Method for Filtering DDoS Attack Traffic through Routing Path within SDN Domain
Meng Yue, Mingzhi Yang, Hanwen Xu, Zhijun Wu · 2025
Attacks that aim to disrupt services, known as Distributed Denial of Service (DDoS), exploit protocol vulnerabilities and utilize legitimate traffic to target systems, thereby threatening the normal operation of the network. This paper proposes a method for filtering DDoS attack traffic along routing paths within the Software Defined Networking (SDN) domain. The method, based on the SDN framework, employs a consistency hashing algorithm to select nodes in the global routing platform, forming secure access paths. By utilizing the accuracy of edge node detection and inter-domain cooperation, the attack is effectively mitigated along the path close to its origin, which is referred to as path filtering. The paper also provides a design for the filtering framework and details the filtering steps.