OcNOS-SP · FastNetMon · BGP Flowspec · RTBH

在您自己的網路中,2 秒內發現並阻止 DDoS 攻擊。

OcNOS 與 FastNetMon 結合後,可在網路邊緣直接實現自動化 DDoS 檢測與緩解——無需清洗中心,無需雲端引流,也不會增加時延。攻擊通過 sFlow/NetFlow 遙測檢出,並在 ASIC 硬體中以線速完成緩解。

為何選擇網路內 DDoS 緩解?

清洗中心增加延遲和成本。硬體級 Flowspec 兩者都不增加。

傳統 DDoS 防護會將所有流量繞行至旁路清洗中心——即便在正常運行時也會讓每個數據包額外引入 10–50 ms 時延,並按 Gbps 收取清洗容量費用。這一模式在攻擊較少、檢測較慢的年代是合理的。

如今的攻擊更快、更大、更頻繁。 OcNOS 與 FastNetMon 將檢測與緩解邏輯直接置於網路邊緣: sFlow/NetFlow 遙測持續從 OcNOS 流向 FastNetMon;一旦檢測到攻擊,FastNetMon 將 BGP Flowspec 規則推送回 OcNOS;OcNOS 在線速下將規則安裝到 ASIC 硬體中。整個迴路在 2 秒內完成 — 且對正常流量沒有任何額外時延。

可檢測並緩解的攻擊類型:

UDP 放大 SYN Flood TCP RST Flood ICMP Flood DNS 查詢泛洪 NTP 放大 Memcached 反射攻擊 容量型頻寬飽和 分片包攻擊

FastNetMon 整合 — 生產級 DDoS 檢測引擎

FastNetMon Advanced 是被全球數百家 ISP 與託管服務商採用的生產級 DDoS 檢測系統:可消費來自 OcNOS 的 sFlow、NetFlow v5/v9、IPFIX 及埠鏡像流量,並按可配置的主機/子網閾值自動觸發緩解動作。

BGP FlowSpec (RFC 8955) — 外科級精準流量過濾

可按源/目的 IP、協議、埠、包長、TCP 標誌、DSCP 與分片類型匹配並過濾攻擊流量。規則通過 BGP 下發並在毫秒級內裝載到 ASIC 硬體——以線速過濾、零 CPU 開銷,可對匹配流量進行丟棄、限速或重定向。

RTBH 黑洞 — 快速直接的防護

適用於大規模流量型攻擊的 BGP 黑洞路由:可由客戶主動觸發,也可在流量超閾值時由 FastNetMon 自動觸發。RTBH 路由會傳播至上遊對等和中轉電信業者,將攻擊流量阻擋在進入您的網路之前。

sFlow & NetFlow 遙測 — 持續流量可視化

OcNOS 在所有邊緣接口上導出 sFlow(RFC 3176)、NetFlow v5/v9 與 IPFIX——採樣由硬體加速且採樣率可配置。可同時為 FastNetMon 提供 DDoS 檢測數據,並向 Kentik、PRTG、Prometheus 或任意流量採集器輸出流量分析數據。

硬體 ACL 過濾 — 靜態、零 CPU 阻斷

ASIC 加速的訪問控制列表可永久阻斷已知惡意主體——按特定 IP、子網、協議或埠實施。可按接口、VLAN 或前綴進行限速;一次配置即在硬體中永久執行,不增加任何路由或處理開銷。

FastNetMon → OcNOS — 自動響應 警報
1 — FastNetMon 通過 sFlow 檢測異常
警報 UDP 洪水 → 203.0.113.50
14 Gbps — 已超過 5 Gbps 閾值
2 — FastNetMon 將 BGP Flowspec 推送至 OcNOS
POST /api/flowspec/rule
match: dst 203.0.113.50/32 proto UDP
action: rate-limit 100Mbps
→ 規則已安裝到 ASIC:0.8 秒
3 — OcNOS 在硬體中以線速強制執行
Flowspec 規則已啟用 14
已丟棄(攻擊) 2.4M pps
速率限制 180K pps
✓ 正常流量正常通過

FastNetMon — 檢測引擎

FastNetMon Advanced 是被全球數百家 ISP 採用的專用 DDoS 檢測引擎,可通過 BGP Flowspec 與 RTBH 與 OcNOS 原生整合,支持 sFlow、NetFlow 與 IPFIX,並可按主機、子網、協議分別配置閾值。

了解 FastNetMon →
<2s
檢測到緩解的閉環 — 從 sFlow 異常到硬體中的 Flowspec 規則
0ms
對正常流量無附加時延 — 過濾在線性 ASIC 中完成,而非旁路清洗器
0%
硬體 ACL 與 Flowspec 執行的 CPU 開銷 — 由 ASIC 加速
600+電信業者部署
60+國家
26網路領域年數
參考架構

In-network DDoS detection and mitigation — full topology

A complete picture of where each protection layer sits. Attack traffic from the internet hits the OcNOS edge routers, where sFlow telemetry continuously feeds FastNetMon. When FastNetMon detects an anomaly, it pushes BGP Flowspec or RTBH back to the edge — installed in ASIC hardware in milliseconds. Upstream peers can also receive RTBH announcements to drop attack traffic before it reaches your network.

