The invention belongs to the technical field of network safety, and particularly relates to a DDoS (Distributed Denial of Service)
attack protection system and method based on SDN (
Software Defined Network) and BGP (
Border Gateway Protocol) process specifications, comprising: a monitoring device for monitoring
router network traffic in real time and detecting abnormal traffic through a sensing device to obtain
attack information; protective device, receiving
attack information of the monitoring equipment, a
network attack filtering platform based on a
software-defined network is used for protecting abnormal flow, and a
software-defined network controller which is used for carrying out
data analysis on attack information and pushing a routing strategy to a
router through a boundary gatewayprotocol flow specification is arranged in the filtering platform, so that the abnormal flow accommodating the attack information is filtered. According to the method, attacks and services are distinguished, passing of the
service flow is guaranteed while the attack flow is suppressed, flow filtering analysis is finer, the situation that a normal
service system cannot be used due to the fact thatlegal flow and illegal flow flowing to a target host are completely blocked is avoided, and the method has important guiding significance for network safety communication.