首页> 外文期刊>Computer networks >Multipath resilient routing for endogenous secure software defined networks
【24h】

Multipath resilient routing for endogenous secure software defined networks

机译:用于内源安全软件定义网络的多路径弹性路由

获取原文
获取原文并翻译 | 示例
           

摘要

SDN improves the flexibility and programmability of the network. However, malicious attacks caused by potential vulnerabilities and backdoors can easily lead to data and rule tampering in the network. To address this problem, this paper proposes an endogenous secure SDN network framework based on multipath resilient routing (MRR). MRR includes multipath comparing forwarding, multipath weighted forwarding, and multipath random forwarding. The framework ensures the correctness of flow rules and data content by dynamically comparing the consistency of multi-heterogeneous path data within a certain period, and multipath can also achieve load balance by weighted forwarding. In the MRR framework, we also present an intermediate information feedback mechanism based on encryption authentication and give a mathematical model to evaluate it. This mechanism can accurately identify and dynamically repair malicious switches. Simulation evaluation and prototype system test show that this framework can achieve high accuracy of flow transmission and high availability of system. At the same time, multipath comparing forwarding will bring some performance costs such as delay, bandwidth, and jitter at initial and attacking time. However, when the appropriate forwarding mode and reasonable period T are selected, the proportion of delay introduced by comparing and ruling can be less than 10%, and the average bandwidth of mixed forwarding is almost the same as traditional multipaths', such as we can guarantee 25% multipath comparing forwarding when the bandwidth requirement is 250 M in prototype system.
机译:SDN提高了网络的灵活性和可编程性。但是,由潜在漏洞和后门引起的恶意攻击可以轻松导致网络中篡改数据和规则。为了解决这个问题,本文提出了一种基于多径弹性路由(MRR)的内源安全SDN网络框架。 MRR包括多路径比较转发,多径加权转发和多径随机转发。该框架通过动态比较多个周期内的多异常路径数据的一致性来确保流程规则和数据内容的正确性,并且多径也可以通过加权转发实现负载平衡。在MRR框架中,我们还提供了一种基于加密认证的中间信息反馈机制,并提供数学模型来评估它。该机制可以准确识别和动态修复恶意交换机。仿真评估和原型系统测试表明,该框架可以实现高精度的流动传输和系统的高可用性。与此同时,多径比较转发将在初始和攻击时间下带来一些性能成本,如延迟,带宽和抖动。 However, when the appropriate forwarding mode and reasonable period T are selected, the proportion of delay introduced by comparing and ruling can be less than 10%, and the average bandwidth of mixed forwarding is almost the same as traditional multipaths', such as we can保证25%多路径比较转发当带宽要求在原型系统中为250米时。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号