamous BGP Incidents in History
- The 2008 YouTube Outage: Pakistan Telecom attempted to block YouTube domestically by announcing a more-specific
/24prefix for YouTube's/22block. Because routers globally prioritize more-specific subnets (longest-prefix match), the bogus route leaked to upstream transit provider PCCW, blackholing YouTube worldwide for over two hours. - The 2018 Amazon Route53 Hijack: Attackers announced Amazon Route53 DNS IP space via eBGP, redirecting traffic meant for the MyEtherWallet web wallet to a phishing server and stealing millions in cryptocurrency.
- Major Cloud Route Leaks: Large regional ISPs accidentally leaking full internet routing tables through local BGP sessions, overloading edge routers and causing massive multi-continent brownouts.
5. Securing the Internet: RPKI & Route Origin Authorization (ROA)
To eliminate BGP hijacking once and for all, the telecommunications industry developed RPKI (Resource Public Key Infrastructure).
How RPKI Route Origin Validation (ROV) Works
1. The legitimate owner of an IP block signs a cryptographic digital certificate called a Route Origin Authorization (ROA) using their Regional Internet Registry (RIR) private key.
2. The ROA explicitly states: "IP Prefix 198.51.100.0/24 is authorized to be originated exclusively by ASN 64496 with a maximum length of /24."
3. Border routers across the world download validated ROA caches and tag every incoming BGP announcement as Valid, Invalid, or NotFound. Any rogue announcement that fails signature validation is immediately dropped!
6. Anycast Architecture: How 1.1.1.1 and 8.8.8.8 Exist Everywhere
In traditional Unicast routing, an IP address exists on exactly one physical server in one physical datacenter. If that server is in Virginia, every user globally must route to Virginia.
In BGP Anycast, dozens or hundreds of datacenters across the globe announce the exact same IP address prefix and ASN simultaneously into the global BGP table:
- When a user in Tokyo queries
1.1.1.1or8.8.8.8, local Japanese ISPs select the shortest BGP AS-PATH to the Tokyo edge node (ping: 1.8 ms). - When a user in Frankfurt queries the same IP, European ISPs route them to Frankfurt (ping: 2.1 ms).
- If an edge datacenter goes offline, BGP withdraws the prefix route, automatically failing over surrounding traffic to the nearest surviving cluster within seconds with zero downtime!
You can benchmark DNS Anycast resolution speed and detect the closest responding Anycast node using the WRLDU DNS Speed Benchmark.
Frequently Asked Questions (FAQ)
How many routes exist in the global BGP routing table?
As of 2026, the global IPv4 routing table contains approximately 950,000 routes, while the IPv6 routing table exceeds 210,000 prefixes. Enterprise core routers utilize high-speed Ternary Content-Addressable Memory (TCAM) to perform line-rate lookups across these millions of routing entries.
Can my home router speak BGP?
Home consumer routers use simple Default Gateways (0.0.0.0/0) pointing to your ISP's upstream Bras/BNG gateway. However, prosumer and small business routers running OpenWrt, VyOS, Mikrotik RouterOS, or pfSense can easily establish BGP peerings using routing daemons like BIRD or FRRouting (FRR).
Why does my IP address show a different location on different speed test websites?
IP geolocation is maintained by independent commercial database vendors (such as MaxMind, IPinfo, and DB-IP) that map BGP prefix announcements and latency triangulation. If an ISP shifts IP ranges between regional pools, it can take several days for geolocation databases to update.
Check your verified IP routing hops, ASN details, and line stability today on WRLDU Network Speed Test.
