Current SDN controllers suffer from a series of potential attacks. For example, malicious flow rules may lead to system disorder by introducing unexpected flow entries. In this paper, we propose Mcad-SA, an aware deci...Current SDN controllers suffer from a series of potential attacks. For example, malicious flow rules may lead to system disorder by introducing unexpected flow entries. In this paper, we propose Mcad-SA, an aware decision-making security architecture with multiple controllers, which could coordinate heterogeneous controllers internally as a "big" controller. This architecture includes an additional plane, the scheduling plane, which consists of transponder, sensor, decider and scheduler. Meanwhile it achieves the functions of communicating, supervising and scheduling between data and control plane. In this framework, we adopt the vote results from the majority of controllers to determine valid flow rules distributed to switches. Besides, an aware dynamic scheduling(ADS) mechanism is devised in scheduler to intensify security of Mcad-SA further. Combined with perception, ADS takes advantage of heterogeneity and redundancy of controllers to enable the control plane operate in a dynamic, reliable and unsteady state, which results in significant difficulty of probing systems and executing attacks. Simulation results demonstrate the proposed methods indicate better security resilience over traditional architectures as they have lower failure probability when facing attacks.展开更多
Software Defined Networking(SDN) provides flexible network management by decoupling control plane and data plane. However, such separation introduces the issues regarding the reliability of the control plane and contr...Software Defined Networking(SDN) provides flexible network management by decoupling control plane and data plane. However, such separation introduces the issues regarding the reliability of the control plane and controller load imbalance in the distributed SDN network, which will cause the low network stability and the poor controller performance. This paper proposes Reliable and Load balance-aware Multi-controller Deployment(RLMD) strategy to address the above problems. Firstly, we establish a multiple-controller network model and define the relevant parameters for RLMD. Then, we design the corresponding algorithms to implement this strategy. By weighing node efficiency and path quality, Controller Placement Selection(CPS) algorithm is introduced to explore the reliable deployments of the controllers. On this basis, we design Multiple Domain Partition(MDP) algorithm to allocate switches for controllers according to node attractability and controller load balancing rate, which could realize the reasonable domain planning. Finally, the simulations show that, compared with the typical strategies, RLMD has the better performance in improving the reliability of the control plane and balancing the distribution of the controller loads.展开更多
软件定义网络(Softeware Defined Network, SDN)是一种新型的网络体系架构,目前已成为下一代互联网研究的热点。为了解决SDN中的网络信息安全问题,文章对SDN中的控制平面、数据平面和应用平面进行分析,梳理并总结了SDN管理中的相关网络...软件定义网络(Softeware Defined Network, SDN)是一种新型的网络体系架构,目前已成为下一代互联网研究的热点。为了解决SDN中的网络信息安全问题,文章对SDN中的控制平面、数据平面和应用平面进行分析,梳理并总结了SDN管理中的相关网络安全问题。提出了一种基于SDN的网络安全框架及安全策略,有效弥补传统网络结构中的网络安全缺陷问题,增强SDN网络安全级别,并建立一种基于终端用户限定与管理的SDN的网络安全框架及其安全策略。展开更多
