期刊文献+

一种软件定义网络的安全服务链动态组合机制 被引量:5

A Dynamic Composition Mechanism for the Security Service Chain Oriented Software Defined Networking
下载PDF
导出
摘要 网络安全功能与硬件设备的紧耦合关系,造成传统网络安全服务模式静态僵化,难以满足未来业务发展的多样化安全需求。为此,基于软件定义网络环境,该文提出一种灵活可配的安全服务链动态组合机制。首先,介绍了该机制的总体结构,并建立了基于向量空间和整数规划的组合模型。其次,设计了启发式算法进行模型求解,并构建了该机制的实现原型。最后,实验结果表明所提组合算法在性能指标上优于对比算法,并且试验验证了该机制的优势。 The close relationship between the network security function and the hardware devices causes the static rigidity of the traditional security service mode, which is difficult to meet the various security requirement of future network business development. Based on the features of the Software Defined Networking(SDN), a dynamic composition mechanism is proposed for the Composable Security Service Chain(CSSC). First, the overall framework is introduced, and a mathematical model about the composition problem is established by the vector space and integer programming. Then, a heuristic algorithm is designed for solving the model, and the prototype is achieved in SDN environment. Finally, the results of the experiments show that the proposed algorithm outperforms the compared ones, and the advantage of the CSSC is validated by the simulation.
出处 《电子与信息学报》 EI CSCD 北大核心 2016年第5期1234-1241,共8页 Journal of Electronics & Information Technology
基金 国家重点基础研究发展计划(2012CB315901 2013CB329104) 国家自然科学基金(61309019 61372121) 国家高技术研究发展计划(2013AA013505)~~
关键词 软件定义网络 安全服务 元能力 功能组合 Software Defined Networking(SDN) Security service Atomic ability Function composition
  • 相关文献

参考文献19

  • 1兰巨龙,程东年,胡宇翔.可重构信息通信基础网络体系研究[J].通信学报,2014,35(1):128-139. 被引量:61
  • 2PAUL S, PAN J L, and JAIN R. Architectures for the future networks and next generation internet: a survey[J]. Computer Communications, 2011, 34(1): 2-42. doi: 10.1016/j.comcom. 2010.08.001.
  • 3黄韬,刘江,霍如,魏亮,刘韵洁.未来网络体系架构研究综述[J].通信学报,2014,35(8):184-197. 被引量:78
  • 4张宏科,罗洪斌.智慧协同网络体系基础研究[J].电子学报,2013,41(7):1249-1254. 被引量:51
  • 5MCKEOWN N, ANDERSON T, BALAKRISHAN H, et al. OpenFlow: Enabling innovation in campus networks[J]. ACM SIGCOMM Computer Communication Review, 2008, 38(2): 69-74. doi: 10.1145/1355734.1355746.
  • 6左青云,陈鸣,赵广松,邢长友,张国敏,蒋培成.基于OpenFlow的SDN技术研究[J].软件学报,2013,24(5):1078-1097. 被引量:420
  • 7周烨,杨旭,李勇,苏厉,金德鹏,曾烈光.基于分类的软件定义网络流表更新一致性方案[J].电子与信息学报,2013,35(7):1746-1752. 被引量:17
  • 8CHIOSI M, CLARKE D, WILLIS P, et al. Network functions virtualization-introductory white paper[R]. SDN and OpenFlow World Congress, Germany, 2012.
  • 9SHIN S, PORRAS P, YEGNESWARAN V, et al. FRESCO: modular composable security services for software-defined networks[C]. Proceedings of the 20th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 2013: 1-16.
  • 10QAZI Z, TU C C, and CHIANG L. SIMPLE-fying middlebox policy enforcement using SDN[C]. Proceedings of the ACM SIGCOMM’13, Hong Kong, China, 2013: 27-38.

二级参考文献112

  • 1林闯,任丰原.可控可信可扩展的新一代互联网[J].软件学报,2004,15(12):1815-1821. 被引量:79
  • 2龚正虎,傅彬,卢泽新.软件集群路由器体系结构的研究[J].国防科技大学学报,2006,28(3):40-43. 被引量:5
  • 3张宏科,苏伟.新网络体系基础研究——一体化网络与普适服务[J].电子学报,2007,35(4):593-598. 被引量:125
  • 4Mckeown N, Anderson T, Balakrishnan H, Parulkar G, Peterson L, Rexford J, Shenker S, Turner J. OpenFlow: Enabling innovation in campus networks. ACM SIGCOMM Computer Communication Review, 2008,38(2):69-74. [doi: 10.1145/1355734. 1355746].
  • 5Elliott C. GENI: Opening up new classes of experiments in global networking. IEEE Internet Computing, 2010,14(1):39-42.
  • 6Gavras A, Karila A, Fdida S, May M, Potts M. Future Internet research and experimentation: The FIRE initiative. ACM SIGCOMM Computer Communication Review, 2007,37(3):89-92. [doi: 10.114511273445.1273460].
  • 7JGN2plus. 2012. http://www.jgn.nict.go.jp/english/index.html.
  • 8SOFIA. 2012. http://fi.ict.ac.cn/research/sofia_overview.htm.
  • 9Yang L, Dantu R, Anderson T, Gopal R. Forwarding and Control Element Separation (ForCES) Framework. RFC 3746, 2004. http://tools.ietf.org/html/rfc3746.
  • 10Greenberg A, Hjalmtysson G, Maltz DA, Myers A, Rexford J, Xie G, Yan H, Zhan J, Zhang H. A clean slate 4D approach to network control and management. ACM SIGCOMM Computer Communication Review, 2005,35(5):41-54. [doi: 10.1145/1096536. 1096541].

共引文献586

同被引文献15

引证文献5

二级引证文献18

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部