A system architecture for thwarting denial of service attacks on a victim data
center is described. The system includes a first plurality of monitors that monitor
network traffic flow through the network. The first plurality of monitors is disposed
at a second plurality of points in the network. The system includes a central controller
that receives data from the plurality of monitors, over a hardened, redundant network.
The central controller analyzes network traffic statistics to identify malicious
network traffic. In some embodiments of the system, a gateway device is disposed
to pass network packets between the network and the victim site. The gateway is
disposed to protect the victim site, and is coupled to the control center by the
redundant hardened network.