• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

一种基于SDP信任增强架构的分段路由数据平面安全模型。

A data plane security model of segmented routing based on SDP trust enhancement architecture.

作者信息

Wang Liang, Ma Hailong, Jiang Yiming, Tang Yin, Zu Shuodi, Hu Tao

机构信息

Institute of Information Technology, PLA Strategic Support Force Information Engineering University, Zhengzhou, 450003, China.

National Digital Switching System Engineering Technology Research Center, Zhengzhou, 450003, China.

出版信息

Sci Rep. 2022 May 24;12(1):8762. doi: 10.1038/s41598-022-12858-2.

DOI:10.1038/s41598-022-12858-2
PMID:35610296
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC9130199/
Abstract

Segment routing (SR) technology is a new network functional technology derived from MPLS technology and based on SDN. Combining SR with software-defined perimeter (SDP), a new network security technology, is expected to solve the traditional problems such as data monitoring, denial of service, and new threats such as loop attack and label detection faced by SR data plane. Focusing on the security management of access devices in the SR data plane, first, this paper proposes an SR security model SbSR (SDP-based SR) based on SDP trust enhancement architecture, then, two-level SDP AH trust verification mechanism and 4 trust management mechanisms including initial trust value, trust evaluation, trust renewal, trust inheritance are designed. In the trust evaluation mechanism as the core of the model, System cloud grey model (1,1) weighted Markov prediction model is introduced to obtain real-time trust based on the historical behavior of device nodes, and 4 indexes, namely benign message ratio, loyal forwarding ratio, forwarding ratio stationarity coefficient, packet rate stationarity coefficient, are introduced to distinguish malicious devices from normal devices. Finally, the simulation test results of 5 security functions and security costs show that the proposed architecture can solve port scanning, traffic monitoring, topology detection, loop attack, and DoS attack of SR network data plane with an average access delay cost of 2.84 s for each new network agent, and realize multi-faceted protection of SR network data plane.

摘要

段路由(SR)技术是一种源自多协议标签交换(MPLS)技术并基于软件定义网络(SDN)的新型网络功能技术。将SR与新型网络安全技术软件定义边界(SDP)相结合,有望解决传统问题,如数据监控、拒绝服务,以及SR数据平面面临的诸如环路攻击和标签检测等新威胁。本文聚焦于SR数据平面中接入设备的安全管理,首先基于SDP信任增强架构提出一种基于SDP的SR安全模型SbSR,然后设计了两级SDP AH信任验证机制以及包括初始信任值、信任评估、信任更新、信任继承在内的4种信任管理机制。在作为模型核心的信任评估机制中,引入系统云灰色模型(1,1)加权马尔可夫预测模型,基于设备节点的历史行为获取实时信任,并引入良性消息比率、忠诚转发比率、转发比率平稳系数、包率平稳系数这4个指标来区分恶意设备和正常设备。最后,5种安全功能和安全成本的仿真测试结果表明,所提出的架构能够解决SR网络数据平面的端口扫描、流量监控、拓扑检测、环路攻击和拒绝服务攻击问题,每个新网络代理的平均接入延迟成本为2.84秒,并实现对SR网络数据平面的多方面保护。

相似文献

1
A data plane security model of segmented routing based on SDP trust enhancement architecture.一种基于SDP信任增强架构的分段路由数据平面安全模型。
Sci Rep. 2022 May 24;12(1):8762. doi: 10.1038/s41598-022-12858-2.
2
A data plane security model of SR-BE/TE based on zero-trust architecture.一种基于零信任架构的SR-BE/TE数据平面安全模型。
Sci Rep. 2022 Nov 29;12(1):20612. doi: 10.1038/s41598-022-24342-y.
3
A novel software-defined network packet security tunnel forwarding mechanism.一种新颖的软件定义网络分组安全隧道转发机制。
Math Biosci Eng. 2019 May 17;16(5):4359-4381. doi: 10.3934/mbe.2019217.
4
TrustBlock: An adaptive trust evaluation of SDN network nodes based on double-layer blockchain.TrustBlock:基于双层区块链的 SDN 网络节点自适应信任评估。
PLoS One. 2020 Mar 10;15(3):e0228844. doi: 10.1371/journal.pone.0228844. eCollection 2020.
5
An intelligent zero trust secure framework for software defined networking.一种用于软件定义网络的智能零信任安全框架。
PeerJ Comput Sci. 2023 Nov 17;9:e1674. doi: 10.7717/peerj-cs.1674. eCollection 2023.
6
Secure multi-path routing for Internet of Things based on trust evaluation.基于信任评估的物联网安全多路径路由
Math Biosci Eng. 2024 Feb 4;21(2):3335-3363. doi: 10.3934/mbe.2024148.
7
Using trust to secure geographic and energy aware routing against multiple attacks.利用信任保障地理和能源感知路由免受多种攻击。
PLoS One. 2013 Oct 21;8(10):e77488. doi: 10.1371/journal.pone.0077488. eCollection 2013.
8
Satellite Network Security Routing Technology Based on Deep Learning and Trust Management.基于深度学习与信任管理的卫星网络安全路由技术
Sensors (Basel). 2023 Oct 15;23(20):8474. doi: 10.3390/s23208474.
9
Using Trust to Establish a Secure Routing Model in Cognitive Radio Network.利用信任在认知无线电网络中建立安全路由模型。
PLoS One. 2015 Sep 30;10(9):e0139326. doi: 10.1371/journal.pone.0139326. eCollection 2015.
10
TITAN: Combining a bidirectional forwarding graph and GCN to detect saturation attack targeted at SDN.TITAN:结合双向转发图和 GCN 检测针对 SDN 的饱和攻击。
PLoS One. 2024 Apr 26;19(4):e0299846. doi: 10.1371/journal.pone.0299846. eCollection 2024.

引用本文的文献

1
A data plane security model of SR-BE/TE based on zero-trust architecture.一种基于零信任架构的SR-BE/TE数据平面安全模型。
Sci Rep. 2022 Nov 29;12(1):20612. doi: 10.1038/s41598-022-24342-y.