首页> 美国卫生研究院文献>Sensors (Basel Switzerland) >Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
【2h】

Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks

机译:软件定义网络中虚拟化安全服务的动态构建方案

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

For a Software Defined Network (SDN), security is an important factor affecting its large-scale deployment. The existing security solutions for SDN mainly focus on the controller itself, which has to handle all the security protection tasks by using the programmability of the network. This will undoubtedly involve a heavy burden for the controller. More devastatingly, once the controller itself is attacked, the entire network will be paralyzed. Motivated by this, this paper proposes a novel security protection architecture for SDN. We design a security service orchestration center in the control plane of SDN, and this center physically decouples from the SDN controller and constructs SDN security services. We adopt virtualization technology to construct a security meta-function library, and propose a dynamic security service composition construction algorithm based on web service composition technology. The rule-combining method is used to combine security meta-functions to construct security services which meet the requirements of users. Moreover, the RETE algorithm is introduced to improve the efficiency of the rule-combining method. We evaluate our solutions in a realistic scenario based on OpenStack. Substantial experimental results demonstrate the effectiveness of our solutions that contribute to achieve the effective security protection with a small burden of the SDN controller.
机译:对于软件定义网络(SDN),安全性是影响其大规模部署的重要因素。 SDN的现有安全解决方案主要集中在控制器本身,该控制器必须通过使用网络的可编程性来处理所有安全保护任务。毫无疑问,这将给控制器带来沉重的负担。更具有破坏性的是,一旦控制器本身受到攻击,整个网络就会瘫痪。为此,本文提出了一种新颖的SDN安全保护体系结构。我们在SDN的控制平面中设计了一个安全服务编排中心,该中心与SDN控制器物理分离,并构建了SDN安全服务。我们采用虚拟化技术构建安全元功能库,并提出基于Web服务组合技术的动态安全服务组合构建算法。规则组合方法用于组合安全元功能,以构建满足用户需求的安全服务。此外,引入了RETE算法以提高规则组合方法的效率。我们在基于OpenStack的实际场景中评估我们的解决方案。大量的实验结果证明了我们解决方案的有效性,这些解决方案有助于在减轻SDN控制器负担的情况下实现有效的安全保护。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号