• •    

基于安全策略的负载感知动态调度机制研究

顾泽宇,张兴明,林森杰   

  1. 国家数字交换系统工程技术研究中心
  • 收稿日期:2017-05-16 修回日期:2017-06-22 发布日期:2017-06-22
  • 通讯作者: 顾泽宇

Research on load-aware dynamic scheduling mechanism based on security strategies

  • Received:2017-05-16 Revised:2017-06-22 Online:2017-06-22

摘要: 针对SDN网络控制器流规则篡改攻击等单点脆弱性威胁,传统安全解决方案如备份、容错机制等存在被动防御缺陷,无法从根本上解决控制层安全问题,结合目前移动目标防御、网络空间拟态防御等主动防御技术研究现状,提出一种基于异构冗余结构的动态安全调度机制,建立控制器执行体与调度体调度模型,根据系统攻击异常、异构度等指标,以安全性为原则设计动态调度策略;同时考虑系统负载因素设计调度算法(Load-aware security scheduling algorithm, LA-SSA),通过该算法将调度问题转化为动态双目标优化问题,以实现优化的调度方案。仿真结果表明,对比静态结构,动态调度机制在累积异常值、输出安全率等指标上有明显优势,说明安全调度机制中的动态性与多样性能够显著提高系统抵御攻击能力,LA-SSA算法机制负载方差较安全优先调度平稳,实现安全调度的同时避免了负载失衡问题,验证了安全调度机制的有效性。

关键词: 单点脆弱性, 主动防御技术, 动态调度机制, 安全策略, 负载感知

Abstract: Concern the problem of the flow rules tampering attacks and other single point vulnerability threats towards SDN controller, traditional security solutions such as backup and fault-tolerant mechanisms which are based on passive defense defects, cannot fundamentally solve the control layer security issues. Combined with the current Moving Target defense and Cyberspace Mimic defense, a dynamic security scheduling mechanism was proposed based on heterogeneous redundant structure. The controller scheduling model was established in which the dynamic scheduling strategy was designed based on security principle combined with attack exception and heterogeneity. Considering the system load factor, the proposed algorithm LA-SSA transform scheduling problem into a dynamic optimization problem. Simulation results show that compared with static structure, the dynamic and diversity of the security scheduling mechanism can significantly improve the system’s ability to resist the attack. And the LA-SSA algorithm which senses load factor guarantees the security while avoiding load imbalance problem.

Key words: single point vulnerability, active defense technology, dynamic scheduling mechanism, security strategy, load sensing

中图分类号: