Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

The Mystery of AS8003 (...it come alive within the final three minutes of the Trump administration...)
Kentik ^ | APRIL 24, 2021 | by Doug Madory Director of Internet Analysis

Posted on 04/24/2021 7:32:22 PM PDT by narses

On January 20, 2021, a great mystery appeared in the internet’s global routing table. An entity that hadn’t been heard from in over a decade began announcing large swaths of formerly unused IPv4 address space belonging to the U.S. Department of Defense. Registered as GRS-DoD, AS8003 began announcing 11.0.0.0/8 among other large DoD IPv4 ranges.

According to data available from University of Oregon’s Routeviews project, one of the very first BGP messages from AS8003 to the internet was:

TIME: 01/20/21 16:57:35 TYPE: BGP4MP/MESSAGE/Update FROM: 62.115.128.183 AS1299 TO: 128.223.51.15 AS6447 ORIGIN: IGP ASPATH: 1299 6939 6939 8003 NEXT_HOP: 62.115.128.183 ANNOUNCE 11.0.0.0/8 The message above has a timestamp of 16:57 UTC (11:57am ET) on January 20, 2021, moments after the swearing in of Joe Biden as the President of the United States and minutes before the statutory end of the administration of Donald Trump at noon Eastern time.

The questions that started to surface included: Who is AS8003? Why are they announcing huge amounts of IPv4 space belonging to the U.S. Department of Defense? And perhaps most interestingly, why did it come alive within the final three minutes of the Trump administration?

By late January, AS8003 was announcing about 56 million IPv4 addresses, making it the sixth largest AS in the IPv4 global routing table by originated address space. By mid-April, AS8003 dramatically increased the amount of formerly unused DoD address space that it announced to 175 million unique addresses.

Following the increase, AS8003 became, far and away, the largest AS in the history of the internet as measured by originated IPv4 space. By comparison, AS8003 now announces 61 million more IP addresses than the now-second biggest AS in the world, China Telecom, and over 100 million more addresses than Comcast, the largest residential internet provider in the U.S.

In fact, as of April 20, 2021, AS8003 is announcing so much IPv4 space that 5.7% of the entire IPv4 global routing table is presently originated by AS8003. In other words, more than one out of every 20 IPv4 addresses is presently originated by an entity that didn’t even appear in the routing table at the beginning of the year.

A valuable asset

Decades ago, the U.S. Department of Defense was allocated numerous massive ranges of IPv4 address space - after all, the internet was conceived as a Defense Dept project. Over the years, only a portion of that address space was ever utilized (i.e. announced by the DoD on the internet). As the internet grew, the pool of available IPv4 dwindled until a private market emerged to facilitate the sale of what was no longer just a simple router setting, but an increasingly precious commodity.

Even as other nations began purchasing IPv4 as a strategic investment, the DoD sat on much of their unused supply of address space. In 2019, Members of Congress attempted to force the sale of all of the DoD’s IPv4 address space by proposing the following provision be added to the National Defense Authorization Act for 2020:

Sale of Internet Protocol Addresses. Section 1088 would require the Secretary of Defense to sell at fair market value all of the department’s Internet Protocol version 4 (IPv4) addresses over the next 10 years. The proceeds from those sales, after paying for sales transaction costs, would be deposited in the General Fund of the Treasury.

The authors of the proposed legislation used a Congressional Budget Office estimate that a /8 (16.7 million addresses) would fetch $100 million after transaction fees. In the end, it didn’t matter because this provision was stripped from the final bill that was signed into law - the Department of Defense would be funded in 2020 without having to sell this precious internet resource.

What is AS8003 doing?

Last month, astute contributors to the NANOG listserv highlighted the oddity of massive amounts of DoD address space being announced by what appeared to be a shell company. While a BGP hijack was ruled out, the exact purpose was still unclear. Until yesterday when the Department of Defense provided an explanation to reporters from the Washington Post about this unusual internet development. Their statement said:

Defense Digital Service (DDS) authorized a pilot effort advertising DoD Internet Protocol (IP) space using Border Gateway Protocol (BGP). This pilot will assess, evaluate and prevent unauthorized use of DoD IP address space. Additionally, this pilot may identify potential vulnerabilities. This is one of DoD’s many efforts focused on continually improving our cyber posture and defense in response to advanced persistent threats. We are partnering throughout DoD to ensure potential vulnerabilities are mitigated.

