Join our Newsletter — 33% off our NHI Course
Home› Glossary› Cyber Security› Source Address Filtering
Cyber Security

Source Address Filtering

← Back to Glossary
By NHI Mgmt Group Updated October 8, 2026 Domain: Cyber Security

A network control that blocks packets with forged source IP addresses from entering or leaving a network. For DNS amplification, this matters because spoofing is what lets attackers redirect large resolver responses toward a chosen victim.

What Source Address Filtering Does

Source address filtering is a basic network hygiene control: it verifies whether packets arriving on an interface should plausibly carry the source IP address they claim. When that check fails, the network drops the traffic instead of forwarding it.

That sounds simple, but it matters because source IP spoofing is an enabling condition for several abuses, especially when an attacker wants to hide where traffic came from or make packets appear to originate from elsewhere. The control is therefore less about authenticating a sender and more about refusing obviously inconsistent network-layer provenance.

Why It Matters for Abuse Prevention

Its most visible value is in limiting spoofed traffic from crossing a trust boundary. If an edge device allows packets with impossible or unexpected source addresses, downstream systems may see traffic that is harder to attribute, harder to rate-limit, and easier to use in reflection or amplification abuse.

For DNS amplification in particular, spoofing is the key enabler because the attacker forges the victim’s address as the source of the request, then uses open resolvers to send much larger replies to the victim. Source address filtering removes one of the easiest ways to launch that pattern from networks that enforce it properly.

It also supports operational clarity. Logs, flow records, and incident investigations are more trustworthy when the network rejects traffic that claims to come from an address block that should never appear on that interface or from a direction where that source is not routable.

Where It Is Applied

Source address filtering is usually implemented at network ingress and, in some designs, at egress. Ingress filtering blocks external packets whose source addresses do not match the expected routing or interface context; egress filtering prevents internal hosts from emitting packets with forged source addresses into the broader internet.

The exact enforcement point depends on the network architecture. ISPs, enterprise edges, cloud gateways, and routed segmentation boundaries can all apply the idea, but the underlying goal is the same: stop packets from using a source address that the path or policy says should not be there.

The control is strongest when it is aligned with routing reality, interface role, and address allocation. If the policy is too loose, spoofed traffic slips through; if it is too rigid or outdated, legitimate traffic can be dropped and cause operational issues.

Limits and Common Misconceptions

Source address filtering is not a substitute for authentication, encryption, or application-layer authorization. It only addresses whether the claimed source address is plausible at the network boundary, not whether the sender is trusted or whether the payload is safe.

It also does not stop every abuse case that involves spoofing. Attackers may still use networks that do not enforce filtering, or they may rely on relays, compromised infrastructure, or abuse paths that bypass the edge where filtering is strongest.

The control is best understood as one of the lowest-friction ways to reduce spoofing at scale. Its value comes from blocking an entire class of malformed or deceptive traffic early, before higher-cost monitoring or response logic has to sort it out.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SI-4 — System MonitoringNetwork spoofing reduction supports monitoring and detection of anomalous traffic flows.
AC-4 — Information Flow EnforcementFiltering forged source addresses enforces allowed network information flows at boundaries.
SC-7 — Boundary ProtectionSource address filtering is a boundary protection control against spoofed external traffic.
Recommendation — Correlate rejected spoofed packets with SI-4 alerts to spot abuse patterns and boundary failures. Apply AC-4 at ingress and egress boundaries to block traffic with implausible source addresses. Use SC-7 boundary enforcement to drop packets whose source addresses do not match path expectations.
CIS Controls v8CIS-13 — Network Monitoring and DefenseSpoofing defense is part of network defense and traffic validation at boundaries.
Recommendation — Monitor boundary traffic for spoofed-source indicators and block them in your network defense stack.
MITRE ATT&CKT1036 — MasqueradingSource IP spoofing is a masquerading technique used to disguise traffic origin.
Recommendation — Map spoofed-source traffic to T1036 and hunt for traffic that impersonates an unexpected origin.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org