Summary
- An AS-relationship dataset transforms selected BGP advertisements through cleaning rules, structural assumptions and validation into customer-provider or peer labels; those labels are inferred routing categories, not disclosed contracts.
- A defensible use preserves the snapshot, collector surface, method version and validation scope, then seeks separate evidence for commercial terms, traffic, location, redundancy and operational effect.
The line is an answer to a narrower question
Suppose a dataset records two AS numbers and classifies one as the other's customer. That line can support topology research, customer-cone analysis or a first-pass dependency map. It cannot reveal the invoice, the ports, the committed rate, the prefixes covered, the cities involved or the right to terminate. It cannot show whether the relationship is the same in Singapore and Frankfurt, or whether one party buys transit for some prefixes while peering for others.
This is not a defect hidden by the researchers. It is the boundary of the object they built. An AS-relationship map answers a question about the most plausible routing relationship that explains public observations under a specified method. A contract answers a different question about obligations between parties. Traffic telemetry answers another. Facility records, router configuration and incident evidence answer still others.
The distinction matters because the compact line is easy to move. It enters dashboards, rankings, supply-chain maps and risk models without carrying the paper that explains how it was produced. Once separated from its provenance, an inference can quietly become a claimed fact.
What a collector actually receives
BGP does not send a public copy of a bilateral agreement. RFC 4271 defines AS_PATH as the path attribute identifying the autonomous systems through which routing information has passed. It also leaves route selection and advertisement to local policy. A network may announce one set of routes to a customer, another to a peer and a narrower set to a collector.
RIPE RIS describes its collectors as machines that ingest BGP data through peering sessions. Some sit on exchange fabrics; others use multihop sessions. Each peer contributes a view shaped by that peer's location and export policy. The resulting archive is extraordinarily valuable, but it is not a wiretap on every interconnection.
The 2013 CAIDA study made its observation window explicit. It drew paths from Route Views and RIS routing-table snapshots taken once a day over the first five days of each month and used the union of what appeared. In the historical cohort discussed by the paper, about one third of contributors provided a full view, while 64% supplied routes to fewer than 2.5% of all ASes. Those numbers belong to the study period, not today's collector population. Their enduring lesson is about selection: a path archive records what participating networks chose to expose from particular vantage points.
How paths become a graph
The next transformation is analytical. CAIDA's account of the method begins with a commercial intuition: a conventional path climbs through customer-to-provider links, may cross one peer link, then descends through provider-to-customer links. Earlier work used that “valley-free” shape to infer which side of an observed connection was the provider.
The 2005 and 2007 work co-authored by kc claffy and colleagues addressed failures in early formulations. A path can fit the expected shape even when an individual edge is labelled incorrectly. Tie breaking can produce absurd results, such as making a large transit provider the customer of a small network. Peer links are especially difficult because many never appear in the collected paths.
The 2013 algorithm took another route. It cleaned AS paths, identified a top clique, sorted networks using transit degree and other tie breakers, and inspected adjacent path triplets. It relied on three structural assumptions: global reachability normally requires a provider, a clique of transit-free networks sits at the top, and provider-to-customer cycles should not occur. It inferred customer-provider edges first and then classified some remaining links as peers.
These steps produce a reproducible model, not a recovered contract archive. The assumptions are part of the result. Change the observed paths, the top-clique input, the cleaning rules or the algorithm, and an edge can change without either network signing a new agreement.
Validation improves a model without erasing its denominator
The 2007 paper did something essential: it asked network personnel. Thirty-eight of 78 contacted autonomous systems responded and supplied relationship types for 3,724 inferred links. Within that set, the method correctly classified 96.5% of customer-provider links, 82.8% of peer links and 90.3% of sibling links, 94.2% overall.
Those are strong results, but the paper did not pretend that the denominator was the whole Internet. Respondents self-selected, and the confirmed relationships represented 9.7% of the links in the public graph. More strikingly, the participating networks reported many adjacencies that BGP tables did not show. The tables missed up to 86.2% of their true adjacencies, predominantly peer links. A clean public map could therefore be accurate about visible edges and still be radically incomplete.
The 2013 paper widened the validation base. It combined directly reported relationships, mutually consistent RPSL policies and documented meanings of BGP communities. It validated 43,613 of 126,082 customer-provider and peer inferences. On that subset it reported 99.6% and 98.7% accuracy respectively. Yet the validation sources themselves disagreed by roughly 1%. The authors treated that disagreement as a limit imposed by available evidence.
