首页> 外文会议>International Conference on Big Data Analysis >Design and Implementation of Cloud Platform Intrusion Prevention System based on SDN
【24h】

Design and Implementation of Cloud Platform Intrusion Prevention System based on SDN

机译:基于SDN的云平台入侵系统的设计与实现

获取原文

摘要

In view of the traditional intrusion prevention system is connected in series mode in the network, the ability of dealing with the intrusion is limited, and it will cause network congestion easily, especially in the cloud computer environment. Aiming at the problems mentioned above, a scheme for the cloud platform intrusion prevention is proposed in the paper, based on the construction of the software defined network. By using the programmable feature of the SDN, the IPS in the scheme will transmit the intrusion information to the controller, when the intrusion detection system detects intrusion. Then the controller will send security policy to virtual switch, so that it can filter the intrusion traffic and achieve the purpose of blocking intrusion behavior dynamically. A comparative analysis between the proposed scheme and transitional IPS is made through the experiment, the result shows that the efficiency of the intrusion detection in the new scheme can be improved by two times compared with the traditional intrusion prevention scheme. So, it has certain reference significance for the deployment of intrusion prevention scheme in cloud environment.
机译:鉴于传统的入侵防护系统在网络中以串联模式连接,处理入侵的能力有限,它将容易地引起网络拥塞,尤其是在云计算机环境中。针对上述问题,根据软件定义网络的构造,在纸上提出了一种云平台入侵防御的方案。通过使用SDN的可编程特征,当入侵检测系统检测入侵时,该方案中的IPS将向控制器发送入侵信息。然后,控制器将安全策略向虚拟交换机发送,以便它可以过滤入侵流量并达到动态阻止入侵行为的目的。通过实验进行了所提出的方案和过渡性IPS之间的比较分析,结果表明,与传统的入侵防御方案相比,新方案中的入侵检测的效率可以提高两次。因此,它对云环境中的入侵防御方案进行了一定的参考意义。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号