SOURCE VALIDATION

IP Spoofing Detection

Identify traffic whose source or destination conflicts with monitored network boundaries.

OPERATIONAL PURPOSE

Move from a network signal to verified context.

Separate unexpected external addresses by source and destination role, then compare volume, packet rate and associated subnet context.

Investigation workflow

Begin with the global condition, narrow the scope by direction and subnet, identify the responsible source and destination relationship, and compare the result with historical behavior before taking action.

CORE CAPABILITIESACTIVE
  • Monitored-subnet validation
  • Unexpected source and destination lists
  • Traffic volume and PPS metrics
  • IPv4/IPv6 investigation filters
  • Fast narrowing of suspicious communication
SHARED DATA CONTEXT

Built to work with the complete Flowtrion platform.

This module uses the same inventory and telemetry model as realtime analytics, security controls, historical reporting and BGP operations.

NetFlow / IPFIX

Use detailed flow relationships for capacity, application and source-destination analysis.

sFlow

Maintain scalable traffic and PPS visibility across high-speed, high-port-count environments.

SPAN / Port Mirroring

Add focused packet-copy visibility for critical services, VLANs and investigation points.

OPERATIONAL WORKFLOW

Investigate source-address anomalies and spoofing indicators

Source-address validation requires more than a single packet counter. Flowtrion uses traffic direction, expected prefixes, interface context and flow behavior to help operators identify addresses appearing where they should not.

Data inputs and analysis

Flow records provide source and destination prefixes, ingress and egress information, protocol, rate and timing. Expected customer, infrastructure and transit prefix definitions create the policy context required for a useful spoofing investigation.

The module highlights unexpected source ranges, direction conflicts and rapid changes in source diversity. Results should be verified against routing asymmetry, NAT, anycast and exporter configuration before an enforcement action is taken.

Operational outcomes

  • Identify unexpected source prefixes by interface or subnet.
  • Support BCP 38 and source-address validation reviews.
  • Separate likely spoofing indicators from legitimate asymmetric routing.
  • Provide evidence for ACL, uRPF or edge-policy changes.

Deployment considerations

Maintain an accurate prefix and interface inventory. Review uRPF mode, multihoming, NAT boundaries and asymmetric paths so the detection policy reflects the real network topology.

Spoofing indicators can be correlated with anomaly, DDoS, DNS and BGP views before ACL, RTBH or FlowSpec actions are considered.

TECHNICAL RESOURCES

Continue with related implementation guides