Location:Home > Product Center >Detection of defensive >

Denial of service system


       DDoS (Distributed "of the Service) Distributed Denial of Service is one of the most common network attack. Criminals control to attack the goal of a large number of hosts on the Internet, send a lot of attack message link block the attack system, the application server, firewall and other facilities resources are exhausted. DDoS attacks in recent years, showing a large flow, high frequency, complicate and industrialization, the development trend of DDoS attacks intensified in the global scope.



       Popular against DDoS attacks, and new forms of attack, green unita since 2001 MB protective green alliance against denial of service System (NSFOCUS Anti - DDoS System, hereinafter referred to as NSFOCUS ADS), has continued since many years research and publish the DDoS resistant products for different industry, a variety of models to meet different needs. NSFOCUS ADS can be found in time attack behavior of background traffic, and quick to attack traffic filtering, protect the normal business operations. The product can be deployed in multiple network environments easily.

Product Detail

Product advantage



Attack traffic identification precision


Application of independent research and development of resistance to denial of service attack algorithm, aiming at different kinds of DDoS attacks using different algorithms (such as flow modeling, deceives, protocol stack behavior pattern analysis, specific application protection, user behavior analysis, dynamic fingerprint identification, etc.) to identify and differentiate and accurate between malicious DDoS message. The attack detection and recognition algorithm efficiency is very high, can withstand all kinds of large flow DDoS attacks, the Syn Flood protection, for example, retention and new connections availability of up to 100%.


Powerful attack prevention ability


Based on independent research and development of science and technology to create a unique green union protection algorithm, green alliance against denial of service attack system can be effective protection of various types of DDoS attacks: there are three kinds of transport layer DDoS protection SYN Flood protection algorithm, two kinds of ACK Flood protection mode, multiple protection strategy of ICMP and UDP, etc; Application layer DDoS protection has six kinds of HTTP Get Flood protection algorithm, the HTTP Post Flood and HTTPS protection algorithm, three kinds of DNS Flood protection algorithm, etc.



NSFOCUS ADS system also has a lot of traffic filtering strategy: support based on black and white list, ACL, regular rule, reflection, the protective rules, pattern matching, GeoIP cloud IP reputation protection strategy such as cleaning.



For many operators in the network client, and the characteristics of the different demand for DDoS protection, ADS equipment to provide protection groups, grouping for users, and for different user groups to provide fine-grained protection strategy. At the same time, in order to reduce the cost of operations, ADS equipment capable of protection objects of various service flow for automatic learning, and the strategies of protection was generated according to the results of the study.



Green science and technology have a security and defense technology research team, can timely find new DDoS attack type, can in the new attack within a week to upgrade protection software; Hardware system also has good expansibility.


T attack protection performance


Depending on the type, the telecommunication level high-end NSFOCUS ADS system adopts advanced multicore processor hardware architecture respectively. Single equipment can have up to 320 GBPS flow of velocity analysis and the DDoS attack protection ability, support for multiple devices at the same time through the BGP routing expansion in the form of load balancing and portchannel realize T level protection.


Flexible ways of application deployment


Due to different customers and scale of the network environment, green alliance against denial of service attack system also contains a variety of product configuration and deployment, including series, bypass and different ways, such as bypass cluster.



In view of the small and medium-sized enterprise customer green unita also provides local protection + cloud cleaning solution. Customers through the local deployment of small flow attack ADS equipment cleaning and fine protection, when attack traffic over the bandwidth load, a key protection notice the cloud cleaning center, from






Mixed cleaning

The local cleaning equipment ADS with the black cloud the CCSS form mixed against DDoS attack protection scheme. Local protection independently controllable, satisfy the requirement of the diversified strategy configuration; Cloud wash protective blessings, 

rapid response to the super flow attack, solve the export bandwidth congestion plight; Further combining with MSS can manage security service, the customer can release the pressure of safety operation.





Value-added operating

Moving cloud platform and traffic detection of cleaning, cleaning equipment completely docking, realize the unity of the whole amount of cleaning equipment within the network scheduling, centralized management, to provide their own staff and customers 

rapid monitoring, quick decision-making ability of cleaning. To customer management of the network client, value-added network security management, statistics. The cloud and mobile client collaborative cleaning customer perceived DDoS attacks, independent

 decisions.






Show