摘要
针对当前基于SDN的网络入侵阻断系统HYDRA的不足,设计并实现了基于SDN技术的网络入侵追踪与响应系统。新系统将控制逻辑和响应逻辑解耦,提高系统的可扩展性。控制层改进任务调度模型,提高系统的顽健性。完善的系统接口规范提高系统可用性。对RYU控制器的研究和改进进一步挖掘控制器潜力,使系统与SDN联系更加紧密。
In view of the shortcomings of the current network intrusion blocking system based on SDN,the network intrusion tracking and response system based on SDN technology was designed and implemented.The logic and response logic were decoupled,and the scalability of the system was improved.The task scheduling model and the robustness of the system were improred.Perfect system interface specification improves the availability of system.The research and improvement of RYU controller further explore the potential of the controller,so that the system is more closely related to SDN.
作者
程俊
龚俭
杨望
臧小东
CHENG Jun;GONG Jian;YANG Wang;ZANG Xiaodong(School of Cyber Science and Engineering,Southeast University,Nanjing 211189,China)
出处
《通信学报》
EI
CSCD
北大核心
2018年第A01期244-250,共7页
Journal on Communications
基金
赛尔网络下一代互联网技术创新资助项目(No.NGII20160409)~~
关键词
软件定义网络
入侵追踪
可扩展性
规范接口
software define network(SDN)
intrusion traceback
scalability
specification interface