OcNOS-SP · FastNetMon · BGP Flowspec · RTBH

在您自己的网络中,2 秒内发现并阻止 DDoS 攻击。

OcNOS 与 FastNetMon 结合后,可在网络边缘直接实现自动化 DDoS 检测与缓解——无需清洗中心,无需云端引流,也不会增加时延。攻击通过 sFlow/NetFlow 遥测检出,并在 ASIC 硬件中以线速完成缓解。

为何选择网络内 DDoS 缓解?

清洗中心增加延迟和成本。硬件级 Flowspec 两者都不增加。

传统 DDoS 防护会将所有流量绕行至旁路清洗中心——即便在正常运行时也会让每个数据包额外引入 10–50 ms 时延,并按 Gbps 收取清洗容量费用。这一模式在攻击较少、检测较慢的年代是合理的。

如今的攻击更快、更大、更频繁。 OcNOS 与 FastNetMon 将检测与缓解逻辑直接置于网络边缘: sFlow/NetFlow 遥测持续从 OcNOS 流向 FastNetMon;一旦检测到攻击,FastNetMon 将 BGP Flowspec 规则推送回 OcNOS;OcNOS 在线速下将规则安装到 ASIC 硬件中。整个回路在 2 秒内完成 — 且对正常流量没有任何额外时延。

可检测并缓解的攻击类型:

UDP 放大 SYN Flood TCP RST Flood ICMP Flood DNS 查询泛洪 NTP 放大 Memcached 反射攻击 容量型带宽饱和 分片包攻击

FastNetMon 集成 — 生产级 DDoS 检测引擎

FastNetMon Advanced 是被全球数百家 ISP 与托管服务商采用的生产级 DDoS 检测系统:可消费来自 OcNOS 的 sFlow、NetFlow v5/v9、IPFIX 及端口镜像流量,并按可配置的主机/子网阈值自动触发缓解动作。

BGP Flowspec (RFC 5575) — 精准流量过滤

可按源/目的 IP、协议、端口、包长、TCP 标志、DSCP 与分片类型匹配并过滤攻击流量。规则通过 BGP 下发并在毫秒级内装载到 ASIC 硬件——以线速过滤、零 CPU 开销,可对匹配流量进行丢弃、限速或重定向。

RTBH 黑洞 — 快速直接的防护

面向大规模流量型攻击的 BGP 黑洞路由:可由客户主动触发,也可在流量超阈值时由 FastNetMon 自动触发。RTBH 路由会传播至上游对等和中转运营商,将攻击流量阻挡在进入您的网络之前。

sFlow & NetFlow 遥测 — 持续流量可视化

OcNOS 在所有边缘接口上导出 sFlow(RFC 3176)、NetFlow v5/v9 与 IPFIX——采样由硬件加速且采样率可配置。可同时为 FastNetMon 提供 DDoS 检测数据,并向 Kentik、PRTG、Prometheus 或任意流量采集器输出流量分析数据。

硬件 ACL 过滤 — 静态、零 CPU 阻断

ASIC 加速的访问控制列表可永久阻断已知恶意主体——按特定 IP、子网、协议或端口实施。可按接口、VLAN 或前缀进行限速;一次配置即在硬件中永久执行,不增加任何路由或处理开销。

FastNetMon → OcNOS — 自动响应 警报
1 — FastNetMon 通过 sFlow 检测异常
警报 UDP 洪水 → 203.0.113.50
14 Gbps — 已超过 5 Gbps 阈值
2 — FastNetMon 将 BGP Flowspec 推送至 OcNOS
POST /api/flowspec/rule
match: dst 203.0.113.50/32 proto UDP
action: rate-limit 100Mbps
→ 规则已安装到 ASIC:0.8 秒
3 — OcNOS 在硬件中以线速强制执行
Flowspec 规则已启用 14
已丢弃(攻击) 2.4M pps
速率限制 180K pps
✓ 正常流量正常通过

FastNetMon — 检测引擎

FastNetMon Advanced 是被全球数百家 ISP 采用的专用 DDoS 检测引擎,可通过 BGP Flowspec 与 RTBH 与 OcNOS 原生集成,支持 sFlow、NetFlow 与 IPFIX,并可按主机、子网、协议分别配置阈值。

了解 FastNetMon →
<2s
检测到缓解的闭环 — 从 sFlow 异常到硬件中的 Flowspec 规则
0ms
对正常流量无附加时延 — 过滤在线性 ASIC 中完成,而非旁路清洗器
0%
硬件 ACL 与 Flowspec 执行的 CPU 开销 — 由 ASIC 加速
600+运营商部署
60+国家
26网络领域年数
参考架构

In-network DDoS detection and mitigation — full topology

A complete picture of where each protection layer sits. Attack traffic from the internet hits the OcNOS edge routers, where sFlow telemetry continuously feeds FastNetMon. When FastNetMon detects an anomaly, it pushes BGP Flowspec or RTBH back to the edge — installed in ASIC hardware in milliseconds. Upstream peers can also receive RTBH announcements to drop attack traffic before it reaches your network.

