The invention relates to an increment deployment SDN network-based method for defending a link
flooding attack. A node
upgrade algorithm is utilized to pick out routers that need to be upgraded into
software-defined network function nodes and the routers are upgraded; when congestion occurs in a network, a congestion link is positioned through the
software-defined network function nodes deployed in the network; congestion link information of the whole network is collected, and on this basis, whether current
network congestion forms a link
flooding attack is judged; and if the link flooding attach is formed, global flow
engineering is started to balance flow of the whole network, otherwise, the congestion link is relieved through
backup of a path. According to the increment deployment SDN network-based method for defending a link
flooding attack, in a traditional network, a small quantity of nodes are upgraded into
software-defined network function nodes, the link flooding
attack is detected, a
link group that is attacked is positioned, and
link flow of the whole network is balanced through centralized
control flow engineering, so that the root of a link flooding
attack is eliminated, thereby effectively defending the link flooding
attack.