SOFTWARE DEFINED NETWORK CAPABLE OF DETECTING DDoS ATTACKS AND SWITCH INCLUDED IN THE SAME
US-2018109556-A1 · Apr 19, 2018 · US
US10637886B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10637886-B2 |
| Application number | US-201715692271-A |
| Country | US |
| Kind code | B2 |
| Filing date | Aug 31, 2017 |
| Priority date | Oct 17, 2016 |
| Publication date | Apr 28, 2020 |
| Grant date | Apr 28, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Software defined network capable of detecting a DDoS attack and a switch included in the same are disclosed. The software defined network comprises a controller arranged on a control plane of the software defined network, and a plurality of switches arranged on a data plane of the software defined network. Here, each of the switches collects packets received through corresponding external network and detects a DDoS attack by using the collected packets.
Opening claim text (preview).
The invention claimed is: 1. A server for performing a software defined network (SDN) installed on the server and connected to at least one external network, the server comprising: a controller arranged on a control plane of the SDN; and a plurality of switches arranged on a data plane of the SDN, wherein each of the plurality of switches collects packets received through corresponding external network using a flow table, when an entropy of the packets collected by a first switch of the plurality of switches is smaller than a predetermined threshold value, the first switch determines that a DDoS attack is detected and transmits a warning message to the controller, and the controller analyzes every packet having an ID of the first switch transmitted the warning message in order to track the corresponding external network having an attacker, and the entropy is defined by the following equation: H = - ∑ 1 n p i log p i Where p i = x i n W = { ( x 1 , y 1 ) , ( x 2 , y 2 ) , … } where, H, n, p i , x and y indicates respectively entropy, number of packets in a window W, probability of IP address of each of the packets in the window W, IP address of destination of the packets and time at which the packets are generated.
Peripheral units, e.g. input or output ports · CPC title
Denial of Service · CPC title
Event detection, e.g. attack signature detection · CPC title
Traffic logging, e.g. anomaly detection · CPC title
Virtual switches · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.