期刊文献+

面向SDN/NFV环境的网络功能策略验证 被引量:2

Verification on policies for network functions in SDN/NFV-based environment
下载PDF
导出
摘要 SDN与NFV技术带来了网络管理的灵活性与便捷性,但SDN的动态转发策略可能导致网络功能策略失效,同时不同网络功能的策略可能互相影响,引起冲突问题。为了在基于SDN/NFV的云网络中对网络功能的策略进行验证,分析了网络功能与SDN设备之间、跨网络功能之间的策略冲突,建立了统一策略表达进行策略解析,设计策略验证方案、框架并进行原型实现,检验不同场景下的虚拟网络功能策略的正确性,并与现有策略冲突验证方案对比,用实验进行了有效性与性能分析。 Although the newly introduced SDN and NFV technologies bring flexibility and convenience in network management,the dynamic forwarding policies introduced by SDN may cause invalidation in the network function policies,and the policies in different network functions may also cause conflicts due to their own behaviors.In order to verify the policies in SDN/NFV-based cloud network,the verification on policies between the network function and the SDN device,as well as across the network functions were considered.A unified policy expression for analysis was summa-rized,and policy verification scheme,framework and prototype implementation were proposed to verify the correctness of polices in different scenarios,then experiments were conducted to justify the effectiveness and performance.
作者 陈浩宇 邹德清 金海 CHEN Haoyu;ZOU Deqing;JIN Hai(National Engineering Research Center for Big Data Technology and System,School of Computer Science and Technology,Huazhong University of Science and Technology,Wuhan 430074,China;Services Computing Technology and System Lab,School of Computer Science and Technology,Huazhong University of Science and Technology,Wuhan 430074,China;Cluster and Grid Computing Lab,School of Computer Science and Technology,Huazhong University of Science and Technology,Wuhan 430074,China;Hubei Engineering Research Center on Big Data Security,School of Cyber Science and Engineering,Huazhong University of Science and Technology,Wuhan 430074,China)
出处 《网络与信息安全学报》 2021年第3期59-71,共13页 Chinese Journal of Network and Information Security
基金 国家重点研发计划(2019YFB2101700) 广州市未来产业关键技术研发专题项目(201902020016)。
关键词 策略验证 云网络 软件定义网络 网络功能虚拟化 policy verification cloud network software-defined networking network function virtualization
  • 相关文献

参考文献3

二级参考文献20

  • 1TbomasDN.软件定义网络--SDN和OpenFlow解析.北京:人民邮电出版社.2014.
  • 2雷葆华.SDN核心技术剖析和实战指南.北京:电子工业出版社.2013.
  • 3VMware-NSX网络虚拟化设计指南.http://www.vmware.com/cn,2013.
  • 4https://www.opennetworking.org/.
  • 5Hu, Hongxin,Ahn, Gail-Joon,Kulkarni, Ketan.Detecting and Resolving Firewall Policy Anomalies[J]. EN . 2012 (3)
  • 6J. G. Alfaro,N. Boulahia-Cuppens,F. Cuppens.Complete analysis of configuration rules to guarantee reliable network security policies[J]. International Journal of Information Security . 2008 (2)
  • 7Gobjuka H,Ahmat K. A.Fast and Scalable Method for Resolving Anomalies in FirewallPolicies. IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS) . 2011
  • 8Al-Shaer, Ehab,Hamed, Hazem,Boutaba, Raouf,Hasan, Masum.Conflict classification and analysis of distributed firewall policies. IEEE Journal on Selected Areas in Communications . 2005
  • 9Hamed, Hazem,Al-Shaer, Ehab.Taxonomy of conflicts in network security policies. IEEE Communications Magazine . 2006
  • 10A.Westerinen,,J.Schnizlein,J.Strassner.Terminology for Policy based Management. RFC 3198 . 2001

共引文献43

同被引文献21

引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部