Study finds RPKI-related events account for a small share of BGP updates
An 11-year study summarised on APNIC's blog associates well below 1% of observed BGP updates with RPKI events, while finding that the share is growing.
What changed
A research summary published on APNIC's blog on 2 October examines whether changes in RPKI authorisations are becoming a significant source of BGP update traffic. Researcher Samuele Quinzi describes an analysis spanning more than 11 years.
The study associates well below 1% of the observed BGP update volume with RPKI events. The share is increasing, but remains small in the measurements reported.
How to read the result
The analysis combines historical RIPE RPKI snapshots with the more recent, higher-frequency RPKI-Flutter dataset. Daily historical snapshots can miss short-lived events. The researchers also count updates within a convergence window after an RPKI event, an approach that can overestimate attribution.
The result concerns aggregate update volume. It should not be read as proof that a particular ROA change cannot affect reachability.
Why it matters for BYOIP teams
Our recommendation is to keep two questions separate in a change review: whether a proposed ROA is correct for the intended announcement, and how the team will observe the transition. Reassuring aggregate research does not replace either check.
A useful change record identifies the prefix, intended origin ASN, permitted prefix length and expected validation state. That makes a later discrepancy easier to investigate, whether it comes from a registry change, provider configuration or route announcement.
What to check
- Record the expected authorisation and routing state before changing a prefix's configuration.
- Monitor validation and reachability during the transition.
- Assign an owner and rollback procedure for unexpected results.
- Keep research findings distinct from service guarantees and provider-specific operating instructions.
Teams considering managed ROA workflows can also read our coverage of AWS VPC IPAM's delegated RPKI and BGP monitoring.
Sources
- Is RPKI becoming harmful to BGP stability?
Samuele Quinzi, guest post on APNIC Blog · published 2 Oct 2026 · checked 6 Oct 2026