MANRS Observatory 3.0: Smarter Tools for Routing Security

Discover how the latest MANRS Observatory updates empower network operators with intuitive tools to enhance global routing security and prevent incidents.

By Medha deb
Created on

The Internet’s backbone relies on the Border Gateway Protocol (BGP) to route data across global networks. However, vulnerabilities in BGP can lead to hijacks, leaks, and outages that disrupt services worldwide. The Mutually Agreed Norms for Routing Security (MANRS) initiative addresses these risks by promoting best practices among network operators. At its core is the MANRS Observatory, a dynamic platform that assesses and visualizes routing security across thousands of autonomous systems (ASNs).

Version 3.0.1 of the Observatory marks a significant evolution, responding directly to user feedback. This update introduces features that make the tool more informative, intuitive, and user-friendly. Network engineers, security analysts, and policymakers now have access to refined data presentations, interactive elements, and streamlined workflows. These enhancements not only simplify daily operations but also accelerate the adoption of secure routing practices globally.

Understanding the MANRS Framework and Its Importance

MANRS, launched by the Internet Society, outlines actionable guidelines for network operators, Internet exchange points (IXPs), and cloud providers. It focuses on six key actions: filtering incorrect announcements, setting up validation systems, maintaining accurate records, publicizing policies, promoting adoption, and offering diagnostic tools.

The Observatory quantifies adherence to these actions through a ‘readiness index.’ This score categorizes networks as ‘ready’ (high compliance), ‘aspiring’ (moderate), or ‘lagging’ (low). By aggregating data from sources like Regional Internet Registries (RIRs), PeeringDB, and routing collectors, it provides a real-time snapshot of global routing health. Recent statistics show over 1,000 participating networks, covering a substantial portion of Internet traffic, underscoring its impact.

Why does this matter? Routing incidents have real-world consequences. In 2020 alone, BGP hijacks affected major services, leading to blackouts and data redirection. Tools like the Observatory empower proactive measures, reducing such events by up to 30% in monitored regions, according to MANRS reports.

Key Enhancements in Visualization and Data Presentation

One of the standout improvements in 3.0.1 is the revamped dashboard layout. Users are greeted with a cleaner overview page that prioritizes critical metrics. Trend indicators—simple up/down arrows—now accompany readiness scores, allowing quick assessment of progress or decline over time.

Interactive elements further elevate usability. Hovering over charts reveals pop-up details, explaining metrics like bogon announcements (invalid prefixes) or AS path anomalies. These tooltips reduce the learning curve for newcomers while providing depth for experts. For multi-network views, stacked historical charts illustrate shifts in readiness categories, making it easier to spot trends across peers or regions.

  • Trend Arrows: Instant visual cues for score changes.
  • Hover Pop-ups: Contextual explanations without cluttering the interface.
  • Stacked Charts: Comparative analysis for groups of ASNs.

This design philosophy emphasizes clarity. Previously verbose reports on issues like invalid routes are now concise, focusing on actionable insights rather than raw data dumps.

Streamlined Metrics for Bogons and Invalid Routes

Bogon announcements—routes from unallocated IP spaces—remain a top concern. The update consolidates related metrics into a single, digestible view. Instead of fragmented counters, users see unified tallies with severity ratings and resolution suggestions.

For instance, the platform now differentiates between minor leaks and potential hijacks, using color-coded alerts. Historical data tracks recurrence, helping operators prioritize fixes. This simplification cuts report length by half, saving time in network operations centers (NOCs).

Metric TypeOld ApproachNew ApproachBenefit
Bogon AnnouncementsMultiple scattered countersConsolidated dashboard widgetFaster triage
AS Path ValidationStatic listsInteractive timelinesTrend identification
Prefix ConsistencyVerbose logsSummary scores with details on demandReduced noise

These changes align with MANRS Action 1 (filtering), enabling operators to enforce policies more effectively.

Custom Groups and Collaborative Monitoring

A game-changer for teams is the custom network group feature. Users can bundle ASNs of interest—such as peers, customers, or regional clusters—into personalized dashboards. This eliminates repetitive searches, providing at-a-glance overviews.

