Glostarep

BGP ORIGIN Attribute Manipulation Is Quietly Reshaping Internet Routing

BGP ORIGIN Attribute Manipulation Is Quietly Reshaping Internet Routing

Quick Reads
  • Cloudflare research finds nearly 70% of BGP paths experience ORIGIN attribute rewrites
  • Transit providers rewrite ORIGIN to attract more traffic and boost revenue
  • The practice violates RFC 4271 standards but has become widespread globally
  • Six out of 16 Tier-1 networks are confirmed manipulators
  • Cloudflare is calling on the IETF to deprecate ORIGIN from route selection entirely
  • African internet operators relying on Tier-1 transit links are directly exposed to this traffic diversion

Cloudflare has uncovered a widespread and largely silent practice that is reshaping how internet traffic flows globally. According to new research published by the company, BGP ORIGIN attribute manipulation is occurring across nearly 70% of observed routing paths. Furthermore, the findings carry serious implications for internet infrastructure across Africa and Nigeria.

Border Gateway Protocol (BGP) is the de facto routing protocol of the internet. It determines how data travels between networks. One of its core components is the ORIGIN attribute, a mandatory field in every BGP announcement. This field signals how a route entered the system. The rules are clear: once an originating network sets it, no other router should change it. However, that rule is being broken, at scale.

How Cloudflare Ran the Experiment

Cloudflare’s research team announced prefixes with different ORIGIN values from all peering locations. They then withdrew those prefixes to trigger path hunting and reveal more routing paths. As a result, what they found was striking. Transit providers, especially large, top-tier ones, are systematically changing ORIGIN values from EGP or INCOMPLETE to the more preferred IGP value. By doing so, they make their routing paths appear more attractive to downstream networks. Consequently, traffic gets redirected through their links, generating more revenue in the process.

To gather this data, Cloudflare used the BGPKIT toolkit to parse routing updates from public BGP collectors at RIPE RIS and RouteViews. In addition, they pulled local BMP data directly from their own border routers. Together, these sources built a detailed picture of ORIGIN rewriting behavior across the global routing table.

The Scale Is Bigger Than Expected

This is not a minor technical footnote. Specifically, the data shows that 26% of the top 50 networks and 20% of the top 100 networks globally are manipulating the BGP ORIGIN attribute. Moreover, six out of 16 Tier-1 networks, the internet’s backbone providers, are confirmed participants. In IPv4 routing, ORIGIN rewriters gained 12 additional paths, an 18% increase. In IPv6, the gain was even sharper at 40%.

The practice was first publicly spotlighted at the RIPE 91 meeting by James Bensley. Subsequently, Celsa Sánchez presented a follow-up study at LACNIC 45, examining its impact across Latin America and the Caribbean. Now, Cloudflare’s global experiment brings hard numbers to a problem the network operations community has long acknowledged but quietly accepted.

What This Means for Nigeria and Africa

For Nigeria and the broader African tech ecosystem, this matters directly. Many Nigerian internet service providers and telecom operators depend on Tier-1 transit networks to route international traffic. Therefore, when transit providers manipulate BGP ORIGIN to divert paths, Nigerian ISPs may unknowingly send traffic through costlier or suboptimal routes, without any visibility into why. As Africa’s internet infrastructure continues to grow, and as local operators work to reduce dependence on expensive international transit, this kind of invisible manipulation could undermine those efforts.

Cloudflare’s position is equally clear on what should happen next. A now-expired Internet-Draft at the IETF had already proposed scrubbing the ORIGIN attribute from BGP path selection. Cloudflare now calls for that conversation to be revived. In their view, there is no valid technical reason for ORIGIN to influence routing decisions in the modern internet. Requiring all BGP implementations to set ORIGIN to IGP by default, or removing its role in path selection entirely, would level the playing field and eliminate the incentive for manipulation.

BGP ORIGIN attribute manipulation is not fringe behaviour. Instead, it is a systematic, revenue-driven tactic embedded in the fabric of global internet routing, and it is time the industry took it seriously.

Leave a Comment

Your email address will not be published. Required fields are marked *