Routing Attack
Pronunciation: ROW-ting uh-TAK
Definition
Routing Attack is an attack or weakness pattern that manipulates or disrupts network path selection to intercept, delay, redirect, isolate, or deny legitimate communications. Routing Attack must be evaluated through its prerequisites, entry point, affected asset or trust boundary, attacker capability, observable indicators, and possible financial or operational impact. Defenses against Routing Attack combine secure design, least privilege, validation, monitoring, rate or value limits, and tested containment and recovery procedures.
Overview
Routing attacks target the mechanisms that determine how traffic reaches its destination. Examples include route hijacking, malicious announcements, prefix leaks, DNS manipulation, peer attacks, and deliberate path changes within overlay or blockchain networks.
Consequences include interception, censorship, partition, degraded consensus, unavailable services, delayed transactions, and exposure of metadata. Encryption can protect content but does not ensure that traffic reaches the correct destination promptly or avoids observable adversarial paths.
Defenses include authenticated routing where supported, route filtering, diverse providers, path monitoring, secure name resolution, encrypted sessions, and failover testing. Applications should detect unexpected latency, regional isolation, peer concentration, and conflicting network views before making irreversible decisions.
Routing Attack is an attack or weakness pattern that manipulates or disrupts network path selection to intercept, delay, redirect, isolate, or deny legitimate communications. Routing security requires path integrity, diversity, monitoring, and safe degraded behavior because encrypted traffic can still be redirected, delayed, or isolated.
Assessment of Routing Attack should trace an attack or weakness pattern that manipulates or disrupts network path selection to intercept, delay, redirect, isolate, or deny legitimate communications from prerequisite and entry point through observable impact on the affected service. A theoretical weakness or scanner result involving attack, weakness pattern that manipulates, and disrupts network path selection to intercept should not be reported as exploitation without corroborating logs, transactions, or configuration evidence. Prevention, detection, containment, and recovery for the Routing attack path should be tested against the architecture associated with attack, weakness pattern that manipulates, and disrupts network path selection to intercept.
Retesting for Routing Attack should reproduce the Routing attack path involving attack, weakness pattern that manipulates, and disrupts network path selection to intercept, examine adjacent paths, and verify the conditions for safely returning the affected service to normal operation.
Key Takeaway
Routing security requires path integrity, diversity, monitoring, and safe degraded behavior because encrypted traffic can still be redirected, delayed, or isolated.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)