首页> 外文会议>IEEE Conference on Communications and Network Security >Modeling Cost of Countermeasures in Software Defined Networking-enabled Energy Delivery Systems
【24h】

Modeling Cost of Countermeasures in Software Defined Networking-enabled Energy Delivery Systems

机译:软件定义的联网能源输送系统中对策成本建模

获取原文

摘要

Software defined networking (SDN) is a networking paradigm to provide automated network management at run time through network orchestration and virtualization. SDN is primarily used for quality of service (QoS) and automated response to network failures. In the context of Energy Delivery System (EDS), SDN can also enhance system resilience through recovery from failures and maintaining critical operations during cyber attacks. Researchers have proposed SDN based architectures for autonomous attack containment, which dynamically modifies access control rules based on configurable trust levels. One of the challenges with such architectures is the lack of a cost model to select the countermeasure which balances the tradeoff between security risk and network QoS. Prior to choosing a particular countermeasure which either quarantines the attack or mitigates the impact, it is also critical to assess the impact on the ability of the operator to conduct normal operations. In this paper, we present an approach to aid in selection of security countermeasures dynamically in an SDN enabled EDS and achieving tradeoff between providing security and QoS. We present the modeling of security cost based on end-toend packet delay and throughput. We propose a non-dominated sorting based multi-objective optimization framework which can be implemented within an SDN controller to address the joint problem of optimizing between security and QoS parameters by alleviating time complexity at O(MN2). The M is the number of objective functions and N is the number of population for each generation respectively. We present simulation results which illustrate how data availability and data integrity can be achieved while maintaining QoS constraints.
机译:软件定义网络(SDN)是一种网络范例,可通过网络编排和虚拟化在运行时提供自动化的网络管理。 SDN主要用于服务质量(QoS)和对网络故障的自动响应。在能源输送系统(EDS)的背景下,SDN还可以通过从故障中恢复并在网络攻击期间维持关键操作来增强系统的弹性。研究人员提出了用于自主攻击控制的基于SDN的体系结构,该体系结构基于可配置的信任级别动态修改访问控制规则。这种架构的挑战之一是缺乏一种成本模型来选择能够在安全风险和网络QoS之间进行权衡的对策。在选择隔离攻击或减轻影响的特定对策之前,评估对操作员进行正常操作的能力的影响也很重要。在本文中,我们提出了一种方法,可帮助在支持SDN的EDS中动态选择安全对策,并在提供安全性和QoS之间进行权衡。我们提出了基于端到端数据包延迟和吞吐量的安全成本建模。我们提出了一种基于非支配排序的多目标优化框架,该框架可以在SDN控制器中实现,以通过减轻O(MN)的时间复杂度来解决安全性和QoS参数之间的优化联合问题。 2 )。 M是目标函数的数量,N是每一代的总体数量。我们提供的仿真结果说明了如何在保持QoS约束的同时实现数据可用性和数据完整性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号