• •    

基于SDN的云平台入侵防御方案设计与实现

姜停停   

  1. 北京电子科技学院
  • 收稿日期:2016-10-08 修回日期:2016-12-03 发布日期:2016-12-03
  • 通讯作者: 姜停停

Design and implementation of cloud platform intrusion prevention system based on SDN

jiang tingting   

  • Received:2016-10-08 Revised:2016-12-03 Online:2016-12-03
  • Contact: jiang tingting

摘要: 针对传统的入侵防御系统是串联在网络环境中的,处理能力有限,易造成网络拥塞的问题,面向云计算应用,设计了一种基于软件定义网络(Software Defined Networking,SDN)的入侵防御方案。该方案利用SDN可编程性,在入侵检测系统检测到入侵时把入侵信息传给控制器,控制器下发安全策略到虚拟交换机,达到过滤入侵流量、动态阻止入侵行为的目的。通过实验与传统入侵防御方案对比分析表明,此方案入侵检测效率提高2倍,对云环境下入侵防御方案的部署具有一定的借鉴意义。

关键词: 云计算, 安全, 入侵防御, 软件定义网络, 控制器

Abstract: Because the traditional intrusion prevention system is connected in series in the network, the ability to deal with the intrusion is limited, and cause network congestion easily. Aiming at the problems, a cloud platform intrusion prevention scheme is designed based on software defined network(SDN). Using the programmable feature of SDN, when the intrusion detection system detects intrusion, it will transmit the intrusion information to the controller, then the controller will send security policy to virtual switch, so that it can filter the intrusion traffic and achieve the purpose of blocking intrusion behavior dynamically. A comparative analysis is mode through the experiment, the result shows that the efficiency of the intrusion detection can be improved by two times compared with the traditional intrusion prevention scheme, it has certain reference significance for the deployment of intrusion prevention scheme in cloud environment.