首页> 外国专利> SDN-based DDOS attack prevention method, apparatus, and system

SDN-based DDOS attack prevention method, apparatus, and system

机译:基于SDN的ddos攻击防范方法,装置和系统

摘要

A software defined networking (SDN)-based distributed denial of service (DDoS) attack prevention method, an apparatus, and a system, where a controller delivers a traffic statistics collection instruction to a first packet forwarding device. The traffic statistics collection instruction instructs the first packet forwarding device to perform traffic statistics collection, and carries a destination Internet Protocol (IP) address. The controller collects statistical data reported by the first packet forwarding device, obtains, according to the statistical data, a statistical value of global traffic flowing to the destination IP address, and delivers a DDoS prevention policy to a second packet forwarding device based on a determining result that the statistical value of the global traffic exceeds the preset threshold. Correspondingly, the second packet forwarding device receives the DDoS prevention policy from the controller, and performs, according to the DDoS prevention policy, prevention process on the traffic flowing to the destination IP address.
机译:一种基于软件定义网络(SDN)的分布式拒绝服务(DDoS)攻击预防方法,装置和系统,其中控制器将流量统计信息收集指令传递给第一分组转发设备。流量统计信息收集指令指示第一分组转发设备进行流量统计信息收集,并携带目的IP地址。控制器收集第一报文转发设备上报的统计数据,根据统计数据获取流向目的IP地址的全局流量的统计值,并根据判断结果向第二报文转发设备下发DDoS防范策略导致全局流量统计值超过预设阈值。相应地,第二分组转发设备从控制器接收DDoS防护策略,并根据DDoS防护策略对流向目的IP地址的流量进行防护处理。

著录项

  • 公开/公告号US10630719B2

    专利类型

  • 公开/公告日2020-04-21

    原文格式PDF

  • 申请/专利权人 HUAWEI TECHNOLOGIES CO. LTD.;

    申请/专利号US201715711725

  • 发明设计人 WU JIANG;

    申请日2017-09-21

  • 分类号H04L29/06;H04L12/26;H04L12/715;H04L12/771;

  • 国家 US

  • 入库时间 2022-08-21 11:29:19

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号