The Silent War for Traffic: Why the BGP ORIGIN Attribute is Broken and Should Be Deprecated

The Border Gateway Protocol (BGP) acts as the central nervous system of the Internet. As the de facto inter-domain routing protocol, it governs how traffic moves across the vast, interconnected mesh of Autonomous Systems (ASes) that comprise our global network. For the system to function, BGP relies on a series of path attributes—metadata attached to routing announcements that allow networks to signal their preferences and constraints. Among these is the "ORIGIN" attribute, a mandatory piece of data meant to identify the source and nature of a routing prefix.

However, recent investigations conducted by Cloudflare, supported by industry discussions at RIPE 91 and LACNIC 45, have uncovered a troubling reality: the ORIGIN attribute is no longer a source of truth. Instead, it has become a weapon in a subtle, revenue-driven arms race. Roughly 70% of observed BGP paths are currently carrying an ORIGIN value different from the one originally set by the source network. This systemic manipulation is not a technical glitch; it is a calculated operational strategy, and it is time for the Internet engineering community to consider whether the ORIGIN attribute has outlived its usefulness.

A Legacy Mechanism in a Modern Landscape

To understand the scope of the problem, one must first understand what the ORIGIN attribute was intended to be. Historically, ORIGIN was designed to indicate the "how" of a route’s injection into the BGP table. It is not to be confused with the origin AS, which identifies which network announced the route. The attribute allows for three specific, standardized values:

  • (0) IGP: Signifying the route is interior to the originating AS.
  • (1) EGP: A relic of the obsolete Exterior Gateway Protocol, now largely defunct.
  • (2) INCOMPLETE: Denoting that the route was learned via an unknown or external source.

In the modern BGP path selection process, the ORIGIN attribute acts as a tie-breaker. When a router receives multiple paths for the same prefix that share identical "Local Preference" and "AS_PATH" lengths, the algorithm defaults to the path with the "lowest" ORIGIN value (IGP being the most preferred, followed by EGP, and finally INCOMPLETE).

While 89.8% of globally observed routes are marked as IGP, the remaining 10%—the EGP and INCOMPLETE routes—are where the trouble begins. Because this attribute is evaluated early in the decision-making process, it presents an irresistible lever for transit providers. By artificially upgrading an INCOMPLETE or EGP route to IGP, a provider can effectively "nudge" traffic toward their own network, ensuring their path is selected over a competitor’s, even if the actual topological cost is identical.

The Revenue-Driven Arms Race: A Chronology of Manipulation

The manipulation of the ORIGIN attribute is not a new phenomenon, but it has largely been an "open secret" among network operators. For years, the practice was silently accepted as an inevitable byproduct of competitive peering dynamics. However, the veil was lifted significantly during the RIPE 91 meeting, where James Bensley presented findings that brought the scale of this behavior into the public spotlight.

Following this, a presentation by Celsa Sánchez at LACNIC 45 provided a deep dive into how this behavior manifests within the Latin American and Caribbean regions. These disclosures have done more than just inform the public; they have fundamentally shifted the incentive structure. Once a major provider begins rewriting attributes to gain a traffic advantage, competitors are forced to follow suit to "level the playing field." What began as a technical non-compliance with RFC 4271—which explicitly states that the ORIGIN attribute "SHOULD NOT be changed by any other speaker"—has morphed into a standardized, competitive tactic.

This cycle of non-compliance has reached a point where the community has begun to view the attribute as fundamentally broken. The existence of an expired Internet-Draft, which once proposed the total deprecation of the ORIGIN attribute, serves as a testament to the fact that the industry has been aware of this decay for years.

Investigative Methodology: Mapping the Manipulation

To quantify the extent of this manipulation, we conducted a rigorous experiment using Cloudflare’s Anycast network. We announced three IPv4 and three IPv6 prefixes, each assigned a specific, controlled ORIGIN value (IGP, EGP, and INCOMPLETE) across all our global peering locations.