An aggregate validation rate is not a confidence score that can be pasted onto any one edge. A specific relationship may sit in a well-observed part of the graph or at its least visible margin. It may have direct operator corroboration or only a structural inference. The paper's percentage describes a tested population under a named method; it does not certify a current contract between two named companies.
A single label compresses a changing arrangement
CAIDA's current dataset page states the hardest limitation plainly: the same pair of autonomous systems can have different semantics by location or prefix, while the model assigns one relationship to the pair. A customer in one region can be a peer elsewhere. Transit can be partial. A sibling structure can resemble another relationship. Free transit and paid peering do not fit comfortably into a binary vocabulary.
Customer cones inherit the same compression. Following inferred customer links gives a powerful comparative measure of reach and hierarchy. But the 2013 paper calls the construct methodologically unclean when the underlying relationships are hybrid. A cone is therefore an analytical projection. It is not a verified customer list, revenue ledger or inventory of paths that packets will take.
The two current CAIDA dataset families add another important distinction. Serial-1 derives monthly graphs from cleaned Route Views and RIS paths. Serial-2 adds evidence from BGP communities, looking glasses and traceroute, along with router-ownership and IP-to-AS inference. More sources may reveal more edges. They also create a longer provenance chain. “Present in serial-2” is not synonymous with “contract confirmed”; it says that a broader method inferred or observed enough evidence to include the link.
The person is part of a measurement institution
CAIDA's official page identifies kc claffy—also Kimberly Claffy—as its principal investigator and as a researcher focused on independent measurement of Internet addressing, routing and naming. UC San Diego's account of her 2017 Jonathan B. Postel Service Award emphasizes not only analysis but infrastructure for collecting, curating and sharing data.
That institutional work is why she is the subject here. It did not happen alone. The AS-relationship papers list changing teams of researchers, including Xenofontas Dimitropoulos, Dmitri Krioukov, Marina Fomenkov, Bradley Huffaker, Young Hyun, George Riley, Matthew Luckie, Amogh Dhamdhere and Vasileios Giotsas. Their sequence matters because it shows a method being challenged, validated and revised—not a finished oracle attributed to one inventor.
Explicit routing roles are still not the whole agreement
RFC 9234 supplies a useful contrast. It defines BGP Roles that two eBGP speakers can mutually confirm for a session and an Only to Customer attribute used in route-leak prevention. Such a negotiated role is stronger evidence of configured routing semantics than a third party's inference from selected paths.
Even that signal remains bounded. It describes a role for a BGP session and the propagation rules associated with it. The RFC recognizes complex relationships where different prefixes or contexts require different treatment. It does not publish prices, capacity or legal obligations, and it is not universally deployed. The hierarchy of evidence is therefore not “inferred or true.” It runs from observed advertisements, through inferred relationships, to operator-confirmed routing roles, contractual records and measured outcomes—each answering a different question.
Use the map without pretending it is the territory
A careful record of an inferred edge should carry the dataset family, snapshot date, address family, collector inputs, method version, edge label, auxiliary evidence and validation scope. If the label changes next month, preserve both states. Ask whether paths changed, collectors changed, the algorithm changed or the networks supplied new evidence before calling it a commercial event.
For consequential decisions, add the missing proof. Use operator statements or mutually confirmed roles to test routing semantics. Use contracts for price and obligation. Use traffic telemetry for load and direction. Use port and facility evidence for physical diversity. Use incident records for resilience.
That discipline does not diminish the map. It makes the map more useful. The enduring achievement of the CAIDA work is not that it turned private agreements into public certainty. It built a transparent way to reason about an otherwise hidden structure—and left enough methodological detail for readers to know where inference ends.
Sources
- UC San Diego: Internet Society honors CAIDA director
- UC San Diego public portrait of kc claffy
- RIPE RIS route collectors
- CAIDA: AS Relationships, Customer Cones, and Validation
- AS Relationships, Customer Cones, and Validation — PDF
- CAIDA inferred AS relationships dataset
- Inferring AS Relationships: Dead End or Lively Beginning? — PDF
- AS Relationships: Inference and Validation — PDF
- CAIDA public portrait
- CAIDA profile: kc claffy
- RFC 4271: BGP-4
- RFC 9234: Route leak prevention using BGP Roles
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