文章主要设计一种软件定义网络(Software Defined Network,SDN)管理系统平台,首先分析系统的用户需求,其次提出其整体框架、模块设计以及数据库设计,并进行系统测试。文章所设计的平台能够优化网络维护的流程,提升网络管理员开展日常网...文章主要设计一种软件定义网络(Software Defined Network,SDN)管理系统平台,首先分析系统的用户需求,其次提出其整体框架、模块设计以及数据库设计,并进行系统测试。文章所设计的平台能够优化网络维护的流程,提升网络管理员开展日常网络维护工作的效率。展开更多
文章深入研究基于强化学习的流量优化与拥塞控制方法在软件定义网络(Software Defined Network,SDN)中的应用。首先,详细阐述SDN网络的架构与原理。SDN网络的灵活性和可编程性为网络管理提供了全新的范式。其次,提出了一种基于强化学习...文章深入研究基于强化学习的流量优化与拥塞控制方法在软件定义网络(Software Defined Network,SDN)中的应用。首先,详细阐述SDN网络的架构与原理。SDN网络的灵活性和可编程性为网络管理提供了全新的范式。其次,提出了一种基于强化学习的流量优化与拥塞控制方法,通过建模状态、动作、奖励等要素,实现网络流量智能调整。最后,在Mininet仿真环境中进行了实验验证。通过监测吞吐量、延迟、拥塞情况等性能指标,验证所提方法的有效性。实验结果表明,在网络性能方面,所提方法相较于传统方法取得了显著改善,具备更好的适应性和优化能力。展开更多
重点研究智慧校园网络与安全的软件定义网络(Software Defined Network,SDN)架构选择,分别讨论SDN架构应用的必要性、实现方法、网络与安全维护建议等内容。从智慧校园的集中部署、意图网络与智慧校园的融合、以零信任为核心构建网络安...重点研究智慧校园网络与安全的软件定义网络(Software Defined Network,SDN)架构选择,分别讨论SDN架构应用的必要性、实现方法、网络与安全维护建议等内容。从智慧校园的集中部署、意图网络与智慧校园的融合、以零信任为核心构建网络安全架构3个维度出发,提出保护智慧校园网络安全的建议。旨在强调SDN架构对于智慧校园建设的运行安全维护作用,以期为今后智慧校园的深化建设提供技术支持。展开更多
In order to improve the scalability and reliability of Software Defined Networking(SDN),many studies use multiple controllers to constitute logically centralized control plane to provide load balancing and fail over.I...In order to improve the scalability and reliability of Software Defined Networking(SDN),many studies use multiple controllers to constitute logically centralized control plane to provide load balancing and fail over.In this paper,we develop a flexible dormant multi-controller model based on the centralized multi-controller architecture.The dormant multi-controller model allows part of controllers to enter the dormant state under light traffic condition for saving system cost.Meanwhile,through queueing analysis,various performance measures of the system can be obtained.Moreover,we analyze the real traffic of China Education Network and use the results as the parameters of computer simulation and verify the effects of parameters on the system characteristics.Finally,a total expected cost function is established,and genetic algorithm is employed to find the optimal values of various parameters to minimize system cost for the deployment decision making.展开更多
为探讨基于软件定义网络(Software Defined Network,SDN)理念的校园网络管理与优化方案,本文从校园网络管理需求、SDN网络架构特点以及基于SDN的校园网络管理优势与场景出发,探讨基于SDN的校园网络管理与优化方案,以网络结构设计、功能...为探讨基于软件定义网络(Software Defined Network,SDN)理念的校园网络管理与优化方案,本文从校园网络管理需求、SDN网络架构特点以及基于SDN的校园网络管理优势与场景出发,探讨基于SDN的校园网络管理与优化方案,以网络结构设计、功能融合以及接口结构、网络安全、负载均衡等角度予以阐述。展开更多
软件定义网络(Software Defined Network,SDN)架构是使用软件编写代码的方式构建网络,实现控制转发平面分离,并对控制平面实现集中管理.生成树协议(Spanning Tree Protocol,STP)是交换式网络的环路避免协议,通过生成树算法(Spanning Tre...软件定义网络(Software Defined Network,SDN)架构是使用软件编写代码的方式构建网络,实现控制转发平面分离,并对控制平面实现集中管理.生成树协议(Spanning Tree Protocol,STP)是交换式网络的环路避免协议,通过生成树算法(Spanning Tree Algorithm,STA),将带有环路的物理拓扑中某台设备的接口设置为阻塞状态,构建逻辑无环拓扑.该文通过Python代码编制网络拓扑文件和RYU控制器文件的方式,实施SDN中的网络环路设计,按照STA算法设计和实现STP环路避免,并在仿真实验平台运行,测试结果表明,实现了SDN网络中环路避免.展开更多
铁路应急通信网络由于涉及业务多、技术种类多,在实现快速搭建的问题上面临比较大的挑战。如何实现应急通信网络的快速搭建,同时满足多种业务、多场景下的不同需求,保证通信网络的稳定性与有效性成为一个值得关注的研究话题。软件定义网...铁路应急通信网络由于涉及业务多、技术种类多,在实现快速搭建的问题上面临比较大的挑战。如何实现应急通信网络的快速搭建,同时满足多种业务、多场景下的不同需求,保证通信网络的稳定性与有效性成为一个值得关注的研究话题。软件定义网络(Software Defined Networking,SDN)提出的控制层与数据层分离的新思想为研究提供新的方向。提出在应急通信中引入SDN技术,构建基于SDN的融合应急通信网络,实现网络的集中控制、状态感知、按需路由等相关功能,提高网络的稳定性与效率。展开更多
随着我国信息技术的不断发展,客户对信息数据的要求也在不断地提高,如需要多样化的数据、数据传递要更加迅速、数据要有较高的自身处理能力等,这就意味着必须要对网络进行灵活的控制。软件定义网络(Software Defined Network,SDN)技术...随着我国信息技术的不断发展,客户对信息数据的要求也在不断地提高,如需要多样化的数据、数据传递要更加迅速、数据要有较高的自身处理能力等,这就意味着必须要对网络进行灵活的控制。软件定义网络(Software Defined Network,SDN)技术的出现有效地实现了这一特点,其不仅可以实现资源的灵活配置、自动配置,还满足数据中心网络的应用需求。因此,就对基于SDN技术的数据中心基础网络构建进行研究。首先分析其构建数据中心的优势,然后从其基本架构、抽象服务等方面来对SDN技术的应用以及基础网络构建进行深入的探讨和分析,以此来为相关部门提供参考。展开更多
基金supported by the Foundation for Innovative Research Groups of the National Natural Science Foundation of China (No.61521003)the National Key R&D Program of China (No.2016YFB0800100,No.2016YFB0800101)the National Natural Science Foundation of China (No.61602509)
文摘Current SDN controllers suffer from a series of potential attacks. For example, malicious flow rules may lead to system disorder by introducing unexpected flow entries. In this paper, we propose Mcad-SA, an aware decision-making security architecture with multiple controllers, which could coordinate heterogeneous controllers internally as a "big" controller. This architecture includes an additional plane, the scheduling plane, which consists of transponder, sensor, decider and scheduler. Meanwhile it achieves the functions of communicating, supervising and scheduling between data and control plane. In this framework, we adopt the vote results from the majority of controllers to determine valid flow rules distributed to switches. Besides, an aware dynamic scheduling(ADS) mechanism is devised in scheduler to intensify security of Mcad-SA further. Combined with perception, ADS takes advantage of heterogeneity and redundancy of controllers to enable the control plane operate in a dynamic, reliable and unsteady state, which results in significant difficulty of probing systems and executing attacks. Simulation results demonstrate the proposed methods indicate better security resilience over traditional architectures as they have lower failure probability when facing attacks.
基金supported in part by the Project of National Network Cyberspace Security (Grant No.2017YFB0803204)the National High-Tech Research and Development Program of China (863 Program) (Grant No. 2015AA016102)+1 种基金Foundation for Innovative Research Group of the National Natural Science Foundation of China (Grant No.61521003)Foundation for the National Natural Science Foundation of China (Grant No. 61502530)
文摘Software Defined Networking(SDN) provides flexible network management by decoupling control plane and data plane. However, such separation introduces the issues regarding the reliability of the control plane and controller load imbalance in the distributed SDN network, which will cause the low network stability and the poor controller performance. This paper proposes Reliable and Load balance-aware Multi-controller Deployment(RLMD) strategy to address the above problems. Firstly, we establish a multiple-controller network model and define the relevant parameters for RLMD. Then, we design the corresponding algorithms to implement this strategy. By weighing node efficiency and path quality, Controller Placement Selection(CPS) algorithm is introduced to explore the reliable deployments of the controllers. On this basis, we design Multiple Domain Partition(MDP) algorithm to allocate switches for controllers according to node attractability and controller load balancing rate, which could realize the reasonable domain planning. Finally, the simulations show that, compared with the typical strategies, RLMD has the better performance in improving the reliability of the control plane and balancing the distribution of the controller loads.
