Prefix List Filtering for Accurate Spoofed Traffic Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for identifying and blocking spoofed IP addresses in telecommunications networks often result in the blocking of legitimate traffic, leading to inefficiencies and security vulnerabilities.

Innovation Solution

A system and method that generates prefix lists from routing information to update network device filters, allowing only legitimate traffic by identifying trusted IP addresses and automatically updating router configurations based on route registries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods block all traffic from unverified IP addresses, then spoofed traffic is blocked, but legitimate traffic is also blocked

Engineering Contradiction:
Improvespoofed traffic blockingVSAvoidlegitimate traffic flow
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by obtaining routing information and generating prefix lists before actual traffic filtering occurs. Network devices are pre-configured with trusted prefix lists derived from authoritative routing data, enabling them to distinguish legitimate traffic sources in advance rather than blocking all unverified traffic

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary computing system that acts as a mediator between routing information sources and network filtering devices. This intermediary obtains routing information, generates prefix lists, and distributes them to network devices, creating a trusted intermediary layer that resolves the contradiction between blocking spoofed traffic and allowing legitimate traffic

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual updates of filter configurations are performed, then filtering rules can be updated, but device resources are consumed and updates may not be timely

Engineering Contradiction:
Improvefiltering accuracyVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system enables self-service by automatically obtaining routing information, generating updated prefix lists, and distributing them to network devices without manual intervention. The computing system autonomously monitors routing changes and pushes updates to network devices, eliminating the need for manual filter configuration updates while maintaining current and accurate filtering rules

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary generation and distribution of prefix lists before they are needed for filtering. By proactively obtaining routing information and preparing updated prefix lists in advance, the system ensures network devices have current filtering rules ready without consuming resources during actual traffic filtering operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12355725B2Systems and methods for blocking spoofed traffic
Publication Date: 2025.07.08 LEVEL 3 COMMUNICATIONS LLC
  • US12355725B2 patent drawing
  • US12355725B2 patent drawing
  • US12355725B2 patent drawing

AI summary

Systems and methods for blocking spoofed traffic within communications networks include obtaining, at a computing system, routing information for an autonomous system of a communications network, the routing information identifying Internet Protocol (IP) addresses associated with the autonomous system. In response to receiving the routing information, the computing system generates a prefix list based on the routing information, the prefix list including one or more prefixes encompassing the IP addresses identified by the routing information. The computing system then transmits instructions to a network device of the communications network configured to cause the network device to update a filter function of the network device based on the prefix list such that the network device permits network traffic that originates from IP addresses within the prefixes of the prefix list.