In-network DDoS protection topology with OcNOS edge and FastNetMon Attack traffic from botnet sources transits an upstream peer to two OcNOS-SP edge routers. The edge routers export sFlow and NetFlow telemetry to a FastNetMon detection engine. When an attack is detected, FastNetMon pushes BGP Flowspec or RTBH routes back to the edge routers via BGP, installing rules in the ASIC for line-rate filtering. Clean traffic continues to the protected customer or data center network. The upstream peer can also receive RTBH announcements over BGP to drop attack traffic before it ingresses the protected network. Attackers distributed botnet 10–100 Gbps Customers legitimate traffic HTTP/DNS/SSH Transit Peer eBGP / RTBH recv Tier-1 Internet RTBH /32 drops OcNOS Edge-01 UfiSpace S9600-72XC Qumran-AX · 4.8 Tbps ASIC HARDWARE Flowspec + ACL drop line-rate · 0% CPU OcNOS Edge-02 UfiSpace S9600-72XC ECMP redundant ASIC Flowspec + ACL attack + clean FastNetMon Detection Engine sFlow + NetFlow analysis < 1s threshold detect sFlow ↑ BGP Flowspec ↓ + RTBH RTBH propagated upstream over eBGP → Protected Servers DC / hosted infra clean traffic only · 0ms added Customer Networks per-tenant policy managed DDoS service clean ✓ attack drop DETECT-TO-MITIGATE LOOP 1. Anomaly detected FastNetMon: <1s 2. BGP Flowspec push FNM → OcNOS: ~200ms 3. ASIC rule installed OcNOS hardware: ~800ms 4. Attack dropped at line rate total loop: <2s · 0ms clean-traffic latency
Attack traffic
Clean traffic
sFlow / NetFlow telemetry
BGP Flowspec / RTBH (control plane)
↳ hover any node for platform, ASIC, BGP, and policy detail
工作原理

從攻擊檢測到流量阻斷 — 四步

從檢測到緩解的整個閉環已實現自動化,一經配置即無需人工幹預便可阻斷攻擊。

1

收集

OcNOS 將所有邊緣接口的 sFlow 與 NetFlow 遙測導出到 FastNetMon。包採樣由硬體加速完成——無 CPU 開銷,不影響轉發性能。

2

檢測

FastNetMon 按主機與子網閾值分析流數據,通常可在 1 秒內識別出流量型洪水、SYN 風暴、UDP 放大、DNS 洪水以及 NTP 反射攻擊。

3

信號

FastNetMon 通過 BGP 自動向 OcNOS 下發 BGP Flowspec 規則(用於精細緩解)或 RTBH 黑洞路由(用於流量型攻擊)。全程自動——攻擊期間無需維運人員幹預。

4

緩解

OcNOS 將 Flowspec 規則或 RTBH 路由直接安裝到 ASIC 硬體中。攻擊流量在全線速下被丟棄或限速。正常流量不受影響地繼續傳輸。攻擊結束後規則自動移除。

使用案例

OcNOS 的 DDoS 防護適用場景

OcNOS DDoS 防護適用於任何在網路邊緣運行開放硬體的電信業者——從小型 ISP 到大型資料中心電信業者均可使用。

🌐

ISP & SP 邊緣防護

保護對等邊緣和中轉鏈路免受會飽和適用於客戶頻寬的流量型 DDoS:在對等路由器進行 sFlow 檢測並自動通過 BGP Flowspec 緩解,可在洪水到達下遊客戶前阻斷;與中轉電信業者協調上遊 RTBH,則可在攻擊進入您的網路前就將其擋在門外。

🏢

資料中心邊界

在資料中心邊界進行直連 DDoS 過濾——保護託管基礎設施與雲工作負載:靜態硬體 ACL 永久阻斷已知惡意主體;動態 Flowspec 規則實時適應新攻擊特徵;流量無需繞行清洗中心,因此對正常流量零時延影響。