I interpret this to mean that the objectives of this effort are twofold. First, to announce this address space to scare off any would-be squatters, and secondly, to collect a massive amount of background internet traffic for threat intelligence.

On the first point, there is a vast world of fraudulent BGP routing out there. As I’ve documented over the years, various types of bad actors use unrouted address space to bypass blocklists in order to send spam and other types of malicious traffic.

On the second, there is a lot of background noise that can be scooped up when announcing large ranges of IPv4 address space. A recent example is Cloudflare’s announcement of 1.1.1.0/24 and 1.0.0.0/24 in 2018.

For decades, internet routing operated with a widespread assumption that ASes didn’t route these prefixes on the internet (perhaps because they were canonical examples from networking textbooks). According to their blog post soon after the launch, Cloudflare received “~10Gbps of unsolicited background traffic” on their interfaces.

And that was just for 512 IPv4 addresses! Of course, those addresses were very special, but it stands to reason that 175 million IPv4 addresses will attract orders of magnitude more traffic. More misconfigured devices and networks that mistakenly assumed that all of this DoD address space would never see the light of day.

Conclusion

While today’s statement from the DoD answers some questions, much remains a mystery. Why did the DoD not just announce this address space themselves instead of directing an outside entity to use the AS of a long dormant email marketing firm? Why did it come to life in the final moments of the previous administration?

We likely won’t get all of the answers anytime soon, but we can certainly hope that the DoD uses the threat intel gleaned from the large amounts of background traffic for the benefit of everyone. Maybe they could come to a NANOG conference and present about the troves of erroneous traffic being sent their way.


TOPICS: Crime/Corruption; Government; US: District of Columbia
KEYWORDS: dod; internet
Navigation: use the links below to view more comments.
first previous 1-2021-4041-50 next last
To: narses
I think DoD's explanation sums it up perfectly.

Defense Digital Service (DDS) authorized a pilot effort advertising DoD Internet Protocol (IP) space using Border Gateway Protocol (BGP). This pilot will assess, evaluate and prevent unauthorized use of DoD IP address space. Additionally, this pilot may identify potential vulnerabilities. This is one of DoD’s many efforts focused on continually improving our cyber posture and defense in response to advanced persistent threats. We are partnering throughout DoD to ensure potential vulnerabilities are mitigated.

With hacked BGP routes, a bad actor could launch an attack sourced from the 11.0.0.0 net. Now, DoD can spot the BGP hackers.

21 posted on 04/24/2021 9:59:50 PM PDT by IndispensableDestiny
[ Post Reply | Private Reply | To 1 | View Replies]

To: narses

Will somebody please explain this to an old FReeper, who can barely turn on a PC, let alone understand all this? Thanks in advance.


22 posted on 04/24/2021 10:24:44 PM PDT by bobby.223 (Retired up in the snowy Mountains of the American Redoubt and it's a great life!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: narses

The message above has a timestamp of 16:57 UTC (11:57am ET) on January 20, 2021, moments after the swearing in of Joe Biden as the President of the United States and minutes before the statutory end of the administration of Donald Trump at noon Eastern time.

Odd timing. Nah.


23 posted on 04/24/2021 10:30:16 PM PDT by McGruff
[ Post Reply | Private Reply | To 1 | View Replies]

To: narses
“......but we can certainly hope that the DoD uses the threat intel gleaned from the large amounts of background traffic for the benefit of everyone.”

No that right there is some funny stuff, I don't care who you are!

Naive as all get out.

24 posted on 04/24/2021 10:39:28 PM PDT by mad_as_he$$
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ken Regis
The DOD had reserved a gazillion IP4 addresses it didn't use for decades. Scammers and bad actors are probably using those addresses to mask the origins of packets or misroute data. Now those addresses are 'lit,' so a device somewhere will actually receive those packets, including info packets about bad routing, address unknown, resends, etc. If something actually examines the data received that uses these addresses, a lot of interesting information about scammers or intel agencies using these addresses might be garnered.

Or, you'd just collect gigabytes of garbage.

25 posted on 04/25/2021 12:11:05 AM PDT by pierrem15 ("Massacrez-les, car le seigneur connait les siens" )
[ Post Reply | Private Reply | To 9 | View Replies]

To: narses

I take it you are talking to yourself and a few close friends since no one else will have a clue what you just wrote.
Wow do I miss Rush.
YOu could bring “everyone” on board.....


