节点文献

云数据中心软件定义网络数据层可生存性保障机制研究

Survivability Assurance Mechanisms for Data Plane of Software-Defined Network in the Cloud Data Centers

【作者】 袁斌

【导师】 金海;

【作者基本信息】 华中科技大学 , 计算机系统结构, 2018, 博士

【摘要】 随着越来越多的业务迁移到云数据中心中,云数据中心面临的用户需求呈现出多样化、差异化和高度定制化等特征。为了应对上述需求,具备高可编程性和强灵活性特征的软件定义网络越来越多的在云数据中心得到部署,成为了云数据中心的重要网络基础设施。然而,软件定义网络中承载实际业务数据流的数据层存在诸多安全缺陷。一旦针对软件定义网络数据层的攻击得以成功实施,那么云服务与云网络基础设施的可用性、网络状态数据的正确性、网络决策的可靠性等都将无法得到保障,其带来的后果和造成的损失将是无法估量的。目前,关于云数据中心软件定义网络数据层安全问题的研究方兴未艾,还存在许多亟需研究和解决的问题。首先,网络转发设备在硬件实现方式与软件处理能力上均存在不足,这使得软件定义网络数据层的基础设施在面对暴力攻击时显得十分脆弱;其次,软件定义网络数据层缺乏容错机制,恶意或错误的内部节点可以很容易的破坏网络状态数据的正确性,进而威胁网络的可靠性;最后,在软件定义网络环境中,主机上运行的服务的数据流都需要通过数据层进行转发,因此软件定义网络数据层的特殊性质势必会影响主机及其上运行的服务,当主机面临攻击时,需要制定综合考虑软件定义网络的特性、服务的特征、攻击的特点、服务质量如何保持的攻击缓解方法。而现有云数据中心软件定义网络数据层安全保障机制的研究呈现碎片化特点,缺少体系化解决方案。针对上述问题和研究现状,开展云数据中心软件定义网络数据层可生存性保障机制研究,综合以下三个方面来全面保障软件定义网络数据层的可生存性:在面向转发设备的攻击缓解方面,提出了基于排队论的系统模型,估算整个系统的抗攻击能力,在该模型的指导下,设计了peer-support策略来整合全网空闲资源以缓解暴力攻击,从而保证软件定义网络数据层基础设施的可用性。首先,基于软件定义网络转发设备的软硬件特性,分析其内部缺陷与缺陷利用方法;进而,模拟针对数据层转发设备的实际攻击,验证缺陷利用方法的可行性,评估攻击成功后对整个网络的影响;然后,把系统抽象为一个排队系统并建立理论模型,估算系统中可被用于攻击缓解的空闲资源总量;最后,基于理论模型,提出peer-support策略,充分利用整个网络的能力来缓解攻击,有效提高软件定义网络数据层的抗攻击能力,增强数据层基础设施的可用性。在内部错误的自动容忍方面,提出并实现了基于拜占庭模型的错误交换机自动容忍方案,确保(在错误交换机数目满足拜占庭容错条件的情况下)控制器输入信息(交换机提供的网络流统计信息)的正确性,从而提高网络决策的可靠性。首先,判别软件定义网络中错误交换机的哪些恶意行为会破坏控制器输入信息的正确性,并分析各种不同行为带来的后果;进而,提出基于拜占庭模型的错误交换机自动容忍方法;然后,分析利用拜占庭模型来解决软件定义网络数据层中内部错误自动容忍问题的可行性,为拜占庭模型在该问题中的应用提供理论依据与实践指导;最后,基于对模型应用过程中问题与挑战的分析,设计基于逻辑代理的错误交换机容忍框架,并在框架中实现拜占庭容错方案,完成对错误交换机的自动容忍,确保控制器输入信息的正确性,从而提高网络决策的可靠性。在缓解针对主机的攻击方面,提出了结合软件定义网络技术和分布式处理技术的攻击缓解方法,为云数据中心软件定义网络数据层中的主机提供保证服务质量的双向保护,提高网络服务的可用性。首先,基于软件定义网络的集中控制方式,实现网络状态的全面分析,从而快速制定攻击缓解策略;进而,利用软件定义网络的可编程性,实现网络流处理规则的自适应产生、安装与删除,使得网络策略得以快速执行;然后,利用分布式处理技术实现子网划分与负载均衡,避免出现单点故障;最后,通过网络流量缓存、基于网络协议的数据包轮询重发等方法来保证正常网络流量转发的正确性和时效性,在高效缓解攻击的同时,有效保证网络服务的服务质量,从而提高网络服务的可用性。综上所述,围绕云数据中心软件定义网络数据层的安全问题,分别从软件定义网络数据层基础设施的可用性、网络决策的可靠性、网络服务的可用性等三方面开展研究,为云数据中心软件定义网络数据层提供体系化的全面保护,保障其可生存性。

【Abstract】 With more and more business being migrated to the Cloud data center,the user needs of Cloud data center become more diversified,differentiated and highly customized.To meet these needs,software defined network(SDN),which are of programmability and high flexibility,has been widely deployed in the Cloud data centers and has become an important network infrastructure of Cloud data centers.However,there are security flaws in the data plane,which is responsible for the actual forwarding and processing of business data.Once the data plane of SDN is compromised,the availability of Cloud service or Cloud network infrastructure,the correctness of network state data,and the reliability of network policies will not be guaranteed.Consequently,the Cloud data center will suffer incalculable losses.At present,the research on security of SDN data plane is in the ascendant.There are still many issues to be further studied.First,the network forwarding devices are the important infrastructure in the SDN.However,they are flawed in hardware implementation and processing capability,which makes the infrastructures of SDN data plane very fragile when facing with brute force attacks.Second,the SDN data plane lacks fault tolerance mechanism.Malicious or fault internal nodes can easily tamper the network state data,which would further affect the generation of network policies and threat the reliability of the network.Finally,since the data flows of the services running on the hosts are forwarded and processed by the data plane in the SDN environment,the special nature of the SDN data plane will inevitably affect the hosts and the services.When the hosts are attacked,it is necessary to formulate a Qo S(Quality of Service)aware attack mitigation method that considers all the characteristics of the SDN,the attack and the service.However,existing protection methods for the SDN data plane lack systemized consideration,showing fragmentation characteristics.Therefore,to provide a comprehensive and systemized protection for SDN data plane in Cloud data center,its survivability assurance mechanisms are studied from the following three aspects:For mitigation of brute force attacks against forwarding devices in SDNs,a queueing theory based system model is established to approximate the capacity of the whole SDN system to defend against attacks.Guided by the model,a peer-support strategy is presented to integrate the idle resources in the whole network for attack mitigation,thus to ensure the availability of the SDN data plane infrastructure.At first,the vulnerabilities of SDN forwarding device and vulnerability exploitation method are analyzed.Then,practical attacks are emulated to verify the feasibility of vulnerabilities exploitation method and to evaluate the impact of the attack on the entire network.Further,the system is modeled as a queueing system to approximate the available idle resources for attack defense.At last,a peer-support strategy based attack mitigation approach is implemented to integrate all the available idle resources to defend against the attack.The proposal can effectively enhance the availability of the SDN data plane infrastructure by strengthening the system’s ability of defending against brute force attacks.For automatic internal faulty tolerance,a Byzantine model based faulty switch tolerance approach is proposed to ensure the correctness of controller’s inputs(the network state information provided by the switches in the data plane)when the Byzantine condition is satisfied,thus to improve the reliability of SDN.At first,the faulty switches’ malicious behaviors that would taint the correctness of controller’s inputs are analyzed.The possible consequences of these malicious behaviors are also investigated.Based on these observations,a Byzantine model based automatic faulty switch tolerance approach is presented.Then,the feasibility of applying Byzantine model in this scenario is studied,which provides theoretical support and practical guidance for the implementation.At last,based on the analyses of implementation challenges,a proxy layer is introduced into the SDN framework to apply Byzantine model and protocol in the SDN environment.The proposed approach can automatically tolerate faulty switches and ensure the correctness of the controller’s inputs.As a result,the reliability of the SDN is effectively improved.For mitigation of attacks against the hosts in SDN environment,a method that combines both the advantages of software-defined networking technique and distributed processing technique is presented to protect the hosts in the SDN of Cloud data centers with Qo S assurance,thus to improve the availability of network services.With the central control mode of SDN,comprehensive analysis of the network status is achievable.Leveraging this,attack mitigation policies can be generated rapidly.Further,the SDN’s programmability makes fast implementation of network polices achievable through adaptive generation,installation and deletion of forwarding rules.Moreover,subnet division and load balancing are implemented with distributed computing techniques.At last,Qo S is maintained by intelligently caching and resending the network packets.With such designs,the hosts in the SDN of Cloud data centers can be comprehensively protected with Qo S guarantee,which effectively improves the availability of network services.In summary,focusing on the security issues of SDN data plane,enhancing mechanisms for the availability of SDN data plane infrastructure,the reliability of network policies and the availability of network services are systematically investigated.Protection methods from all the three aspects are proposed to assure the survivability of SDN data plane in the Cloud data centers.

  • 【分类号】TP393.08;TP308
  • 【被引频次】3
  • 【下载频次】198
  • 攻读期成果
节点文献中: 

本文链接的文献网络图示:

本文的引文网络