By withdrawing these prefixes, we triggered the "path hunting" process—a phase where BGP routers seek alternative paths after a primary route is removed. This allowed us to observe the propagation behavior and, crucially, to identify which networks were rewriting the ORIGIN attribute during the path propagation phase. We parsed the update messages using the BGPKIT toolkit against the MRT dumps provided by RIPE RIS and RouteViews, while also supplementing our findings with internal BMP data collected from our own border routers.

BGP ORIGIN attribute manipulation and its impact on the Internet

The results were startling. By isolating "two-hop" AS paths—paths where we announced the route directly to a peer, which then propagated it further—we could definitively attribute ORIGIN changes to specific transit providers.

Key Findings in IPv4 and IPv6

In our IPv4 testing, we analyzed 352 direct peers. The data revealed that while the majority of peers preserved the integrity of the ORIGIN attribute, a significant minority were not just rewriting values to IGP, but were actively manipulating them to EGP or INCOMPLETE to explicitly deprioritize certain routes.

Our investigation into IPv6 revealed a similar trend, though with a fascinating, inconsistent twist: several direct peers exhibited different manipulation behaviors depending on the address family. This implies that many network operators are managing their routing policies with a granular, often disjointed, approach to IPv4 and IPv6, treating them as separate operational silos rather than a cohesive network strategy.

The Tier-1 Hierarchy and the Impact on Traffic

Perhaps the most significant finding from our study is the concentration of this behavior within the upper echelons of the Internet hierarchy. When we applied our analysis to Tier-1 ASes—the backbone providers of the Internet—we found that six out of 16 Tier-1 networks were actively manipulating the ORIGIN value to IGP.

When an AS at the top of the hierarchy changes an ORIGIN value, the downstream effects are immense. Using CAIDA’s AS Rank as a proxy for network influence, we found that 20.3% of the ASes engaged in rewriting ORIGIN fall within the top-50 of the global AS hierarchy.

The economic implications are equally significant. In our experimental data, we observed that resetting the ORIGIN to IGP secured an 18% increase in path selection for IPv4 and a staggering 40% increase for IPv6. These "extra" paths are not being chosen because they are faster, more stable, or more secure; they are chosen simply because a transit provider decided to flip a bit in a header to capture more traffic and, by extension, more peering revenue. This is a clear demonstration that route selection, once a matter of technical efficiency, has become a distorted marketplace where the loudest attribute wins.

Implications: A Call for Deprecation

The current state of the ORIGIN attribute creates a "tragedy of the commons." Every time an AS rewrites an ORIGIN value, they marginally degrade the utility of the attribute for everyone else. We have reached a tipping point where the ORIGIN attribute is no longer providing useful information about the source of a route; instead, it is providing information about the commercial intent of the transit providers handling that route.

Given the widespread, intentional misuse of the ORIGIN attribute, we argue that it is time to move toward its deprecation. We recognize that removing a mandatory attribute from a protocol as sensitive as BGP is a monumental task that cannot happen overnight. However, the status quo is indefensible.

The Path Forward

We propose a two-pronged approach to the community and the IETF:

  1. Immediate Normalization: We should require vendor implementations to set the ORIGIN attribute as "IGP" for all routes, both received and advertised. Since the vast majority of the Internet is already using IGP, this would effectively neutralize the attribute as a meaningful differentiator in path selection.
  2. Reviving the Scrubbing Draft: We must revisit the expired "Scrubbing BGP ORIGIN Attribute" draft. By standardizing the "scrubbing" of this attribute at the network boundary, we can prevent transit providers from imposing their commercial biases on the routing tables of their peers.

The Internet is a collaborative endeavor, but it is currently hampered by a routing protocol that incentivizes dishonest signaling. By deprecating the ORIGIN attribute, we can restore the integrity of BGP path selection, ensuring that traffic follows the most efficient path—not the one with the most manipulated metadata. The era of the ORIGIN attribute should come to an end; the Internet will be faster, fairer, and more robust for it.