Uploaded November 2025 | Updated September 2026, 1 week ago
Cloudflare runs a vast global network with complicated peering relationships that present a unique complexity for detecting route leaks. AS-to-AS relationships alone are insufficient to distinguish a legitimate BGP prefix announcement from a leaked announcement. Instead, each prefix needs to be precisely evaluated at the prefix level for path validity.
In this presentation, we will show you how we built prefix-level route leak detection at Cloudflare with a highly scalable pipeline. We will share our methods that other networks might find useful in capturing their own route leaks, especially to those who operate BGP Anycast networks. In addition to this, we will discuss our progress toward BGP ASPA (Autonomous System Provider Authorization) compliance, Cloudflare’s strategy to leverage RFC9234 Only-to-Customer (OTC) attribute, and how they fit alongside our prefix-level BGP route leak detection as preventative measures.
Bryton Herdes: Bryton Herdes is a Principal Network Engineer at Cloudflare with a role split between both the edge and backbone global network. Prior to Cloudflare, he worked primarily in the ISP networking space, helping bring fiber and wireless connectivity to rural parts of the United States. Bryton mostly spends his time at Cloudflare working on network design, implementation, and fighting fires.
Cloudflare runs a vast global network with complicated peering relationships that present a unique complexity for detecting route leaks. AS-to-AS relationships alone are insufficient to distinguish a legitimate BGP prefix announcement from a leaked announcement. Instead, each prefix needs to be precisely evaluated at the prefix level for path validity.
In this presentation, we will show you how we built prefix-level route leak detection at Cloudflare with a highly scalable pipeline. We will share our methods that other networks might find useful in capturing their own route leaks, especially to those who operate BGP Anycast networks. In addition to this, we will discuss our progress toward BGP ASPA (Autonomous System Provider Authorization) compliance, Cloudflare’s strategy to leverage RFC9234 Only-to-Customer (OTC) attribute, and how they fit alongside our prefix-level BGP route leak detection as preventative measures.
Bryton Herdes: Bryton Herdes is a Principal Network Engineer at Cloudflare with a role split between both the edge and backbone global network. Prior to Cloudflare, he worked primarily in the ISP networking space, helping bring fiber and wireless connectivity to rural parts of the United States. Bryton mostly spends his time at Cloudflare working on network design, implementation, and fighting fires.





