This invention is to minimize influence to other network by preventing
unauthorized accesses such as DDoS attacks and probing by worms. When the
blocking apparatuses 10a and 10b detect outbound packets by the DDoS
attacks or by the probing by the worm, they carry out the Egress
filtering for such outbound packets to prevent the packets relating to
the unauthorized access from being sent to the backbone network 1000.
Moreover, because a notice to the effect that the unauthorized access is
detected is sent to other blocking apparatuses 10c and 10d via the
management apparatus 16, for example, the blocking apparatuses 10c and
10d precautionarily carry out the Ingress filtering to prevent the
packets relating to the unauthorized access from being sent to the
network C and D.