摘要
网络功能虚拟化(NFV)为服务链构建带来了灵活性与动态性,然而,软件化与虚拟化环境可能存在软件漏洞、后门等安全风险,对服务链(SC)的安全产生影响。为此,该文提出一种服务链上虚拟网络功能(VNF)调度方法。首先,为虚拟网络功能构建异构镜像池,避免利用共模漏洞的大范围攻击;随后,以特定周期选择服务链虚拟网络功能进行调度,加载异构镜像对该网络功能的执行实体进行替换;最后,考虑调度对网络功能性能的影响,应用斯坦科尔伯格博弈对攻防过程建模,以最优化防御者收益为目标求解服务链上各网络功能的调度概率。实验表明,该方法能够降低攻击者攻击成功率,同时将调度产生的开销控制在可接受范围内。
Network Function Virtualization(NFV)brings flexibility and dynamics to the construction of service chain.However,the software and virtualization may cause security risks such as vulnerabilities and backdoors,which may have impact on Service Chain(SC)security.Thus,a Virtual Network Function(VNF)scheduling method is proposed.Firstly,heterogeneous images are built for every virtual network function in service chain,avoiding widespread attacks using common vulnerabilities.Then,one network function is selected dynamically and periodically.The executor of this network function is replaced by loading heterogeneous images.Finally,considering the impact of scheduling on the performance of network functions,Stackelberg game is used to model the attack and defense process,and the scheduling probability of each network function in the service chain is solved with the goal of optimizing the defender’s benefit.Experiments show that this method can reduce the rate of attacker’s success while controlling the overhead generated by the scheduling within an acceptable range.
作者
季新生
徐水灵
刘文彦
仝青
李凌书
JI Xinsheng;XU Shuiling;LIU Wenyan;TONG Qing;LI Lingshu(National Digital Switching System Engineering & Technological R&D Center,Zhengzhou 450002,China)
出处
《电子与信息学报》
EI
CSCD
北大核心
2019年第10期2435-2441,共7页
Journal of Electronics & Information Technology
基金
国家自然科学基金(61521003,61602509)
国家重点研发计划项目(2016YFB0800100,2016YFB0800101)~~
关键词
网络功能虚拟化
服务链
网络安全
动态
异构
博弈论
Network Function Virtualization(NFV)
Service Chain(SC)
Cyber security
Dynamic
Heterogeneous
Game theory