Prefix List Filtering for Accurate Spoofed Traffic Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for identifying and blocking spoofed IP addresses in telecommunications networks often result in the blocking of legitimate traffic, leading to inefficiencies and security vulnerabilities.
Innovation Solution
A system and method that generates prefix lists from routing information to update network device filters, allowing only legitimate traffic by identifying trusted IP addresses and automatically updating router configurations based on route registries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods block all traffic from unverified IP addresses, then spoofed traffic is blocked, but legitimate traffic is also blocked
Solution Approach 1:
The system performs preliminary actions by obtaining routing information and generating prefix lists before actual traffic filtering occurs. Network devices are pre-configured with trusted prefix lists derived from authoritative routing data, enabling them to distinguish legitimate traffic sources in advance rather than blocking all unverified traffic
Solution Approach 2:
The patent introduces an intermediary computing system that acts as a mediator between routing information sources and network filtering devices. This intermediary obtains routing information, generates prefix lists, and distributes them to network devices, creating a trusted intermediary layer that resolves the contradiction between blocking spoofed traffic and allowing legitimate traffic
2Reliability
If manual updates of filter configurations are performed, then filtering rules can be updated, but device resources are consumed and updates may not be timely
Solution Approach 1:
The system enables self-service by automatically obtaining routing information, generating updated prefix lists, and distributing them to network devices without manual intervention. The computing system autonomously monitors routing changes and pushes updates to network devices, eliminating the need for manual filter configuration updates while maintaining current and accurate filtering rules
Solution Approach 2:
The system performs preliminary generation and distribution of prefix lists before they are needed for filtering. By proactively obtaining routing information and preparing updated prefix lists in advance, the system ensures network devices have current filtering rules ready without consuming resources during actual traffic filtering operations
Data Source
AI summary
Systems and methods for blocking spoofed traffic within communications networks include obtaining, at a computing system, routing information for an autonomous system of a communications network, the routing information identifying Internet Protocol (IP) addresses associated with the autonomous system. In response to receiving the routing information, the computing system generates a prefix list based on the routing information, the prefix list including one or more prefixes encompassing the IP addresses identified by the routing information. The computing system then transmits instructions to a network device of the communications network configured to cause the network device to update a filter function of the network device based on the prefix list such that the network device permits network traffic that originates from IP addresses within the prefixes of the prefix list.


