A more-specific prefix is a smaller network block announced within a larger address range, such as a /24 inside a /17. In BGP, more-specific routes often win path selection and can override a broader legitimate announcement. Attackers use this behavior to make forged routes attractive.
What More-Specific Prefix Means in BGP
A more-specific prefix is a narrower network announcement inside a larger address block, and BGP typically prefers it over the broader route. That makes it a powerful routing signal, but also a route-selection lever that can be abused.
Why More-Specific Prefixes Matter in Routing
The core property is simple: the longest-prefix match usually wins. If one AS announces a /24 inside someone else’s /17, routers often pick the /24 for traffic destined to that address space. This is why more-specifics are common in traffic engineering, failover, and mitigation, but also why they can be used to redirect traffic away from the intended origin.
More-specific announcements do not need to replace the original route to be effective. They can sit alongside the legitimate aggregate and still attract traffic for the targeted addresses. In practice, that means reachability, path preference, and route visibility all become part of the security and operations picture.
How More-Specific Prefixes Are Used
Operators may announce more-specifics to influence inbound traffic, shift load, or isolate a problem path. The same mechanism can support regional ingress control or emergency rerouting when an aggregate route is too coarse for operational needs. Because routing policy is distributed, the real effect depends on upstream filtering, prefix-length acceptance, and the policies of transit and peer networks.
That makes the term more than a routing detail. It describes a behavior that can change which network path is considered most attractive, even when the original announcement is still present. The security significance is that route preference is not purely about ownership of the larger block, but about how specific the competing advertisements are.
Security Implications of More-Specific Routes
Because BGP generally favors more-specific announcements, forged or unauthorized prefixes can divert traffic if they are accepted upstream. That can enable interception, blackholing, censorship-like redirection, or simple service disruption. The attack value comes from the fact that many networks trust routing policy more than origin intent.
Defensive controls therefore focus on route validation, prefix filtering, and monitoring for unexpected specificity changes. A route that is technically valid syntactically can still be suspicious operationally if it is more specific than expected or appears from an unusual origin.
Risk and Threat Considerations
More-specific prefixes create a real exposure because the routing system often treats a narrower announcement as the preferred path, even when it is malicious or accidental. That makes them a common mechanism for hijacks, traffic steering, and service disruption.
Failure mechanism: An attacker or misconfigured network announces a narrower prefix than the legitimate owner, upstream systems accept it, and traffic shifts to the forged route through longest-prefix match.
Impact: Traffic can be intercepted, dropped, delayed, or redirected, which can break availability, undermine trust in route origin, and expose sensitive sessions to path manipulation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1565 — Data Manipulation | BGP prefix manipulation changes traffic direction and route preference. |
| Recommendation — Monitor for unauthorized route changes and correlate unexpected more-specific announcements with traffic diversion. | ||
| NIST CSF 2.0 | DE.AE-02 — Detected Anomalies are Analyzed | Unexpected more-specific prefixes are routing anomalies that warrant analysis. |
| PR.DS-10 — Integrity Is Protected | Route integrity depends on preventing unauthorized or altered announcements. | |
| Recommendation — Analyze abnormal prefix-length changes and investigate route origin inconsistencies. Protect routing integrity with origin validation and prefix filtering. | ||
| NIST SP 800-53 Rev 5 | SC-7 — Boundary Protection | Filtering and controlling inbound route acceptance is a boundary protection problem. |
| SI-4 — System Monitoring | Monitoring is needed to detect suspicious route specificity changes and hijacks. | |
| Recommendation — Enforce boundary controls that reject unauthorized or out-of-policy route advertisements. Alert on unexpected more-specific route announcements and route-origin changes. | ||
Practitioner Guidance
What to watch for: Treat unexpected specificity as a routing anomaly, especially when a new more-specific appears for address space you already originate or depend on. The most useful operational question is whether the announcement is both authorized and consistent with your normal aggregation policy.
Governance implication: Maintain explicit origin and prefix-length policy, because the absence of a clean aggregate strategy makes it easier for an unintended more-specific to become operationally dominant. For external validation and route-policy context, practitioners often cross-check routing behavior against RPKI route origin validation and the operational realities described in RIPE routing recommendations.
Related resources from NHI Mgmt Group
- Should organisations use new AI-specific identity standards or existing ones?
- What breaks when a custom SSO implementation is too tightly coupled to tenant-specific IdP settings?
- What breaks when an app is approved without assistant-specific governance?
- Who is accountable for access drift when protocol-specific controls create exceptions?