期刊文献+

DiffSec:一种差别性的智能网络安全服务模型 被引量:3

DiffSec: A Differentiated Intelligent Network Security Service Model
下载PDF
导出
摘要 网络安全对于现代信息社会越来越重要,随之而来的是网络安全的代价也越来越高.如何在保证网络安全的前提下,尽可能降低网络安全的开销是一个挑战性的任务.基于不同的用户群体具有不同安全需求的事实,提出了根据用户安全等级不同而提供有差别的安全服务的模型DiffSec,论证了该模型能够有效降低网络安全服务开销和提升网络性能,能够适应网络安全技术长期发展的需要.基于该模型,采用NFV和SDN结合的技术设计了安全接入网络(SANet)的结构和相应的智能控制方法,实现了原型系统.原型系统的实验结果表明:SANet不仅能够提供灵活、正确的网络安全功能,也具有良好的网络性能和实用价值. Network security for our modern information society is more and more important, and what followed by the cost of network security is increasing. It is a challenging task to reduce the cost of network security as much as possible on the premise of ensuring network security. Based on the fact that different user communities have different security requirements, this paper proposes a model called DiffSec that provides differentiated security services according to different user security levels. We argue that this model can effectively reduce the network security service cost and improve the network performance and can meet the needs of long-term development of the network security technology. Based on the DiffSec, we design the structure of the secure access network (SANet) and the corresponding intelligent control method using the combination of NFV and SDN, and implement the prototype system. The experimental results of the prototype system show that SANet can not only provide flexible and correct network security functions, but also has good network performance and practical value.
作者 邓理 吴伟楠 朱正一 陈鸣 Deng Li;Wu Weinan;Zhu Zhengyi;Chen Ming(College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106)
出处 《计算机研究与发展》 EI CSCD 北大核心 2019年第5期955-966,共12页 Journal of Computer Research and Development
基金 国家自然科学基金项目(61772271 61379149)~~
关键词 网络安全 软件定义网络 网络功能虚拟化 智能控制 原型系统 network security software-defined networking (SDN) network function virtualization (NFV) intelligent control prototype system
  • 相关文献

参考文献5

二级参考文献33

  • 1V. Jacobson, D. K. Smetters, J. D. Thornton, et al. "Networking Named Content", Communicetions oftheACM, vol. 55, no. 1, pp 117-124, January 2012.
  • 2T. Koponen, M. Chawla, B. G. Chun, et al. "A Data-Oriented (and Beyond) Network Architec- ture", Proceedings of the conference on Applil- cations, technologies, architecture and protocols for computer communications, August 2007, Kyoto, Japan, pp 181-192.
  • 3B. Ahlgren, C. Dannewitz, C. Imbrenda, et al. "A Survey of Information-Centric Networking", IEEE Communications Magazine, vol. 50, no.7, pp 26- 36, July 2012.
  • 4R. Jing, L. Lemin, C. Huan, et el. "On the De- ployment of Information-Centric Network: Pro- grammability and Virtualization", Proceedings of the International Conference on Computing, Networking and Communications (ICNC), Feb. 16-19, 2015, Garden Grove Canada, pp 690- 694.
  • 5D. Cheriton, M. Gritter. "TRIAD: A New Next-Generation Internet Architecture", January, 2000, http://www-dsg.stanford.edu/triad/triad. ps.gz.
  • 6S. Shailendra, 13. Panigrahi, H. K. Rath, et al. "A Novel Overlay Architecture for Information Centric Networking", Proceedings of the Twenty First National Conference on Communications (NCC), Febuary 2015, Mumbai, India, pp 1-6.
  • 7CCNx project, http://www.ccnx.org.
  • 8Sail. http://www.sail-project.eu/.
  • 9E. Suyong, M. Jibiki, M. Murata, et el. "A Design of an ICN Architecture Within the Framework of SDN", Proceedings of Seventh International Conference on Ubiquitous end Future Networks (ICUFN), July 2015, Sapporo, pp 141-146.
  • 10W. Jin, R. Jing, L Kejie, et el. "An Optimal Cache Management Framework for Information-Cen- tric Networks with Network Coding", Pro- ceedings of Networking Confrence, June 2014, Trondheim, pp 1-9.

共引文献133

同被引文献28

引证文献3

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部