About This Architecture
SDN threat mitigation framework using Ryu controller and OpenFlow rules to detect and block DDoS attacks in SOHO networks. Traffic flows from external gateways through an SDN switch to internal hosts (PCs, IoT devices), while the control plane monitors statistics and triggers anomaly detection. The threat detection engine analyzes baseline traffic patterns, and when anomalies exceed thresholds, the mitigation engine installs blocking rules via OpenFlow. This architecture demonstrates how software-defined networking enables dynamic, policy-driven security responses without manual firewall reconfiguration. Fork this diagram on Diagrams.so to customize threat thresholds, add WAF rules, or integrate with your SIEM platform.