BGP hijacking can redirect traffic before applications see it
A routing hijack diverts traffic before it ever reaches your servers, so nothing in your application notices.
Your logs show a drop in traffic, if anything. The redirected traffic can be inspected or used to obtain certificates for your domain by satisfying automated validation. It is a reminder that some of your security depends on parties you have no relationship with, and that monitoring for it is a different discipline from monitoring your own estate.
More on Internet routing
- BGP announces reachability, not truthA claim, not a proof
- Route leaks can be accidental and disruptiveThe whole motorway down a side lane
- RPKI validates route origins, not the whole pathOnly the first pair of hands is signed for
- More specific Internet routes usually winThe narrower claim takes it
- Anycast sends one address to multiple placesOne address, many doorsteps
- Route filtering is Internet hygieneWe all drink from the same main
