FINDING · EVALUATION
HOWLR successfully detects 83% of the 1,902 real-world prefix hijack incidents observed in high-confidence Cloudflare Radar data from May 2026. The detection method fails when the hijacked prefix contains no authenticatable witnesses, and also cannot defend against routing adversaries capable of transparently forwarding non-targeted traffic within the prefix.
From 2026-doumanidis-howlr-client-driven-approach — HOWLR: A Client-Driven Approach to BGP Hijack Detection · §4, §7 · 2026 · arXiv preprint
Implications
- Circumvention tools should treat HOWLR-style detection as a necessary but insufficient layer: a determined nation-state adversary with traffic-forwarding capability can preserve witness consistency and evade detection, so complementary signals (latency anomalies, path-length changes) should also be monitored.
- 17% of real hijack events occur on prefixes with no TLS witnesses, so circumvention bridges/relays on witness-sparse infrastructure must have alternative detection mechanisms or avoid those prefixes entirely.
Tags
Extracted by claude-sonnet-4-6 — review before relying.