seismo

method & limits ← back to the seismograph
Experimental. Seismo is an auto-generated experiment by BGPKIT. It is not an alerting service, not an incident tracker, and not a root-cause claim. Numbers can be wrong in interesting ways; use the raw MRT data to verify anything before you cite it.

What this is

Seismo watches RIPE RIS update streams (collectors rrc00 and rrc01), folds them into a per-session routing-change signal, detects activity that goes beyond what each source did in the previous six days, and attributes the changes to the ASes involved: the origin side (whose routes changed) and the mid-path side (which transit ASes entered or left the observed paths).

Data

Detection

  1. Fold: every UPDATE from every session becomes counters per (session, 5-minute bucket): elements, withdrawals, path changes (new AS path differs from the last one), reversals (the new path equals the path before the last one).
  2. Baselines: per session and metric, median and MAD over the six baseline days (~1,700 buckets).
  3. Candidate flag: a bucket flags when it exceeds a floor, is at least 4x the session's median, and is at least 5 robust deviations away (z >= 5).
  4. Novelty bar: a candidate counts as novel only if it is also at least 3x the 99.9th percentile of the baseline days. This keeps rare spikes even for noisy sessions while dropping anything a source does routinely.
  5. Periodic / background: candidates below the novelty bar that recur at the same time of day on two or more baseline days are reported as periodic; the rest are background noise from chronically busy sessions. Chronic sources are tracked but do not suppress novel events by themselves.
  6. Magnitude: log10 of the summed novel signal, a Richter-style scale where +1 magnitude means roughly 10x signal.
  7. Events: consecutive novel buckets merge into an event; each event lists its top contributing sessions and a cross-collector check (was the same session, AS, or window also flagged on the other collector?).

Attribution

Definitions

Path change
an announcement whose AS path differs from the last announced path for the same (session, prefix).
Reversal
a change whose new path equals the path before the previous one (A to B to A): oscillation.
Novel flag / event
activity beyond everything the source did in the six baseline days (see the novelty bar).
Flap / churn
loosely, repeated path changes affecting the same prefix or session. Exact numbers on the page: "path changes" and "reversals".
Swap pair
one AS left and another joined the same differing path segment in the same change.

Limits & known gaps

Credits & corrections

Data: RIPE RIS (thank you). Parsing: bgpkit-parser. Everything else: BGPKIT. Not affiliated with or endorsed by RIPE NCC. Corrections and complaints: hello@bgpkit.com.