文摘软件定义网络(Softeware Defined Network, SDN)是一种新型的网络体系架构,目前已成为下一代互联网研究的热点。为了解决SDN中的网络信息安全问题,文章对SDN中的控制平面、数据平面和应用平面进行分析,梳理并总结了SDN管理中的相关网络安全问题。提出了一种基于SDN的网络安全框架及安全策略,有效弥补传统网络结构中的网络安全缺陷问题,增强SDN网络安全级别,并建立一种基于终端用户限定与管理的SDN的网络安全框架及其安全策略。
文摘文章深入研究基于强化学习的流量优化与拥塞控制方法在软件定义网络(Software Defined Network,SDN)中的应用。首先,详细阐述SDN网络的架构与原理。SDN网络的灵活性和可编程性为网络管理提供了全新的范式。其次,提出了一种基于强化学习的流量优化与拥塞控制方法,通过建模状态、动作、奖励等要素,实现网络流量智能调整。最后,在Mininet仿真环境中进行了实验验证。通过监测吞吐量、延迟、拥塞情况等性能指标,验证所提方法的有效性。实验结果表明,在网络性能方面,所提方法相较于传统方法取得了显著改善,具备更好的适应性和优化能力。
文摘重点研究智慧校园网络与安全的软件定义网络(Software Defined Network,SDN)架构选择,分别讨论SDN架构应用的必要性、实现方法、网络与安全维护建议等内容。从智慧校园的集中部署、意图网络与智慧校园的融合、以零信任为核心构建网络安全架构3个维度出发,提出保护智慧校园网络安全的建议。旨在强调SDN架构对于智慧校园建设的运行安全维护作用,以期为今后智慧校园的深化建设提供技术支持。
基金the National High-tech R&D Program ("863" Program) of China,the National Science Foundation of China,National Science & Technology Pillar Program of China,the National Science Foundation of China,the Post-Doctoral Funding of China,Tsinghua-Huawei joint research project
文摘In order to improve the scalability and reliability of Software Defined Networking(SDN),many studies use multiple controllers to constitute logically centralized control plane to provide load balancing and fail over.In this paper,we develop a flexible dormant multi-controller model based on the centralized multi-controller architecture.The dormant multi-controller model allows part of controllers to enter the dormant state under light traffic condition for saving system cost.Meanwhile,through queueing analysis,various performance measures of the system can be obtained.Moreover,we analyze the real traffic of China Education Network and use the results as the parameters of computer simulation and verify the effects of parameters on the system characteristics.Finally,a total expected cost function is established,and genetic algorithm is employed to find the optimal values of various parameters to minimize system cost for the deployment decision making.
文摘为探讨基于软件定义网络(Software Defined Network,SDN)理念的校园网络管理与优化方案,本文从校园网络管理需求、SDN网络架构特点以及基于SDN的校园网络管理优势与场景出发,探讨基于SDN的校园网络管理与优化方案,以网络结构设计、功能融合以及接口结构、网络安全、负载均衡等角度予以阐述。
文摘软件定义网络(Software Defined Network,SDN)架构是使用软件编写代码的方式构建网络,实现控制转发平面分离,并对控制平面实现集中管理.生成树协议(Spanning Tree Protocol,STP)是交换式网络的环路避免协议,通过生成树算法(Spanning Tree Algorithm,STA),将带有环路的物理拓扑中某台设备的接口设置为阻塞状态,构建逻辑无环拓扑.该文通过Python代码编制网络拓扑文件和RYU控制器文件的方式,实施SDN中的网络环路设计,按照STA算法设计和实现STP环路避免,并在仿真实验平台运行,测试结果表明,实现了SDN网络中环路避免.
文摘铁路应急通信网络由于涉及业务多、技术种类多,在实现快速搭建的问题上面临比较大的挑战。如何实现应急通信网络的快速搭建,同时满足多种业务、多场景下的不同需求,保证通信网络的稳定性与有效性成为一个值得关注的研究话题。软件定义网络(Software Defined Networking,SDN)提出的控制层与数据层分离的新思想为研究提供新的方向。提出在应急通信中引入SDN技术,构建基于SDN的融合应急通信网络,实现网络的集中控制、状态感知、按需路由等相关功能,提高网络的稳定性与效率。
文摘随着我国信息技术的不断发展,客户对信息数据的要求也在不断地提高,如需要多样化的数据、数据传递要更加迅速、数据要有较高的自身处理能力等,这就意味着必须要对网络进行灵活的控制。软件定义网络(Software Defined Network,SDN)技术的出现有效地实现了这一特点,其不仅可以实现资源的灵活配置、自动配置,还满足数据中心网络的应用需求。因此,就对基于SDN技术的数据中心基础网络构建进行研究。首先分析其构建数据中心的优势,然后从其基本架构、抽象服务等方面来对SDN技术的应用以及基础网络构建进行深入的探讨和分析,以此来为相关部门提供参考。