摘要
现有互联网安全体系结构僵化且效率低下。基于"以可变的有限节点资源支持多样安全应用需求、以内置的安全结构提供多级安全保障"这一认识,避免单一追求高安全等级或高服务质量的简单模式,提供更高的灵活性和可扩展性,提出一种基于重构的安全业务—服务—构件模型,并在此基础上给出可重构网络安全体系的初步构想和具有多级安全保障的可重构安全承载网络结构,给出了可重构安全承载网络构建及重构算法。仿真结果验证了算法的有效性和性能。
Current Internet security architecture is fixed and exhibits low efficiency. Based on the thinking of "supporting di- verse security applications with the variable limited node resources and providing multilevel security guarantee by inherent se- curity architecture", avoiding limitations of traditional model aiming at pursuing high security quality of service and ensuring security by providing more flexibility and scalability, this paper first presented a network reconfiguration-oriented security busi- ness-services-components model, and gave a preliminary conception of reconfigurable network security architecture as well. Then this paper proposed a novel security structure which was named reconfigurable security carrying network ( RSCN for short) to provide muhilevel security guarantee. At last, it gave the construction algorithm and reconstruction algorithm of RSCN. The simulation results show that the algorithms are effective.
出处
《计算机应用研究》
CSCD
北大核心
2014年第4期1167-1171,共5页
Application Research of Computers
基金
国家"973"计划资助项目(2012CB315901
2013CB329104)
国家"863"计划资助项目(2011AA01A103
2011AA01A101
2013AA013505)
国家科技支撑计划资助项目(2011BAH19B01)
关键词
可重构网络
安全组合
多级安全
构建与重构
安全构件
reconfigurable network
security composition
multi-level security
construction and reconfiguration
security components