GA/T 1714-2020 in English
VALIDInformation security technology—Security technology requirements for flow anomaly detection and cleaning products
- Issued on:2020-03-06
- Implemented on:2020-05-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$214.00
本标准规定了异常流量检测和清洗产品的安全功能要求、自身安全功能要求和安全保障要求及等级划分要求,适用于异常流量检测和清洗产品的设计、开发与测试。
Introduction
Interpretation of the standard technical framework
This standard constructs a three-layer technical architecture including the abnormal traffic detection system, the cleaning system and the management center, and uses deep flow detection technology to identify and deal with common DDoS attacks such as SYN Flood and UDP Flood.
Analysis of core functional requirements
| Functional modules | Basic level requirements | Enhanced level requirements |
|---|---|---|
| Traffic collection | Support NetFlow/sFlow | Need to support 3+ protocols such as IPFIX |
| Attack identification | Signature library matching | Add self-learning algorithm |
| Cleaning capability | Basic filtering | Support GRE/MPLS injection |
Key technology implementation
Deep Flow Inspection Technology
By analyzing 12 core indicators such as the five-tuple, message size, and flow rate in NetFlow messages, combined with the sliding time window algorithm, sub-second attack identification is achieved.
BGP diversion mechanism
Enhanced products require automatic linkage with routers. When an attack occurs, the traffic is diverted to the cleaning center through BGP protocol updates, and the typical convergence time is ≤30 seconds.
Implementation Recommendations
- Deployment Architecture: It is recommended to adopt dual-machine hot standby deployment at the backbone network egress, and 50% performance margin should be reserved for cleaning capabilities
- Policy Configuration: The baseline learning cycle is recommended to be ≥7 days, and the SYN Flood threshold should be set lower than 120% of the business peak traffic
- Compliance Verification: It is required to pass the Level 3 Security Protection Test of the Computer Information System Security Product Quality Supervision and Inspection Center of the Ministry of Public Security
Standard Evolution Analysis
This standard incorporates machine learning technology into the specification system for the first time, and achieves breakthroughs in the following aspects compared to the 2015 version of GB/T 18336:
- Added requirements for abnormal traffic detection in IPv6 environments
- Cleared security audit specifications for API interfaces
- Strengthened supply chain security management clauses

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GA 1182-2014 in English
synthetic capsaicin
2014-08-28 -

GA 629.4-2004 in English
Database specification for national traffic management information-Part 4:Database specification for accident statistics information
2004-02-13