节点文献
SDN中服务部署的拟态防御方法
Mimic defense method for service deployment in SDN
【摘要】 基于SDN与NFV的服务部署是提升网络性能与网络服务的重要技术,但是在服务部署过程中会出现一些安全问题,如服务链被篡改、截取、重放等。利用拟态防御理论,提出一种基于拟态防御的SDN服务部署架构,该架构利用动态异构冗余的特点,对服务部署过程中的主要攻击实现主动防御,有效增加攻击难度。结合服务部署的特点,改进了拟态防御中的调度机制和判决机制,增加了系统的异构程度,提升了系统的安全性与执行效率。
【Abstract】 Service deployment based on SDN and NFV is an important technology to improve network performance and network services.However, there are some security issues in the service deployment process,such as service chain tampering, interception, replay, and so on.Based on the theory of mimicry defense, An SDN service deployment architecture based on mimic defense was proposed. This architecture can take advantage of the characteristics of dynamic heterogeneous redundancy to achieve active defense against some attacks during service deployment, effectively increasing the difficulty of hacker attacks.At the same time, combined with the characteristics of service deployment, the scheduling mechanism and judgment mechanism in the mimicry defense are improved, the heterogeneity of the system is increased, the safety and execution efficiency of the system is improved.
【Key words】 service deployment; mimic defense; heterogeneous; MD5 judgment;
- 【文献出处】 通信学报 ,Journal on Communications , 编辑部邮箱 ,2018年S2期
- 【分类号】TP393.08
- 【被引频次】14
- 【下载频次】251