IDENTIFYING BOGON ADDRESS SPACES
First Claim
1. A method comprising:
- obtaining an indication of network address spaces in a network, the indication of network address spaces being based on route advertisements transmitted by a plurality of routers associated with the network, the route advertisements identifying the network address spaces in the network;
receiving a data report generated by a capturing agent deployed on a host in the network, the data report identifying a network flow captured by the capturing agent at the host;
identifying a network address associated with the network flow;
based on the indication of network address spaces, determining whether the network address associated with the network flow is within the network address spaces in the network;
when the network address is not within the network address spaces in the network, determining that the network address is a bogon address; and
when the network address is within the network address spaces in the network, determining that the network address is not the bogon address.
1 Assignment
0 Petitions
Accused Products
Abstract
Systems, methods, and computer-readable media for identifying bogon addresses. A system can obtain an indication of address spaces in a network. The indication can be based on route advertisements transmitted by routers associated with the network. The system can receive a report generated by a capturing agent deployed on a host. The report can identify a flow captured by the capturing agent at the host. The system can identify a network address associated with the flow and, based on the indication of address spaces, the system can determine whether the network address is within the address spaces in the network. When the network address is not within the address spaces in the network, the system can determine that the network address is a bogon address. When the network address is within the address spaces in the network, the system can determine that the network address is not a bogon address.
124 Citations
20 Claims
-
1. A method comprising:
-
obtaining an indication of network address spaces in a network, the indication of network address spaces being based on route advertisements transmitted by a plurality of routers associated with the network, the route advertisements identifying the network address spaces in the network; receiving a data report generated by a capturing agent deployed on a host in the network, the data report identifying a network flow captured by the capturing agent at the host; identifying a network address associated with the network flow; based on the indication of network address spaces, determining whether the network address associated with the network flow is within the network address spaces in the network; when the network address is not within the network address spaces in the network, determining that the network address is a bogon address; and when the network address is within the network address spaces in the network, determining that the network address is not the bogon address. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A system comprising:
-
one or more processors; and one or more computer-readable storage devices having stored therein instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising; obtaining an indication of network address spaces in a network, the indication of network address spaces being based on route advertisements transmitted by a plurality of routers associated with the network, the route advertisements identifying the network address spaces in the network; receiving a data report generated by a capturing agent deployed on a host in the network, the data report identifying a network flow captured at the host by the capturing agent; identifying a network address associated with the network flow; based on the indication of network address spaces, determining whether the network address associated with the network flow is within the network address spaces in the network; when the network address is not within the network address spaces in the network, determining that the network address is a bogon address; and when the network address is within the network address spaces in the network, determining that the network address is not the bogon address. - View Dependent Claims (12, 13, 14, 15)
-
-
16. A computer-readable storage device storing instructions which, when executed by a processor, cause the processor to perform operations comprising:
-
detecting route advertisements transmitted by a plurality of routers associated with a network, the route advertisements identifying valid network address spaces in the network; based on the route advertisements, obtaining an indication of network address spaces associated with the network; receiving, by a system, a data report generated by a capturing agent deployed on a host in the network, the data report identifying a network flow captured at the host by the capturing agent; identifying, by the system, a network address associated with the network flow; based on the indication of network address spaces, determining, by the system, whether the network address associated with the network flow is within the network address spaces in the network; when the network address is not within the network address spaces in the network, determining, by the system, that the network address is a bogon address; and when the network address is within the network address spaces in the network, determining, by the system, that the network address is not the bogon address. - View Dependent Claims (17, 18, 19, 20)
-
Specification