BGP exchanges reachability information in the form of prefixes, which are usually originated by a single Autonomous System (AS). If multiple ASes originate the same prefix, this is referred to as a Multiple Origin ASes (MOAS) prefix. One reason for MOAS prefixes are BGP prefix hijacks, which are mostly short-lived and have been studied extensively in the past years. In contrast to short-lived MOAS, long-lived MOAS have remained largely understudied. In this paper, we focus on long-lived MOAS prefixes and perform an in-depth study over six years. We identify around 24k long-lived MOAS prefixes in IPv4 and 1.4k in IPv6 being announced in January 2023. By analyzing the RPKI status we find that more than 40% of MOAS prefixes have all origins registered correctly, with only a minority of MOAS having invalid origins. Moreover, we find that the most prominent CIDR size of MOAS prefixes is /24 for IPv4 and /48 for IPv6, suggesting their use for fine-grained traffic steering. We attribute a considerable number of MOAS prefixes to mergers and acquisitions of companies. Additionally, more than 90% of MOAS prefixes are originated by two origin ASes, with the majority of detected origin AS relations being customer-provider. Finally, we identify that the majority of MOAS users are IT companies, and just 0.9% of IPv4 MOAS and 6.3% of IPv6 MOAS prefixes are used for anycast.
翻译:BGP以前缀形式交换可达性信息,这些前缀通常由单个自治系统(AS)发起。若多个AS发起相同前缀,则称为多源AS(MOAS)前缀。MOAS前缀的成因之一是BGP前缀劫持,这类劫持大多短暂存在,过去几年已得到广泛研究。与短期MOAS相比,长期存在的MOAS仍缺乏深入探讨。本文聚焦长期MOAS前缀,开展为期六年的深度研究。我们识别出2023年1月宣告的约2.4万个IPv4长期MOAS前缀和1400个IPv6长期MOAS前缀。通过分析RPKI状态发现,超过40%的MOAS前缀所有源均已正确注册,仅少数MOAS存在无效源。此外,MOAS前缀最突出的CIDR大小为IPv4的/24和IPv6的/48,表明其用于精细流量引导。我们将大量MOAS前缀归因于企业并购。同时,超过90%的MOAS前缀由两个源AS发起,且检测到的源AS关系中大多数为客户-提供商关系。最后,我们识别出多数MOAS用户为IT企业,仅0.9%的IPv4 MOAS和6.3%的IPv6 MOAS前缀用于任播。