Access controls remain robust: detailed reports are restricted to owned networks, but group summaries foster collaboration. Export options in JSON or shareable links facilitate NOC handoffs or partner discussions. Imagine briefing stakeholders with a stable URL to a tailored readiness report—no more screenshots or manual compilations.

For MANRS partners like IXPs, this means monitoring ecosystem-wide compliance without exposing sensitive data. It’s a step toward the collaborative spirit of MANRS.

Expanded Data Sources for Comprehensive Insights

Metric accuracy hinges on quality inputs. Version 3.0.1 integrates PeeringDB alongside RIR WHOIS for contact validation (MANRS Action 3). This dual querying catches discrepancies, ensuring policies reflect reality.

New feeds from global routing collectors enrich incident detection. The result? A more holistic readiness index that correlates with real-world performance. Early adopters report 15-20% improvements in self-assessments post-update.

User Interface Overhaul: Intuitive and Accessible

The entire interface has been polished for efficiency. Expanded help sections use plain language, with searchable FAQs embedded in context. Navigation is hierarchical: global stats lead to regional breakdowns, then ASN specifics.

Mobile responsiveness ensures field engineers can check metrics on the go. Dark mode support reduces eye strain during late-night shifts—a small but appreciated touch.

Supporting Onboarding with Aspirant Accounts

To lower entry barriers, aspirant accounts let prospective MANRS members preview their network’s data during audits. This self-service tool highlights gaps, streamlining applications and boosting join rates.

API Access and Programmatic Use

Power users rejoice: the public API delivers raw data for custom integrations. From automated alerts to third-party dashboards, it extends the Observatory’s reach. Terms ensure ethical use, prohibiting commercial resale.

Impact on Global Routing Security

Since launch, the Observatory has tracked millions of announcements, identifying patterns in incidents. Regions with high MANRS adoption show fewer leaks. As version 3.0.1 rolls out, expect accelerated progress toward a more secure Internet.

Operators using these tools report quicker incident resolution—often under 30 minutes versus hours previously. Policymakers leverage aggregated views for awareness campaigns.

Future Directions and Community Feedback

MANRS continues iterating based on input. Upcoming features may include AI-driven anomaly detection and expanded metrics for IPv6. Join the community via forums or the registration portal to shape what’s next.

Frequently Asked Questions (FAQs)

What is the MANRS readiness index?
It scores networks on compliance with MANRS actions, from 0-100, categorized as ready, aspiring, or lagging.

Who can access detailed reports?
Only verified MANRS participants for their own ASNs; public views are aggregated.

Is the Observatory free?
Yes, with registration for advanced features.

How does PeeringDB integration help?
It verifies contact info, aligning records with MANRS requirements.

Can I export data?
JSON exports and shareable links are available for reports.

In summary, MANRS Observatory 3.0.1 transforms routing security from a reactive chore into a proactive advantage. By making complex data approachable, it empowers the community to build a resilient Internet infrastructure.

References

  1. MANRS Observatory Official Page — MANRS.org. 2024-05-01. https://manrs.org/manrs-observatory/
  2. Introduction to the MANRS Observatory — ICANN (archived). 2019-11-06. https://archive.icann.org/meetings/icann66/files/content=t_attachment,f_%227-%20York%20-20191106-MANRS-Observatory-Intro.pdf%22/7-%20York%20-20191106-MANRS-Observatory-Intro.pdf (Authoritative ICANN presentation on foundational metrics, remains relevant for core concepts).
  3. New Features on the MANRS Website — MANRS.org. 2022-06-01. https://manrs.org/2022/06/new-features-on-the-manrs-website/
  4. MANRS Observatory Update Improves User Interface — MANRS.org. 2021-04-01. https://manrs.org/2021/04/manrs-observatory-update-improves-user-interface-partner-accounts/
  5. You Asked and We Listened: New Features in the MANRS Observatory — Internet Society. 2020-02-01. https://www.internetsociety.org/blog/2020/02/you-asked-and-we-listened-new-features-in-the-manrs-observatory/
Medha Deb is an editor with a master's degree in Applied Linguistics from the University of Hyderabad. She believes that her qualification has helped her develop a deep understanding of language and its application in various contexts.

Read full bio of medha deb