{
  "node_id": "bgp-security-ddos-mitigation",
  "title": "Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2019-12-31",
  "bluf": "This special publication on Resilient Interdomain Traffic Exchange (RITE) includes initial guidance on securing the interdomain routing control traffic, preventing IP address spoofing, and certain aspects of DoS/DDoS detection and mitigation. The primary focus of these recommendations are the points of interconnection between enterprise networks, or hosted service providers, and the public internet. The primary audience includes information security officers and managers of federal enterprise networks. The guidance also applies to the network services of hosting providers and internet service providers (ISPs) when they are used to support federal IT systems.\n\nThe core recommendations reduce the risk of accidental and malicious attacks in the routing control plane, and they help detect and prevent IP address spoofing and resulting DoS/DDoS attacks. Technologies recommended for securing interdomain routing control traffic include Resource Public Key Infrastructure (RPKI), BGP origin validation (BGP-OV), and prefix filtering. Additionally, technologies recommended for mitigating DoS/DDoS attacks include prevention of IP address spoofing using source address validation (SAV) with access control lists (ACLs) and unicast Reverse Path Forwarding (uRPF). Other technologies such as remotely triggered black hole (RTBH) filtering, flow specification (Flowspec), and response rate limiting (RRL) are also recommended as part of the overall security mechanisms.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-1800-14-bgp-rov",
    "nist-cybersecurity-framework-2-0",
    "nist-sp-800-53-r5",
    "nist-sp-800-207",
    "cisa-cross-sector-cybersecurity-goals"
  ],
  "primary_citations_count": 7
}