Join our Newsletter — 33% off our NHI Course
Home› Glossary› Cyber Security› More-Specific Prefix
Cyber Security

More-Specific Prefix

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Cyber Security

A more-specific prefix is a smaller network block announced within a larger address range, such as a /24 inside a /17. In BGP, more-specific routes often win path selection and can override a broader legitimate announcement. Attackers use this behavior to make forged routes attractive.

What More-Specific Prefix Means in BGP

A more-specific prefix is a narrower network announcement inside a larger address block, and BGP typically prefers it over the broader route. That makes it a powerful routing signal, but also a route-selection lever that can be abused.

Why More-Specific Prefixes Matter in Routing

The core property is simple: the longest-prefix match usually wins. If one AS announces a /24 inside someone else’s /17, routers often pick the /24 for traffic destined to that address space. This is why more-specifics are common in traffic engineering, failover, and mitigation, but also why they can be used to redirect traffic away from the intended origin.

More-specific announcements do not need to replace the original route to be effective. They can sit alongside the legitimate aggregate and still attract traffic for the targeted addresses. In practice, that means reachability, path preference, and route visibility all become part of the security and operations picture.

How More-Specific Prefixes Are Used

Operators may announce more-specifics to influence inbound traffic, shift load, or isolate a problem path. The same mechanism can support regional ingress control or emergency rerouting when an aggregate route is too coarse for operational needs. Because routing policy is distributed, the real effect depends on upstream filtering, prefix-length acceptance, and the policies of transit and peer networks.

That makes the term more than a routing detail. It describes a behavior that can change which network path is considered most attractive, even when the original announcement is still present. The security significance is that route preference is not purely about ownership of the larger block, but about how specific the competing advertisements are.

Security Implications of More-Specific Routes

Because BGP generally favors more-specific announcements, forged or unauthorized prefixes can divert traffic if they are accepted upstream. That can enable interception, blackholing, censorship-like redirection, or simple service disruption. The attack value comes from the fact that many networks trust routing policy more than origin intent.

Defensive controls therefore focus on route validation, prefix filtering, and monitoring for unexpected specificity changes. A route that is technically valid syntactically can still be suspicious operationally if it is more specific than expected or appears from an unusual origin.

Risk and Threat Considerations

More-specific prefixes create a real exposure because the routing system often treats a narrower announcement as the preferred path, even when it is malicious or accidental. That makes them a common mechanism for hijacks, traffic steering, and service disruption.

Failure mechanism: An attacker or misconfigured network announces a narrower prefix than the legitimate owner, upstream systems accept it, and traffic shifts to the forged route through longest-prefix match.

Impact: Traffic can be intercepted, dropped, delayed, or redirected, which can break availability, undermine trust in route origin, and expose sensitive sessions to path manipulation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1565 — Data ManipulationBGP prefix manipulation changes traffic direction and route preference.
Recommendation — Monitor for unauthorized route changes and correlate unexpected more-specific announcements with traffic diversion.
NIST CSF 2.0DE.AE-02 — Detected Anomalies are AnalyzedUnexpected more-specific prefixes are routing anomalies that warrant analysis.
PR.DS-10 — Integrity Is ProtectedRoute integrity depends on preventing unauthorized or altered announcements.
Recommendation — Analyze abnormal prefix-length changes and investigate route origin inconsistencies. Protect routing integrity with origin validation and prefix filtering.
NIST SP 800-53 Rev 5SC-7 — Boundary ProtectionFiltering and controlling inbound route acceptance is a boundary protection problem.
SI-4 — System MonitoringMonitoring is needed to detect suspicious route specificity changes and hijacks.
Recommendation — Enforce boundary controls that reject unauthorized or out-of-policy route advertisements. Alert on unexpected more-specific route announcements and route-origin changes.

Practitioner Guidance

What to watch for: Treat unexpected specificity as a routing anomaly, especially when a new more-specific appears for address space you already originate or depend on. The most useful operational question is whether the announcement is both authorized and consistent with your normal aggregation policy.

Governance implication: Maintain explicit origin and prefix-length policy, because the absence of a clean aggregate strategy makes it easier for an unintended more-specific to become operationally dominant. For external validation and route-policy context, practitioners often cross-check routing behavior against RPKI route origin validation and the operational realities described in RIPE routing recommendations.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org