The present invention provides a method, system, and computer program
product for quickly and automatically blocking a plurality of computer
systems in response to detection of a widespread vulnerability or
software infection. The method comprises: providing a list of Internet
Protocol (IP) addresses corresponding to a plurality of devices to be
blocked in a network; and for each IP address in the list: determining a
router in the network connected to the IP address; determining a layer-2
Media Access Control (MAC) address associated with the IP address; and
applying a CAM filter to a core switch associated with the router to
block communication from the device corresponding to the IP address, at
the core switch; wherein the blocking of the plurality of devices occurs
automatically in response to the provision of the list of IP addresses.