计算机应用

• 人工智能与仿真 •    下一篇

基于拜占庭容错的 SDN 控制面的抗攻击性研究

高洁1,邬江兴1,胡宇翔2,李军飞1   

  1. 1. 解放军信息工程大学
    2. 国家数字交换系统工程技术研究中心,郑州 450002
  • 收稿日期:2017-02-20 修回日期:2017-04-12 发布日期:2017-04-12 出版日期:2017-05-13
  • 通讯作者: 高洁

The Research of Control Plane’ Anti-attacking in SDN Based on Byzantine Fault-Tolerant

  • Received:2017-02-20 Revised:2017-04-12 Online:2017-04-12 Published:2017-05-13

摘要: 针对 SDN 网络的单点故障,拜占庭错误,静态配置等安全性问题,为了解决拜占庭故障,应对未知的漏洞后门,增强网络的动态性,提出了基于拜占庭协议的SDN结构,并设计的动态控制器视图选举算法。将动态性、异构性和冗余性引入到 SDN,打破了攻击链,增强了网络的主动防御能力。通过对控制器异构性的量化,设计了两阶段求解控制器视图的选举算法。仿真结果表明,与主备结构相比,引入异构的拜占庭协议的结构的抗攻击能力更强。

Abstract: Abstract: In the light of single point failure, Byzantine fault, static configuration and other security problems in the SDN networks, In order to solve the Byzantine fault, defense the unknown vulnerabilities and back doors, enhance the dynamic of the network, a SDN architecture based on Byzantine protocol is proposed,and the dynamic controller view election algorithm is designed. The dynamics, heterogeneity and redundancy is introduced into the SDN, so that the attack chain is broken and the capabilities of network active defense is enhanced. Based on the quantification of the controller’s heterogeneity, the two stage algorithm is designed to seek for the controller view. Simulation results show that, the structure of the heterogeneous Byzantine protocol is more resistant to attack, compared with the p-b structure.

中图分类号: