Software defined network-oriented DDoS attack defense system and method
A software- and network-oriented technology, applied in transmission systems, electrical components, etc., can solve problems such as safety issues that cannot be ignored
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- Publication Date
- 2017-04-19
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The invention belongs to the technical field of network security, in particular to the technical field of software-defined network security defense. Background technique
[0002] In recent years, Software Defined Network (SDN, Software Defined Network), as a new generation of network architecture, has become an emerging research hotspot. The emergence of the SDN network architecture makes up for many defects in the traditional network architecture. The SDN network is different from the distributed control of the traditional network, and the forwarding behavior of the SDN network switch is controlled by a unified controller. Administrators can manage the network more flexibly. It cannot be ignored that in practical applications, although the SDN network provides great convenience in network management, security issues in the SDN network environment cannot be ignored either. Traditional network real-time defense solutions against DDoS attacks mostly re...
Examples
example 1
[0078] In order to make the technical problems and technical solutions to be solved by the present invention clearer, the following will describe in detail the embodiments of defending against DDoS attacks of portal websites with reference to the accompanying drawings.
[0079] A software-defined network-oriented DDoS attack defense system realizes the identification and interception of DDoS attack traffic in the SDN network architecture environment. The invention is divided into three parts: an SDN network data collection part, a DDoS attack identification part and a DDoS attack interception part. The former part provides the decision-making basis for the latter part. The data collection part uses the OpenFlow flow table data of the switches in the SDN network, and the controller extracts and analyzes the data in real time to identify abnormal DDoS attack traffic; the attack interception part is based on Based on the judgment result in the previous part, a blocking flow table...