You get a bonus - 1 coin for daily activity. Now you have 1 coin

Bogon filtering of IP addresses

Lecture



Bogon filtering is the practice of filtering bogons, which are bogus (forged) IP addresses of a computer network. Bogons include IP packets on the public Internet that contain addresses that do not fall within any range allocated or delegated by the Internet Assigned Numbers Authority (IANA) or a delegated Regional Internet Registry (RIR), and that are not authorized for public use on the Internet. Areas of unallocated address space are called bogon space.

Bogons also include some address ranges from allocated space, also known as martian packets, mainly when they are used as a source address. Addresses reserved for private networks , such as 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 and fd00 :: / 8 , loopback interfaces such as 127.0.0.0/8 and : :1, and link-local addresses such as 169.254.0.0 / 16 and fe80::/64 are part of it. Also falling into this category are addresses for carrier-grade NAT, Teredo and 6to4, as well as documentation prefixes.

Many Internet service providers and end-user firewalls filter and block bogons because they have no legitimate use and are usually the result of accidental misconfiguration or malicious intent. Bogons can be filtered using router access control lists (ACLs) or using a BGP «black hole».

IP addresses that are currently in bogon space may later cease to be bogons, since IANA and other registries frequently allocate new address space to Internet service providers. Announcements of new assignments are often published on network operator mailing lists (such as NANOG) to ensure that operators have the opportunity to remove bogon filtering for addresses that have become legitimate. For example, the addresses in 49.0.0.0/8 were not allocated until August 2010, and are now used by APNIC. Over time, IPv4 address exhaustion will mean that there are fewer and fewer IPv4 bogons. IANA maintains a list of allocated and reserved IPv4 network blocks. As of November 2011, the Internet Engineering Task Force (IETF) recommends that, since there are no longer any unallocated IPv4 / 8 addresses, bogon filters based on registration status should be removed. Nevertheless, bogon filters should still check for martian packets.

The term bogon comes from hacker jargon, first appearing in the Jargon File in version 1.5.0 (dated 1983). It is defined as the quantum of bogosity, or the property of being bogus. A bogon packet is often bogus both in the ordinary sense of being forged for illegitimate purposes, and in the hacker sense of being incorrect, absurd, and useless.

These unused IP addresses are collectively known as bogon, short for «bogus login» ​​or a login from a place you know no one can log in from.

For example, addresses from 100.xxx to 107.xxx have not yet been allocated (assigned) (as of September 2009; see for the full current list)

Bogons are not the same as reserved private address ranges:

10.0.0.0/8 (10.ххх)
172.16.0.0/12 (172.16.хх - 172.31.хх)
192.168.0.0/16 (192.168.хх)

Bogon filtering of IP addresses

Table 3.1: List of current bogon prefixes (aggregated)

See also

  • Reverse path forwarding
  • IP hijacking
  • Ingress filtering
  • private IP addresses

Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "information security - Cryptography and Cryptanalysis. Steganography. Information protection"

Terms: information security - Cryptography and Cryptanalysis. Steganography. Information protection