26 posted on 04/25/2021 2:39:19 AM PDT by rodguy911 ((FreeRepublic home of the free because of the Brave---Where we go One))
[ Post Reply | Private Reply | To 1 | View Replies]

To: narses

Per 1 article Global Resource Systems owns or is involved in all of this so who owes it? https://www.tampabay.com/news/military/2021/04/24/pentagon-mystery-with-a-florida-connection-is-solved-sort-of/

“””What a Pentagon spokesman could not explain Saturday is why the Defense Department chose Global Resource Systems LLC, a company with no record of government contracts, to manage the address space.”””


27 posted on 04/25/2021 3:33:20 AM PDT by blueyon (`nt to be a nothing burger)
[ Post Reply | Private Reply | To 1 | View Replies]

To: narses

So who is PAUL G YOVOVICH who is MGR of it with another man http://search.sunbiz.org/Inquiry/corporationsearch/SearchResultDetail?inquirytype=EntityName&directionType=PreviousList&searchNameOrder=GLOBALRESOURCESYSTEMS%20M060000016990&aggregateId=forl-m06000001699-a8147ffb-e7b4-41e1-a981-2bd8900de732&searchTerm=GLOBAL%20RIFLEX%20SOLUTIONS%20CORP&listNameOrder=GLOBALRESOURCESUSA%20V130771Also
why is Global Resource Systems LLC inactive?


28 posted on 04/25/2021 3:49:31 AM PDT by blueyon (`nt to be a nothing burger)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ransomnote

great post and the movie continues....


29 posted on 04/25/2021 4:24:35 AM PDT by rodguy911 ((FreeRepublic home of the free because of the Brave---Where we go One))
[ Post Reply | Private Reply | To 20 | View Replies]

To: pierrem15; familyop

Both, excellent replies.
I have used wireshark to solve small problems with IP cameras.

I appreciate your explanations. I understand more.

Thank you.


30 posted on 04/25/2021 4:28:31 AM PDT by Ken Regis
[ Post Reply | Private Reply | To 25 | View Replies]

To: narses

Need the space because of the advent of autonomous AI drone swarms and the like?


31 posted on 04/25/2021 5:01:20 AM PDT by PIF (They came for me and mine ... now its your turn)
[ Post Reply | Private Reply | To 1 | View Replies]

To: narses

Bkmk


32 posted on 04/25/2021 5:29:17 AM PDT by motor_racer (Who will bell the cat?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: narses; rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; ...

33 posted on 04/25/2021 5:40:05 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Ping


34 posted on 04/25/2021 6:24:44 AM PDT by Bob Ireland (The Democrap Party is the enemy of freedom.They use all the seductions and deceits of the Bolshevics)
[ Post Reply | Private Reply | To 5 | View Replies]

To: poconopundit

Ping.

This article completely over my head; however, you might possibly understand significance and motive.

What IS understood: the mention of Biden equals red flag and caution as corruption and treason will soon follow.


35 posted on 04/25/2021 6:46:58 AM PDT by V K Lee (Resist, we will! Remember, we must!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ransomnote

I think that’s true but I surely wish I knew more. There is chatter that the military is in control and Biden is not pres, etc., but I would really like more clarity on what’s going on.


36 posted on 04/25/2021 7:37:36 AM PDT by spacejunkie2001
[ Post Reply | Private Reply | To 20 | View Replies]

To: narses

can someone explain this, in english please?


37 posted on 04/25/2021 7:41:51 AM PDT by joe fonebone (Free Beer Tomorrow)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bigbob
Occams razor says to me that this was a planned DoD test and the timing is just coincidence.

38 posted on 04/25/2021 8:03:17 AM PDT by Bratch
[ Post Reply | Private Reply | To 12 | View Replies]

To: bobby.223; All

GOD IS IN CONTROL.


39 posted on 04/25/2021 8:11:02 AM PDT by MikeSteelBe (The South will be in the right in the next war of Northern aggression.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: bobby.223; All

GOD IS IN CONTROL.


40 posted on 04/25/2021 8:11:05 AM PDT by MikeSteelBe (The South will be in the right in the next war of Northern aggression.)
[ Post Reply | Private Reply | To 22 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-50 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson