期刊文献+

基于LE-Trie的SDN访问控制策略研究 被引量:1

SDN access control strategy based on LE-Trie
原文传递
导出
摘要 为解决SDN(software defined networks)网络面临的网络安全问题,提出了基于集中控制思想的访问控制策略,将访问控制规则下发到源交换机,由此可以在源头上抑制无效的数据流。通过采用区间值起止点的最大公共前缀作为构建LE-Trie的基本元素,解决了IP地址和端口的区间无法在树中进行构造的问题。在此基础上,提出了基于多区域LE-Trie(multi-area-domain LE-Trie MADLT)的规则检测和匹配方法。该算法将对规则的顺序匹配转化为对多域的匹配,减少了匹配次数,从而提高了访问控制服务器的工作效率。对比实验结果表明,在进行冲突检测时,MADLT在时间性能上较顺序算法平均提高2.97倍,较传统Trie算法平均提高30.4%;在进行规则匹配时,MADLT在时间性能上较顺序算法平均提高2.3倍,较传统Trie算法平均提高16.3%。由此证明,本文提出的集中访问控制策略可以有效地实现SDN网络中的数据访问控制。 In order to solve the network security problems facing SDN network,This paper proposes an access control strategy based on the centralized idea. The access control rules are deployed to source switches,so as to control the invalid dataflow from its source nodes. The maximum public prefix value of interval's starting and ending point is used to build LE-Trie as basic element,which solves the problem that the IP and port range cannot be constructed in the tree. On this basis,this paper proposes detection and matching algorithm of rule named multi-area-domain LE-Trie( MADLT). It changes the method of sequence matching into Multi-domain matching and reduces the number of matching,so as to improve the working efficiency of the access control server. Contrast experimental results demonstrate that,in collision rules detection,the MADLT algorithm is 2. 97 times than that of sequence algorithm in time performance,and increased by 30. 4% than that of traditional Trie algorithm in collision detection. In rule matching,MADLT is 2. 3 times higher on average than sequence algorithm and increased by 16. 3% than that of traditional Trie algorithm in time performance. Thus,the centralized access control strategy in this paper can effectively realize the data access control of SDN network.
出处 《重庆邮电大学学报(自然科学版)》 CSCD 北大核心 2015年第5期674-682,共9页 Journal of Chongqing University of Posts and Telecommunications(Natural Science Edition)
基金 国家自然科学基金项目(61370139) 网络文化与数字传播北京市重点实验室资助项目(ICDD201309) 北京市属高等学校创新团队建设与教师职业发展计划项目(IDHT20130519)~~
关键词 软件定义网络 LE-Trie 访问控制策略 访问控制规则匹配 software defined networks LE-Trie access control strategy access control rules matching
  • 相关文献

参考文献16

  • 1ONF. Software-Defined Networking: the New Norm for Networks[EB/OL]. [2015-05-04]. http://wenku.baidu.com/view/74cbdflac281e53a5802ffa7.html.
  • 2SHIN Seungwon, PHIL P, VINOD Y. FRESCO: Modular Composable Security Services for Software-Defined Networks[C]//Proceedings of Network and Distributed Security Symposium. San Diego: Internet Society , 2013: 135-139.
  • 3KANG Nanxi, REXFORD R, WALKER D. Policy Transformation in Software Defined Networks[C]// ACM SIGCOMM Computer Communication Review-Special october issue. New York: ACM Special Interest Group on Data Communication, 2012(12): 309-310.
  • 4YOUNA J, JAMES B D. CRiBAC: Community-centric role interaction based access control model Computers Security[J]. computer & secturity, 2012, 31(4): 497-523.
  • 5邓文洋,周洲仪,林思明,刘金刚.开放式环境下一种基于信任度的RBAC模型[J].计算机工程,2013,39(2):112-118. 被引量:8
  • 6殷晓玲,夏启寿,王汝传.Web Services中基于信任的动态访问控制[J].计算机应用研究,2011,28(11):4331-4334. 被引量:5
  • 7KRAUTSEVICH L, LAZOUSKI A, MARTINELLI F. Risk-aware Usage Decision Making in Highly Dynamic Systems[C]// The Fifth Internet Monitoring and Protection. Barcelona, Spain: IEEE press, 2010: 29-34.
  • 8初晓博,秦宇.一种基于可信计算的分布式使用控制系统[J].计算机学报,2010,33(1):93-102. 被引量:21
  • 9苏铓,李凤华,史国振.基于行为的多级访问控制模型[J].计算机研究与发展,2014,51(7):1604-1613. 被引量:17
  • 10李中,李晓.一种性能优化的防火墙规则匹配算法[J].计算机应用研究,2013,30(4):1205-1207. 被引量:3

二级参考文献163

共引文献148

同被引文献9

引证文献1

二级引证文献21

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部