Atlantic Council urges BGP, DNS security reforms
An Atlantic Council report argues US private companies controlling Internet infrastructure should do more to secure BGP and DNS, and calls for federal procurement and diplomacy incentives.
This Atlantic Council policy report examines how private sector companies—ISPs, CDNs, and cloud providers—shape the Internet's topology and security through their control of core protocols like the Border Gateway Protocol (BGP) and the Domain Name System (DNS). It argues that while the US government was the Internet's original architect, governance has largely privatized, giving companies like Amazon, Google, AT&T, Verizon, Akamai, and Cloudflare outsized influence over global routing and naming infrastructure, yet many firms underuse this influence to improve security.
The report cites real-world incidents illustrating the risks of insecure BGP and DNS: a 2018 Iranian-linked campaign (referred to in reporting as Sea Turtle) that hijacked DNS servers of entire countries to steal information, and a June 2019 Verizon BGP route leak that caused a cascading outage affecting Amazon, Cloudflare, and other major providers due to lack of route-origin validation safeguards. These examples are used to demonstrate systemic vulnerabilities in Internet routing and naming protocols rather than to detail a specific new campaign.
The report concludes with policy recommendations: adding Internet protocol security best practices to federal procurement rules, mandating BGP/DNS protections for federal agencies, encouraging private sector threat-data-sharing dialogues, and reinvesting in State Department cyber diplomacy to establish norms against attacks on core Internet infrastructure. Overall, this is a policy and research piece rather than an active threat report, with no specific new indicators of compromise or ongoing campaign.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/report/the-politics-of-internet-security-private-industry-and-the-future-of-the-web
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free