The invention discloses a
moving target defense system for an SDN (self-defending network). The
system consists of a
moving target defense module and an SDN controller management module; the
moving target defense module comprises a flow analysis module, a mapping
information storage module, a target conversion module, an
encryption transmission module, a load balance module, a safety
authentication module, a business flow recording
database and a mapping information recording
database; the SDN controller management module comprises a flow table generation module, a flow table distribution / synchronization module, a
route selection module, a DNS
service module, a load balance module, a
distributed management module, a safety communication module, a redundant
backup module, a safety
authentication module and a flow
table database; furthermore, the invention also discloses a moving target defense method for the SDN. Through the moving target defense
system and the moving target defense method disclosed by the invention, the difficulty of an attacker to detect a target is increased further, and therefore the safety of an
intranet is comprehensively protected.