IDENTIFYING BOGON ADDRESS SPACES
First Claim
1. A method comprising:
- identifying a network address associated with a network flow;
determining whether the network address is associated with one or more network address spaces in a network, the determining based on route advertisements associated with the one or more network address spaces;
when the network address is not associated with the one or more network address spaces, determining the network address is a bogon address and filtering and/or marking the network flow; and
when the network address is associated with the one or more network address spaces, determining the network address is not the bogon address.
1 Assignment
0 Petitions
Accused Products
Abstract
Systems, methods, and computer-readable media for identifying bogon addresses. A system can obtain an indication of address spaces in a network. The indication can be based on route advertisements transmitted by routers associated with the network. The system can receive a report generated by a capturing agent deployed on a host. The report can identify a flow captured by the capturing agent at the host. The system can identify a network address associated with the flow and, based on the indication of address spaces, the system can determine whether the network address is within the address spaces in the network. When the network address is not within the address spaces in the network, the system can determine that the network address is a bogon address. When the network address is within the address spaces in the network, the system can determine that the network address is not a bogon address.
-
Citations
20 Claims
-
1. A method comprising:
-
identifying a network address associated with a network flow; determining whether the network address is associated with one or more network address spaces in a network, the determining based on route advertisements associated with the one or more network address spaces; when the network address is not associated with the one or more network address spaces, determining the network address is a bogon address and filtering and/or marking the network flow; and when the network address is associated with the one or more network address spaces, determining the network address is not the bogon address. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A system comprising:
-
one or more processors; and one or more computer-readable storage devices having stored therein instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising; identifying a network address associated with a network flow; determining whether the network address is associated with one or more network address spaces in the network, the determining based on route advertisements associated with the one or more network address spaces; when the network address is not associated with the one or more network address spaces, determining the network address is a bogon address and filtering and/or marking the network flow; and when the network address is associated with the one or more network address spaces, determining the network address is not the bogon address. - View Dependent Claims (12, 13, 14, 15)
-
-
16. A computer-readable storage device storing instructions which, when executed by a processor, cause the processor to perform operations comprising:
-
identifying a network address associated with a network flow; determining whether the network address is associated with one or more network address spaces in a network, the determining based on route advertisements associated with the one or more network address spaces; when the network address is not associated with the one or more network address spaces, determining the network address is a bogon address and filtering and/or marking the network flow; and when the network address is associated with the one or more network address, determining the network address is not the bogon address. - View Dependent Claims (17, 18, 19, 20)
-
Specification