节点文献

边缘网络中基于联邦学习的安全服务链设计及优化

Design and Optimization of Security Service Chains Based on Federated Learning in Edge Networks

【作者】 方芳

【导师】 李勇明;

【作者基本信息】 重庆大学 , 信息与通信工程, 2024, 硕士

【摘要】 为了满足用户日益增长的网络服务体验需求,网络服务提供商会在边缘网络中部署服务功能链(Service Function Chain,SFC),将服务功能有序连接起来,从而为用户提供低延时的定制服务。但随着针对边缘设备的网络攻击的增加,部署在边缘环境的SFC会面临巨大的安全挑战。现有的SFC安全方案大多专注于研究如何按照控制层预定义的服务策略进行流量转发和流量处理,忽视了SFC组件上服务策略的制定、管理以及用户隐私安全。为了解决这些问题,本文提出了一个高效的安全服务链框架,其具体内容包括以下两个方面:(1)基于联邦学习的安全服务链构建。通过融合联邦学习和SFC框架构建安全服务链,其组件利用本地流量数据和系统运行数据协同训练安全服务策略模型,保护用户数据隐私的同时实现服务策略的智能化制定和管理。同时利用卷积神经网络和门控循环单元构建安全服务策略模型,并将该模型部署在SFC的分类器处,增强分类器的流量分类能力。仿真结果表明基于联邦学习的安全服务链的异常检测性能优于现有的SFC安全方案。(2)基于模型压缩的安全服务链优化。由于边缘网络中设备的计算和带宽资源存在异构性,安全服务链中服务策略模型训练会带来高昂的通信开销,影响服务功能链的服务效率。因此本文基于稀疏化和量化技术提出了一个高效的服务策略模型压缩机制,该机制将随机均匀量化器和Top-k压缩器结合形成组合压缩器,并利用自适应量化机制补偿组合压缩器导致的收敛速度变慢问题,从而在不大幅牺牲收敛速度的同时提高服务策略模型的压缩效率。仿真结果表明,在三种不同的学习场景下,该压缩机制在保证模型准确性和收敛速度的前提下,显著降低了模型训练的通信成本,最多能节约98%的通信开销,提升了安全服务链的服务效率。

【Abstract】 To meet the growing demand for network service experience from users,network service providers deploy service function chains(SFCs)in edge networks,connecting service functions in an orderly manner to provide users with low-latency customized services.However,with increased cyberattacks against edge devices,SFCs deployed in edge networks face significant security challenges.Most SFC security solutions focus on forwarding and processing traffic data according to predefined service policies from the control plane,neglecting the formulation and management of service policies on SFC components and users’privacy security.To overcome the above challenges,an efficient security service chain framework is proposed in this thesis,mainly including the following two contents:(1)Construction of a security service chain based on federated learning.By integrating federated learning and the SFC framework,the security service chain allows its components to utilize local traffic data and system operational data for collaborative training of security service policy models,which protects users’data privacy while achieving intelligent formulation and management of service policies.Meanwhile,a security service model using convolutional neural networks and gated recurrent units is deployed at the classifiers of the SFC,enhancing the traffic classification capability of classifiers.Simulation results show that the anomaly detection performance of the security service chain based on federated learning is superior to the existing SFC security solutions.(2)Optimization of the security service chain based on model compression.Due to the heterogeneity of computing and bandwidth resources in edge devices,high communication overhead is afforded for the training of service policy models in the security service chain,affecting the efficiency of the security service chain.Therefore,an efficient service model compression mechanism based on sparsification and quantization techniques is proposed in this thesis.This compression mechanism combines a random uniform quantizer with a Top-k compressor and utilizes an adaptive quantization scheme to compensate for the slow convergence rate caused by the composed compressor,which improves the compression efficiency of service policy models.Simulation results show that under three different learning scenarios,the proposed compression mechanism significantly reduces the communication overhead of model training while providing good model accuracy and convergence rate,thus enhancing the service efficiency of the security service chain.

  • 【网络出版投稿人】 重庆大学
  • 【网络出版年期】2026年 06期
  • 【分类号】TP393.08;TP181
节点文献中: 

本文链接的文献网络图示:

本文的引文网络