Experimental. Seismo is an auto-generated experiment by BGPKIT. It is not an alerting
service, not an incident tracker, and not a root-cause claim. Numbers can be wrong in interesting ways;
use the raw MRT data to verify anything before you cite it.
What this is
Seismo watches RIPE RIS update streams (collectors rrc00 and rrc01), folds them into a per-session routing-change signal, detects activity that goes beyond what each source did in the previous six days, and attributes the changes to the ASes involved: the origin side (whose routes changed) and the mid-path side (which transit ASes entered or left the observed paths).
Data
- RIPE RIS MRT update files, five-minute cadence, for the two collectors.
- Parsed and folded locally with
bgpkit-parser(BGPKIT's open-source Rust parser). - Window: a target day plus six baseline days. The target day shown on the main page is stated in the header ("data YYYY-MM-DD").
- Everything shown is what a collector peer announced to that collector. It is a view, not the whole Internet.
Detection
- Fold: every UPDATE from every session becomes counters per (session, 5-minute bucket): elements, withdrawals, path changes (new AS path differs from the last one), reversals (the new path equals the path before the last one).
- Baselines: per session and metric, median and MAD over the six baseline days (~1,700 buckets).
- Candidate flag: a bucket flags when it exceeds a floor, is at least 4x the session's median, and is at least 5 robust deviations away (z >= 5).
- Novelty bar: a candidate counts as novel only if it is also at least 3x the 99.9th percentile of the baseline days. This keeps rare spikes even for noisy sessions while dropping anything a source does routinely.
- Periodic / background: candidates below the novelty bar that recur at the same time of day on two or more baseline days are reported as periodic; the rest are background noise from chronically busy sessions. Chronic sources are tracked but do not suppress novel events by themselves.
- Magnitude: log10 of the summed novel signal, a Richter-style scale where +1 magnitude means roughly 10x signal.
- Events: consecutive novel buckets merge into an event; each event lists its top contributing sessions and a cross-collector check (was the same session, AS, or window also flagged on the other collector?).
Attribution
- Origin: for a withdrawal, the origin is the last ASN of the last known path for that prefix; for a path change, the origin of the new path. The per-event origin breakdown covers the sessions that triggered the event, within the event window only.
- Mid-path: each path change is diffed against the previous path (consecutive duplicates collapsed; common head and tail stripped). ASes that left the differing segment count as "removed", ASes that joined as "inserted".
- Swap pairs: changes with small differing segments are counted as (removed, inserted) ASN pairs, giving the "AS X swapped with AS Y" tables. The very large numbers usually come from a busy source oscillating between two transit options, not from two networks flapping at each other.
- Observation-side: a change is counted for the ASes that entered or left one collector peer's path. If AS X is "removed" here, that can mean AS X moved, or that the peer switched away from X. Telling those apart requires checking whether many independent sessions show the same change at the same time (cross-session synchrony), which this page does not yet do.
Definitions
- Path change
- an announcement whose AS path differs from the last announced path for the same (session, prefix).
- Reversal
- a change whose new path equals the path before the previous one (A to B to A): oscillation.
- Novel flag / event
- activity beyond everything the source did in the six baseline days (see the novelty bar).
- Flap / churn
- loosely, repeated path changes affecting the same prefix or session. Exact numbers on the page: "path changes" and "reversals".
- Swap pair
- one AS left and another joined the same differing path segment in the same change.
Limits & known gaps
- Six baseline days is a short window; seasonal or weekly patterns are mostly invisible to it.
- The novelty multiplier (3x the baseline p99.9) is a hand-tuned parameter; borderline items flip when it changes.
- Attribution currently covers a single target day per collector; no long history yet.
- Statistics are per session, not per AS; an AS with several sessions is shown aggregated on the Per-AS page but detected per session.
- Control plane only: nothing here is validated against traffic. "Withdrawn from a collector's view" is not "unreachable".
- 100% automatic; no human reviews these numbers before they are published.
Credits & corrections
Data: RIPE RIS (thank you). Parsing: bgpkit-parser. Everything else: BGPKIT. Not affiliated with or endorsed by RIPE NCC. Corrections and complaints: hello@bgpkit.com.