In-network DDoS protection topology with OcNOS edge and FastNetMon Attack traffic from botnet sources transits an upstream peer to two OcNOS-SP edge routers. The edge routers export sFlow and NetFlow telemetry to a FastNetMon detection engine. When an attack is detected, FastNetMon pushes BGP Flowspec or RTBH routes back to the edge routers via BGP, installing rules in the ASIC for line-rate filtering. Clean traffic continues to the protected customer or data center network. The upstream peer can also receive RTBH announcements over BGP to drop attack traffic before it ingresses the protected network. Attackers distributed botnet 10–100 Gbps Customers legitimate traffic HTTP/DNS/SSH Transit Peer eBGP / RTBH recv Tier-1 Internet RTBH /32 drops OcNOS Edge-01 UfiSpace S9600-72XC Qumran-AX · 4.8 Tbps ASIC HARDWARE Flowspec + ACL drop line-rate · 0% CPU OcNOS Edge-02 UfiSpace S9600-72XC ECMP redundant ASIC Flowspec + ACL attack + clean FastNetMon Detection Engine sFlow + NetFlow analysis < 1s threshold detect sFlow ↑ BGP Flowspec ↓ + RTBH RTBH propagated upstream over eBGP → Protected Servers DC / hosted infra clean traffic only · 0ms added Customer Networks per-tenant policy managed DDoS service clean ✓ attack drop DETECT-TO-MITIGATE LOOP 1. Anomaly detected FastNetMon: <1s 2. BGP Flowspec push FNM → OcNOS: ~200ms 3. ASIC rule installed OcNOS hardware: ~800ms 4. Attack dropped at line rate total loop: <2s · 0ms clean-traffic latency
Attack traffic
Clean traffic
sFlow / NetFlow telemetry
BGP Flowspec / RTBH (control plane)
↳ hover any node for platform, ASIC, BGP, and policy detail
工作原理

从攻击检测到流量阻断 — 四步

从检测到缓解的整个闭环已实现自动化,一经配置即无需人工干预便可阻断攻击。

1

收集

OcNOS 将所有边缘接口的 sFlow 与 NetFlow 遥测导出到 FastNetMon。包采样由硬件加速完成——无 CPU 开销,不影响转发性能。

2

检测

FastNetMon 按主机与子网阈值分析流数据,通常可在 1 秒内识别出流量型洪水、SYN 风暴、UDP 放大、DNS 洪水以及 NTP 反射攻击。

3

信号

FastNetMon 通过 BGP 自动向 OcNOS 下发 BGP Flowspec 规则(用于精细缓解)或 RTBH 黑洞路由(用于流量型攻击)。全程自动——攻击期间无需运维人员干预。

4

缓解

OcNOS 将 Flowspec 规则或 RTBH 路由直接安装到 ASIC 硬件中。攻击流量在全线速下被丢弃或限速。正常流量不受影响地继续传输。攻击结束后规则自动移除。

使用案例

OcNOS 的 DDoS 防护适用场景

OcNOS DDoS 防护适用于任何在网络边缘运行开放硬件的运营商——从小型 ISP 到大型数据中心运营商均可使用。

🌐

ISP & SP 边缘防护

保护对等边缘和中转链路免受会饱和面向客户带宽的流量型 DDoS:在对等路由器进行 sFlow 检测并自动通过 BGP Flowspec 缓解,可在洪水到达下游客户前阻断;与中转运营商协调上游 RTBH,则可在攻击进入您的网络前就将其挡在门外。

🏢

数据中心边界

在数据中心边界进行直连 DDoS 过滤——保护托管基础设施与云工作负载:静态硬件 ACL 永久阻断已知恶意主体;动态 Flowspec 规则实时适应新攻击特征;流量无需绕行清洗中心,因此对正常流量零时延影响。

