期刊文献+

DDoS攻击下基于SDN的工业控制系统边云协同信息安全防护方法 被引量:5

Edge-Cloud Synergy Information Security Protection Method for Industrial Control System Based on SDN Under DDoS Attack
下载PDF
导出
摘要 软件定义网络(software-defined network,SDN)是一种新型网络架构,其特点是控制与转发分离并支持通过编程的方式对网络进行控制・SDN与工业控制系统的结合为解决工业控制系统信息安全问题提供了新的思路,同时也使得DDoS攻击成为工业控制系统网络的主要安全威胁.过载攻击作为一种转换的DDoS攻击,利用SDN控制器及交换机中负载受限这一漏洞,对整个SDN网络造成威胁.与此同时,由于SDN网络业务需求量的不断增长和网络应用的多样性,SDN网络规模正在由初期的单一控制器网络逐步向多控制器网络转变•面对日益复杂的网络规模,在边缘端资源受限的情况下难以进行有效防御.针对上述问题,利用云端资源优势,基于SDN网络,并结合端址跳变和负载均衡算法提出一种工业控制系统边云协同信息安全防护方法,有效防御DDoS攻击. Software-defined network(SDN)is a new type of network architecture,which is characterized by the separation of control and forwarding and supports programmatic control of the network.The combination of SDN and industrial control systems provides new ideas for solving the information security problems of industrial control systems,while also making DDoS attacks a major security threat to industrial control system networks.As a converted DDoS attack,overload attack uses the vulnerability of limited load in SDN controllers and switches to pose a threat to the entire SDN network.At the same time,due to the continuous growth of SDN network service demand and the diversity of network applications,the scale of SDN network is gradually changing from the initial single-controller network to the multi-controller network.Facing the increasingly complex network scale,it is difficult to effectively defend the attacks when resources on the edge are limited.Therefore,based on SDN network,this article proposes an edge-cloud synergy information security protection method for industrial control system to effectively defend against DDoS attacks,which uses the resource advantage of cloud computing and combines with port and address hopping and load balancing algorithms.
作者 叶鑫豪 周纯杰 朱美潘 杨健晖 Ye Xinhao;Zhou Chunjie;Zhu Meipan;Yang Jianhui(School of Artificial Intelligence and Automation,Huazhong University of Science and Technology,Wuhan 430074)
出处 《信息安全研究》 2021年第9期861-870,共10页 Journal of Information Security Research
基金 国家自然科学基金项目(61873103)
关键词 DDOS攻击 软件定义网络 边云协同 工业控制系统 信息安全 DDoS attacks software-defined network edge-cloud synergy industrial control system information security
  • 相关文献

参考文献13

二级参考文献86

  • 1李蕊,李跃,姜臻,赵雅囡,徐浩,刘海涛,王鹏.一种能有效满足重要用户高可靠性需求的新型供电系统保护方向元件[J].中国电机工程学报,2013,33(S1):98-105. 被引量:3
  • 2袁皓,杨晓懿.信息安全模型安全控制研究[J].信息安全与通信保密,2007,29(2):78-80. 被引量:6
  • 3Wen Xitao, Chen Yan, Hu Chengchen, Shi Chao. Towards a secure controller platform for OpenFlow applications//Proceedings of the ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking (HotSDN13). Hong Kong, China, 2013:171-172.
  • 4Kreutz D, Ramos F, Verissimo P. Towards secure and dependable software-defined networks//Proceedings of the ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking (HotSDN13). Hong Kong, China, 2013:55-60.
  • 5Kazemian P, Varghese G, McKeown N. Header space analysis: Static checking for networks//Proceedings of the 9th USENIX Symposium on Network Systems Design and Imple- mentation (NSDI). San Jose, USA, 2012:3-5.
  • 6Kazemian P, Chang M, Zeng Hongyi. Real time network policy checking using header space analysis//Proceedings of the 9th USENIX Symposium on Network Systems Design and Implementation (NSDI). Lombard, USA, 2013.. 4-6.
  • 7Porras P, Shin S, Yegneswaran V, Fong M. A security enforcement kernel for OpenFlow networks//Proceedings of the ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking (HotSDN2012). New York, USA, 2012:123-125.
  • 8Sherwood R, Gibb G, Yap K K, et al. FlowVisor: A network virtualization layer. OpenFlow Switch Consortium, CA, USA: OPENFLOW-TR-2009-1, 2009.
  • 9Son S, Shin S, Yegneswaran V, Porras P. Model checking invariant security properties in OpenF|ow//Vroceedings of the IEEE International Conference on Communications (ICC' 2013). Budapest, Hungary, 2013:2-6.
  • 10Monsanto C, Reich J, Foster N, Rexford J, Walker D. Composing software defined networks//Proceedings of the 10th USENIX Conference on Networked Systems Design and Implementation. Berkeley, USA, 2013:1-14.

共引文献94

同被引文献40

引证文献5

二级引证文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部