What problem does it solve?
Organizations cannot tell whether their internet routes are actually protected against BGP prefix hijacking and route leaks until someone tests the defenses. This Skill provides a controlled, lab-based methodology to simulate hijack attacks, verify RPKI route origin validation, and confirm that BGP monitoring tools detect unauthorized announcements before a real attacker does.
Core Features & Use Cases
- Isolated Lab Simulation: Builds Containerlab topologies with FRRouting routers to safely simulate more-specific prefix hijacks, exact-origin hijacks, and route leaks without touching production internet routing.
- RPKI Validation Testing: Configures Routinator and FRR route-maps to verify that Route Origin Authorizations and ROV policies actually block invalid announcements, including edge cases like loose ROA max-lengths.
- Monitoring & Detection: Deploys BGPalerter, pybgpstream, and RIPEstat queries to detect and analyze unauthorized route announcements in real time and historically.
- Use Case: A cloud hosting company wants to confirm its RPKI deployment protects its customer prefixes. The Skill simulates a /25 more-specific hijack and an origin hijack in a lab, confirms ROV blocks them, identifies an unprotected prefix with no ROA, and produces a remediation report.
Quick Start
Ask the AI to build a Containerlab BGP lab and simulate a prefix hijack against AS65001's 10.0.0.0/24 to test whether RPKI validation blocks the attack.