🛡️

託管 DDoS 防護服務

電信業者可按受保護前綴計費,將基於客戶的 DDoS 防護作為託管服務對外提供:FastNetMon 支持每客戶閾值方案,OcNOS 按客戶執行 Flowspec 規則——無需共享清洗基礎設施,每位客戶的防護都是網內專屬的。

常見問題

使用 OcNOS 的 DDoS 防護 — 常見問題

BGP Flowspec 是什麼,OcNOS 如何用於 DDoS 緩解?
BGP FlowSpec (RFC 8955, originally RFC 5575) is a BGP extension that distributes granular traffic filtering rules across routers — similar to pushing ACLs via BGP, but with more granular match conditions. OcNOS supports Flowspec matching by source IP, destination IP, protocol, source/destination port, packet length, TCP flags, DSCP, and IP fragment type. When FastNetMon detects an attack, it pushes Flowspec rules to OcNOS via BGP in milliseconds. OcNOS installs these rules directly in the ASIC hardware, where they drop or rate-limit matching traffic at full line rate — with zero CPU overhead.
FastNetMon 如何與 OcNOS 整合,響應速度如何?
FastNetMon receives sFlow, NetFlow v5/v9, or IPFIX telemetry from OcNOS interfaces and continuously analyzes traffic against configurable per-host and per-subnet thresholds. When an anomaly exceeds the threshold — for example, a UDP flood exceeding 5 Gbps to a single destination — FastNetMon automatically triggers either a BGP Flowspec rule (for surgical, protocol-specific mitigation) or an RTBH blackhole route (for full prefix blackholing) via BGP to OcNOS. The detect-to-mitigate loop is automated and typically completes in under 2 seconds.
本方案能檢測並緩解哪些類型的 DDoS 攻擊?
FastNetMon with OcNOS detects and mitigates the most common DDoS attack types: volumetric floods (UDP amplification, ICMP flood, raw bandwidth saturation), protocol attacks (SYN flood, TCP RST flood, fragmented packet attacks), and application-layer attacks detectable by flow analysis (DNS query floods, NTP amplification, Memcached amplification). BGP Flowspec can match on protocol, port, TCP flags, and fragment type for precise surgical mitigation. For volumetric attacks where precision is less important than speed, RTBH blackholing drops all traffic to the targeted prefix at the network edge.
OcNOS 能在沒有 FastNetMon 的情況下進行 DDoS 緩解嗎?
Yes. OcNOS provides three independent DDoS mitigation mechanisms that work without FastNetMon: static hardware ACLs (ASIC-accelerated, zero CPU overhead) for permanent blocking of known bad actors; manual RTBH blackholing via BGP for operator-triggered prefix blackholing; and reception of BGP Flowspec rules from any standard BGP speaker. Operators with existing detection platforms — Arbor/Netscout, A10 Networks, Cloudflare Magic Transit, or Kentik — can use OcNOS as the enforcement plane, receiving Flowspec or RTBH commands from their existing detection system.
RTBH 黑洞是什麼,什麼情況下應使用它而非 Flowspec?
RTBH (Remotely Triggered Black Hole) blackholing works by advertising the targeted destination prefix via BGP with a next-hop pointing to a discard interface. All upstream routers that receive the RTBH advertisement will drop all traffic destined for that prefix at their edge — stopping attack traffic before it enters your network. RTBH is the right choice for high-volume volumetric attacks where stopping all traffic to a destination (including legitimate traffic) is acceptable to protect the rest of the network. BGP Flowspec is preferable when you need surgical mitigation — for example, blocking only UDP port 53 to a destination while allowing TCP traffic through. In practice, operators often start with RTBH for speed and switch to Flowspec for precision once the attack is characterized.
通過 OcNOS 在網內進行 DDoS 緩解能否替代清洗中心?
In-network mitigation complements or partially replaces scrubbing centers depending on the attack type and scale. For volumetric attacks targeting your own prefixes, OcNOS with FastNetMon provides faster response (sub-2-second) at lower cost than routing traffic through a scrubbing center — because the filtering happens in-line at the network edge in hardware ASICs. For very large attacks that saturate upstream links before reaching your routers, upstream RTBH with your transit providers combined with in-network Flowspec is the most effective approach. Managed DDoS service providers can also use OcNOS as the per-customer enforcement plane for per-customer Flowspec rules and thresholds.
獲得保護

在開放硬體上守護您的網路。

與我們的安全與網路專家對話:我們會帶您梳理拓撲結構、威脅模型,以及適合您環境的 Flowspec 與 RTBH 配置。

預約 DDoS 演示 下載 OcNOS VM