The invention relates to a defending device which has
active defense function for routers, a defending
system which consists of the defending device, routers and a
remote control platform and a method which can actively defend routers. The defending device of the invention comprises a
system administration module, an intrusion detection module, a
router control module, an audit
logging module and a
remote control response module. The defending device,
system and platform of the invention utilize the Libpcap function
library, adopt a bottom-layer packet capture technique which is integrated with an intrusion detection technique, parse whether the data packets are normal or not by a method of
data stream analysis, monitor and obstruct the illegal
data stream according to whether the data packets are normal or not and give an alarm to the administrators of the
remote control platform by the audit
logging module. The defending device, system and platform of the invention greatly increase the safety performance and the anti-
attack performance of routers and effectively protect the normal operation of the whole network, thereby providing a network administration platform where the network administrators can detect potential safety hazards, receive the feedback of the information of potential safety hazards and process the information of potential safety hazards in time.