The invention discloses a SDN (
software defined network) framework,
system and working method combining DDoS (distributed denial of service)
threat filtering and routing optimization. The SDN framework comprises an application plane, a data plane, and a control plane, wherein when an
attack threat is detected by any IDS device located on the data plane, the application plane is notified to enter the
attack type analysis process; the application plane is used for making analysis of the
attack type and making the corresponding
treatment strategy for the attack
threat according to the attack type; the control plane provides an attack threat
processing interface for the application plane and provides the optimal path
algorithm and / or an attack threat identification interface for the data plane. According to the SDN framework,
system and working method, when a network suffers from a large-scale DDoS threat, traffic forwarding of routing optimization can be realized according to the real-time conditions of a link, meanwhile, DDoS threat identification and response
processing can be conducted quickly and accurately, and
network communication quality can be comprehensively guaranteed.