I would apply policing to discard that traffic.
First define an ACL that permits all ip traffic from that specific machine.
access-list 101 permit ip x.x.x.x 0.0.0.0 (host machine) any
next define a class-map that identifies the ACL we did previously.
class-map POLICE_TRAFFIC
match access group 101
then define the policy-map to police that traffic.
policy-map POLICE
class POLICE_TRAFFIC
police x (threshold were if traffic exceeds x it will be dropped)
then apply the policy map to the outgoing interface.
service-policy POLICE out
More information on policing is on the link below.
http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fqos_c/fqcprt4/qcfpoli.htm
HTH