A method and system for detecting routing loops and time-to-live (TTL)
expiry attacks in a telecommunications network are disclosed. The
detection of routing loops and TTL expiry attacks can be achieved based
on the comparison of TTL expiries occurring on two or more routers in the
network. A quantity of TTL expiries associated with a router can be
summed. Additionally, a quantity of TTL expiries associated with other
routers that are operatively coupled to the router can be summed. A
difference between the sums can be calculated and a determination of
whether a routing loop exists can be made in response to the difference.