🛡️

托管 DDoS 防护服务

运营商可按受保护前缀计费,将基于客户的 DDoS 防护作为托管服务对外提供:FastNetMon 支持每客户阈值方案,OcNOS 按客户执行 Flowspec 规则——无需共享清洗基础设施,每位客户的防护都是网内专属的。

常见问题

使用 OcNOS 的 DDoS 防护 — 常见问题

BGP Flowspec 是什么,OcNOS 如何用于 DDoS 缓解?
BGP Flowspec (RFC 5575) is a BGP extension that distributes granular traffic filtering rules across routers — similar to pushing ACLs via BGP, but with more granular match conditions. OcNOS supports Flowspec matching by source IP, destination IP, protocol, source/destination port, packet length, TCP flags, DSCP, and IP fragment type. When FastNetMon detects an attack, it pushes Flowspec rules to OcNOS via BGP in milliseconds. OcNOS installs these rules directly in the ASIC hardware, where they drop or rate-limit matching traffic at full line rate — with zero CPU overhead.
FastNetMon 如何与 OcNOS 集成,响应速度如何?
FastNetMon receives sFlow, NetFlow v5/v9, or IPFIX telemetry from OcNOS interfaces and continuously analyzes traffic against configurable per-host and per-subnet thresholds. When an anomaly exceeds the threshold — for example, a UDP flood exceeding 5 Gbps to a single destination — FastNetMon automatically triggers either a BGP Flowspec rule (for surgical, protocol-specific mitigation) or an RTBH blackhole route (for full prefix blackholing) via BGP to OcNOS. The detect-to-mitigate loop is automated and typically completes in under 2 seconds.
本方案能检测并缓解哪些类型的 DDoS 攻击?
FastNetMon with OcNOS detects and mitigates the most common DDoS attack types: volumetric floods (UDP amplification, ICMP flood, raw bandwidth saturation), protocol attacks (SYN flood, TCP RST flood, fragmented packet attacks), and application-layer attacks detectable by flow analysis (DNS query floods, NTP amplification, Memcached amplification). BGP Flowspec can match on protocol, port, TCP flags, and fragment type for precise surgical mitigation. For volumetric attacks where precision is less important than speed, RTBH blackholing drops all traffic to the targeted prefix at the network edge.
OcNOS 能在没有 FastNetMon 的情况下进行 DDoS 缓解吗?
Yes. OcNOS provides three independent DDoS mitigation mechanisms that work without FastNetMon: static hardware ACLs (ASIC-accelerated, zero CPU overhead) for permanent blocking of known bad actors; manual RTBH blackholing via BGP for operator-triggered prefix blackholing; and reception of BGP Flowspec rules from any standard BGP speaker. Operators with existing detection platforms — Arbor/Netscout, A10 Networks, Cloudflare Magic Transit, or Kentik — can use OcNOS as the enforcement plane, receiving Flowspec or RTBH commands from their existing detection system.
RTBH 黑洞是什么,什么情况下应使用它而非 Flowspec?
RTBH (Remotely Triggered Black Hole) blackholing works by advertising the targeted destination prefix via BGP with a next-hop pointing to a discard interface. All upstream routers that receive the RTBH advertisement will drop all traffic destined for that prefix at their edge — stopping attack traffic before it enters your network. RTBH is the right choice for high-volume volumetric attacks where stopping all traffic to a destination (including legitimate traffic) is acceptable to protect the rest of the network. BGP Flowspec is preferable when you need surgical mitigation — for example, blocking only UDP port 53 to a destination while allowing TCP traffic through. In practice, operators often start with RTBH for speed and switch to Flowspec for precision once the attack is characterized.
通过 OcNOS 在网内进行 DDoS 缓解能否替代清洗中心?
In-network mitigation complements or partially replaces scrubbing centers depending on the attack type and scale. For volumetric attacks targeting your own prefixes, OcNOS with FastNetMon provides faster response (sub-2-second) at lower cost than routing traffic through a scrubbing center — because the filtering happens in-line at the network edge in hardware ASICs. For very large attacks that saturate upstream links before reaching your routers, upstream RTBH with your transit providers combined with in-network Flowspec is the most effective approach. Managed DDoS service providers can also use OcNOS as the per-customer enforcement plane for per-customer Flowspec rules and thresholds.
获得保护

在开放硬件上守护您的网络。

与我们的安全与网络专家对话:我们会带您梳理拓扑结构、威胁模型,以及适合您环境的 Flowspec 与 RTBH 配置。

预约 DDoS 演示 下载 OcNOS VM