skip to content

Why is a weeks-long BGP peering session a better target for blind spoofed-segment injection than a short web connection?

level: juniorimportance: should knowfreq 42%

answer

  1. the attacker sends but never sees
  2. what names a connection uniquely
  3. how long the target stays reachable
  4. port 179 is published, addresses are too
  5. only the ephemeral port and position remain

basics

~20 s

Time and predictability. The peering session stays up for weeks, so thousands of spoofed guesses can be tried against it, and both router addresses plus TCP port 179 are public, leaving far less of the connection identity to guess.

solid answer

~50 s

An attacker who is off-path is blind: they can emit packets with a forged source address but never see the real ones, so every forged segment has to match the connection by guesswork. What must match is the four-tuple - both addresses and both ports - plus a sequence number the receiver will accept. A short HTTP connection frustrates all of that: it exists for a second or two and its client-side ephemeral port is random and unknown. A BGP peering session between two routers is the opposite. It is up for weeks, its destination port is the well-known 179, and the two router addresses are usually documented publicly, so only the local ephemeral port and the current sequence position remain unknown - and the attacker has weeks of wall-clock time to keep firing guesses at them.

go deeper

for a junior

Be ready to say what an off-path attacker cannot do - see the flow - and therefore what must be guessed: two addresses, two ports and a sequence value.

for a middle

Explain why a well-known destination port and publicly documented router addresses collapse most of the four-tuple, leaving the ephemeral port and the sequence position as the only real unknowns.

for a senior

Show you can rank your own long-lived flows by exposure: how long they stay up, how public their endpoints are, and what breaks downstream when one is torn down.

for a principal

Own the argument that session lifetime is itself an exposure, and be able to say when you would trade a control session's convenient permanence for authenticated segments or a shorter life.

## The position: blind and off-path An off-path attacker sits somewhere that can *emit* traffic toward the two endpoints of an existing TCP connection but cannot *observe* that connection. They can forge the source address on a packet they send. They cannot read a single byte the two real endpoints exchange. Everything a legitimate sender knows for free - which ports are in use, where the byte stream has reached - the blind attacker has to guess and can never confirm directly. That one asymmetry is what makes target selection the whole game. The attack is a brute-force search, so the attacker picks the flow where the search is smallest and the time available is longest. ## What has to match For a forged segment to be handed to an existing connection rather than dropped, it must: - carry the right source address and source port (the far endpoint of the session), - carry the right destination address and destination port (the near endpoint), - carry a sequence number the receiver considers acceptable. Those first four values are the four-tuple that names the connection. If any is wrong, the segment either lands on no connection at all or lands on the wrong one. ## Why a short connection is a bad target A browser fetching a page opens a connection whose client port was chosen from a large randomised range, and closes it seconds later. The attacker does not know that port, has no way to learn it from off-path, and even a correct guess arrives after the connection has gone. The search space is large and the deadline is immediate. ## Why a long-lived control session is a good one A peering session between two routers, or a replication link between two database servers in a fleet, inverts every one of those properties: - **Lifetime measured in weeks.** Spoofed guesses are cheap and independent; a session that stays up for a month lets the attacker send an enormous number of them. Nothing about the connection gets *harder* as time passes. - **A published destination port.** BGP listens on TCP 179. That half of the port pair is not a secret at all. - **Public endpoint addresses.** Router addresses and peering relationships are routinely documented in routing registries and public looking-glass services, so the two IP addresses are usually known rather than guessed. - **A predictable existence.** The attacker does not need to catch the session being created; it is simply always there. What is left unknown is the ephemeral port on the initiating side and the current sequence position in the stream. That is a much smaller search than the one a short connection presents, and it can be attacked continuously. ## Why the payoff is also better Target selection is not only about cost. A single successful injection into a web connection breaks one page load. A single successful injection into a peering session terminates it, which withdraws the routes learned over it and forces reconvergence across everything downstream. For an actor whose objective is disruption rather than a foothold, the long-lived session is both the cheapest target and the most valuable one. Nothing is installed and nothing is stolen; the whole operation is one accepted packet. A replication link across a server fleet shows the same shape from a different angle: it is long-lived, its port is fixed by the deployment, and dropping it stalls or desynchronises the followers. ## What actually reduces the exposure The properties the attacker exploited are the ones worth attacking back. Randomising the local ephemeral port range widens the part of the tuple that is genuinely secret. Authenticating the segments themselves removes the guessing game entirely, because a segment without a valid authentication value is discarded no matter how well the tuple and sequence were guessed. Requiring that segments arrive from an expected hop distance removes the off-path attacker's ability to reach the session at all. None of those depend on noticing the guesses; they change what a correct guess is worth. ## The claim to keep straight A long-lived session is not weaker because it is old. It is weaker because it gives an attacker who must brute-force a search both a smaller search and unlimited time to run it.

  • Does an off-path attacker learn anything from the fact that a session stays up?
    Only that their guesses have not landed yet. They see no responses to forged packets, because responses go to the spoofed address, not to them. That blindness is why the attack is a pure brute-force search rather than a feedback loop, and why a target with a small remaining search space is worth so much more than a large one.
  • A replication link inside one data centre has private addresses. Does that make it a poor target?
    It raises the bar for a purely external attacker, because forged packets must reach the endpoints and the addresses are not published. It does not help against an actor with a transit vantage or any presence that can emit toward those addresses. Private addressing narrows who can attempt the attack; it does not change the arithmetic for whoever can.
  • Why does a short-lived connection's randomised client port matter so much?
    It is the only part of the four-tuple the attacker cannot look up. A wide, unpredictable ephemeral range adds roughly sixteen bits of guessing on top of the sequence search, and the connection expires long before that many guesses can be sent. Narrow or predictable port ranges throw that protection away.

Guessing a combination lock is hopeless if the lock disappears after two seconds. The same lock left hanging on the same gate for a month, with three of its four dials already printed on the gate, is a different problem.

saying these in an interview costs you the question

  • Says the attacker can read the session to learn the ports
  • Claims a long session is safer because it is established
  • Thinks the attacker must complete a handshake first
  • Assumes public addresses are irrelevant to the attack
  • Treats session lifetime as unrelated to exposure

context