The invention discloses a
software defined
network security situation assessment method. The advantages of SDN (
software defined network) control and direct and quick information collection are combined, an open SDN security situation assessment framework is provided on account of three kinds of attacks of an SDN forwarding surface, the
security framework closely fits a framework of an SDN controller, an
anomaly detection module extracts characteristic indexes according to the SDN and various
attack characteristics, an SVM (
support vector machine) classification
algorithm is selected for identification, and
attack pre-judgment is given. A security situation assessment module performs
quantitative assessment on
network security situations according to information collected by the
anomaly detection module, and
attack sensitivity and
noise resistance of an assessment
system are regulated through setting of a threshold value. Different weights are allocated to different attacks based on an AHP (
analytic hierarchy process) so as to fit out a comprehensive security situation of the network. The method is flexible and simple, attach behaviors can be detected accurately, the
quantitative assessment of the security situations of the network is given, and monitoring and assessment of the security status of the SDN forwarding surface are realized with lower cost.