# Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating

DevFeed: [Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating](<https://devfeed.tech/articles/beyond-origin-validation-four-classes-of-routing-attack-nobody-is-validating-11442.md>)

Original publisher: [Read original article](<https://labs.ripe.net/author/antonio-prado/beyond-origin-validation-four-classes-of-routing-attack-nobody-is-validating/>)

Author: Antonio Prado

Published: 2026-07-21T12:33:47Z

Content type: article

Language: en

Sources: [RIPE Labs](<https://devfeed.tech/sources/ripe-labs.md>)

Topics: [BGP](<https://devfeed.tech/topics/bgp.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Routing Security](<https://devfeed.tech/topics/routing-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [bgp](<https://devfeed.tech/tags/bgp.md>), [internet-attacks](<https://devfeed.tech/tags/internet-attacks.md>), [operational](<https://devfeed.tech/tags/operational.md>), [routing-security](<https://devfeed.tech/tags/routing-security.md>), [rpki](<https://devfeed.tech/tags/rpki.md>), [security](<https://devfeed.tech/tags/security.md>), [validation](<https://devfeed.tech/tags/validation.md>)

## AI overview

The article argues that RPKI and cryptographic origin validation do not cover every BGP attack. It describes a malformed Prefix-SID incident that caused widespread updates and session resets, then presents a taxonomy of four macro-categories and eight micro-categories for routing attacks and their operational defences.

## Source excerpt

RPKI has made real progress against prefix hijacking. But when you map every known class of BGP attack against the defences that exist, four of them turn out to sit entirely outside cryptographic validation: handled with local filters, static thresholds and reactive response.