22-08-2023 дата публикации
Номер: CN116633579A
Принадлежит:
The invention discloses an early detection and mitigation method for depletion of DDos by a slow TCAM under an SDN. The method comprises the following steps: step 1, periodically obtaining a flow table of each switch, and counting the number of flow table items longer than a fixed time length; if the value of the counted message and the value of the byte number field are both greater than the last moment, recording a change value; 2, calculating a cumulative sum value; step 3, extracting the cumulative sum value of each switch, judging whether the cumulative sum value is greater than a given threshold value, and if so, executing step 4; 4, calculating Duration, API, CMOP, CVOP and AMOIPPS characteristic values of each flow table item, inputting the characteristic values into the trained multi-voting model, if the flow table item is considered to be abnormal, deleting the flow table item by the controller, and adding a source Ip corresponding to the flow table item into a blacklist; otherwise ...
Подробнее