The invention discloses a
software defined network-based DDoS
attack cross-layer cooperative defense method and aims to solve the problems of over high communication pressure of a southbound interfaceand a control plane as well as over high calculation pressure of an SDN controller. According to the technical scheme, the method comprises the following steps: constructing an SDN-based DDoS attackcross-layer cooperative defense framework comprising a data plane and a control plane, performing coarse-grained detection on data flow by the data plane to acquire DDoS
attack abnormal flow data, andperforming fine-grained detection on the DDoS
attack abnormal flow data by the control plane to acquire an exchanger closest to a bot network; deploying a
DDoS defense strategy on the exchanger closest to the bot network by the SDN controller of the control plane, and performing
DDoS defense according to the
DDoS defense strategy by the SDN exchanger of the data plane. Through cooperation of thedata plane and the control plane, the cooperative defense
advantage of the SDN is completely utilized and the problems of
high pressure of the SDN southbound interface and too large burden of the SDNcontroller are solved, so that the exchanger can perform automatic defense intelligently.