
For decades, many of us have described the Internet as ‘a collection of interconnected networks’. But when we look closely at operational data, that tidy description breaks down. In practice, connectivity is often conditional, influenced by private cloud architectures, carrier-grade Network Address Translation (cgNAT), firewalls, commercial disputes, and sometimes even geopolitical events. Our recent work presented at ACM NINeS 206 offers a new way to understand this reality: By treating partial reachability as a first-class feature of the Internet, not an anomaly.
In this study, we propose a connectivity-defined Internet core, one that does not rely on administrative authority but on actual reachability. That framing leads naturally to two operational states: Peninsulas, where connectivity is partial but persistent, and islands, where parts of the Internet become partitioned away from that core. These concepts help explain patterns that operators, researchers, and measurement platforms have observed for years — but never quantified.
Why partial reachability matters
One of the most striking findings is that peninsulas are more common than traditional outages. When our team examined long‑running datasets — including RIPE Atlas and DNS root measurements — we found that peninsula and island behaviour often overwhelms the signal of genuine operational incidents. In RIPE’s DNSMON, for example, peninsula‑related effects can be five to almost ten times larger than the events operators typically treat as meaningful outages. This means many of the ‘anomalies’ engineers chase are not outages at all, but structured patterns of partial reachability.
Another important insight is that the impact distribution is heavily skewed. While nearly half of peninsula events come from short-lived routing transients, almost all of the time spent in peninsula states — around 90% — is caused by a small set of long-lasting events, roughly 7% of the total. These are often tied to persistent policy decisions, commercial arrangements, or structural network conditions. In practical terms, this means that most user-perceived harm comes from a handful of stubborn issues — not the more frequent but brief disruptions.
How the research was carried out
To study partial reachability at Internet scale, we compared two complementary measurement systems. Trinocular provided a wide view by regularly probing about five million IPv4 /24 networks from six globally distributed sites. Meanwhile, RIPE Atlas, with its roughly 13,000 vantage points, offered immense diversity and sensitivity to directional routing behaviour by probing the DNS root servers. These systems allowed us to observe both edge‑to‑core and core‑to‑edge connectivity patterns.
From this data, we developed algorithms anchored in our reachability-based definition of the Internet core, enabling identification of peninsulas and islands. Results were consistent across three years of data. Even more encouraging, our team showed that reliable detection can be achieved with as few as three well‑chosen vantage points, significantly lowering the bar for adoption by operators with limited measurement resources. Validation against CAIDA Ark confirmed that these signals are real, with recall around 0.94 and precision between 0.42 and 0.82, depending on event category.
What this means for operators
For those responsible for network reliability, integrating peninsula‑aware thinking into operational workflows can bring major benefits. Many operators already recognize that asymmetry, filtering, or routing inconsistencies can degrade certain paths without causing complete outages. Peninsula detection provides a concrete way to surface and classify these cases. Adding peninsula and island indicators to existing dashboards can help teams avoid misinterpreting partial reachability as full outages, and avoid spending cycles debugging symptoms instead of root causes.
This approach also clarifies measurement hygiene. RIPE Atlas and DNS root monitoring streams are often noisy, and engineers can over‑escalate when they see inconsistent or partial responses. By factoring out peninsula and island effects before interpreting results, operators gain a clearer view of the underlying operational events — especially those tied to root server behaviour or wide‑area routing issues.
In addition, partial reachability metrics offer valuable context for Border Gateway Protocol (BGP) and peering teams. Persistent peninsulas often reflect underlying peering policies, filtering asymmetries, or de‑peering incidents that affect only subsets of paths. These signals can be early indicators of commercial or policy changes taken by upstreams or neighbors.
Relevance beyond operations
A connectivity‑based definition of the Internet core also helps inform Internet governance discussions. It highlights that no single economy or organization can unilaterally claim or operate ‘the’ Internet core — a finding that adds nuance to debates about sovereignty, routing fragmentation, and national Internet initiatives. Government decisions can still create islands or peninsulas, but they cannot centralize control of the global core as a whole.
Where the community can go next
There is considerable room for further work. IPv6 introduces different topological dynamics, making it important to investigate whether peninsula patterns behave differently across address families. There are also opportunities to combine peninsula detection with BGP update streams, Resource Public Key Infrastructure (RPKI) validity, and geolocation to produce semi‑automated root-cause labels. Looking forward, embedding peninsula‑aware metrics directly into routing controllers and Service Level Objective (SLO) monitoring systems could enable faster response to long‑lived partial events.
Finally, we advocate for shared, regularly refreshed ground‑truth datasets. With community‑maintained benchmarks spanning Atlas, Ark, and other platforms, operators and researchers would be able to validate and compare peninsula/island detectors much more effectively.
Guillermo Guillermo Baltra is a network researcher dedicated to understanding and improving the Internet’s underlying infrastructure. His work combines innovative network measurement techniques to strengthen the security, reliability, and resilience of critical online services.
The views expressed by the authors of this blog are their own and do not necessarily reflect the views of APNIC. Please note a Code of Conduct applies to this blog.