发明名称 SYSTEM AND METHOD FOR SOFTWARE DEFINED BEHAVIORAL DDOS ATTACK MITIGATION
摘要 Systems and methods for software defined behavioral DDoS attack mitigation are provided. According to one embodiment, a method is provided for controlling multiple distributed denial of service (DDoS) mitigation appliances. A DDoS attack mitigation central controller configures attack mitigation policies for the DDoS attack mitigation appliances. The DDoS attack mitigation policies are sent to the DDoS attack mitigation appliances through a network connecting the DDoS attack mitigation central controller and the DDoS attack mitigation appliances.
申请公布号 US2017111397(A1) 申请公布日期 2017.04.20
申请号 US201615396470 申请日期 2016.12.31
申请人 Fortinet, Inc. 发明人 Jain Hemant Kumar
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method for controlling a plurality of distributed denial of service (DDoS) mitigation appliances, comprising: providing a distributed software defined networking (SDN) architectural solution to DDoS mitigation by decoupling a control plane and a data plane for DDoS attack mitigation, wherein functionality associated with the control plane is implemented within a DDoS attack mitigation central controller and includes adaptive, continuous estimation of behavioral thresholds based on past traffic and management of DDoS attack mitigation policies and wherein functionality associated with the data plane is implemented within and distributed among the plurality of DDoS mitigation appliances and includes collection of granular traffic rate information regarding traffic observed by each of the plurality of DDoS mitigation appliances; configuring, by the DDoS attack mitigation central controller, the DDoS attack mitigation policies for the plurality of DDoS attack mitigation appliances comprising collecting, by the DDoS attack mitigation central controller, the granular traffic rate information from the plurality of DDoS attack mitigation appliances, and estimating granular behavioral packet rate thresholds based on the granular traffic rate information; and causing, by the DDoS attack mitigation central controller, the plurality of DDoS attack mitigation appliances to enforce the granular behavioral packet rate thresholds by sending the DDoS attack mitigation policies to the plurality of DDoS attack mitigation appliances through a network connecting the DDoS attack mitigation central controller and the plurality of DDoS attack mitigation appliances.
地址 Sunnyvale CA US