A system and method for filtering unwanted Internet Protocol traffic based
on blacklists receives a first blacklist containing a first plurality of
Internet protocol addresses associated with unwanted Internet traffic.
The system also operates a first plurality of access control lists
adapted to block the unwanted Internet traffic from one of the first
Internet protocol addresses listed in the first blacklist. The system
also assigns a first weight to each of the first Internet protocol
addresses based on a reliability of Internet traffic from each of the
first Internet protocol addresses. Additionally, the system reduces a
first number of the first access control lists to optimally trade off a
number of desirable Internet protocol addresses blocked with a number of
bad Internet protocol addresses blocked based on the first weight of each
of the first Internet protocol addresses.