Wang Liang, Ma Hailong, Jiang Yiming, Tang Yin, Zu Shuodi, Hu Tao
Institute of Information Technology, PLA Strategic Support Force Information Engineering University, Zhengzhou, 450003, China.
National Digital Switching System Engineering Technology Research Center, Zhengzhou, 450003, China.
Sci Rep. 2022 May 24;12(1):8762. doi: 10.1038/s41598-022-12858-2.
Segment routing (SR) technology is a new network functional technology derived from MPLS technology and based on SDN. Combining SR with software-defined perimeter (SDP), a new network security technology, is expected to solve the traditional problems such as data monitoring, denial of service, and new threats such as loop attack and label detection faced by SR data plane. Focusing on the security management of access devices in the SR data plane, first, this paper proposes an SR security model SbSR (SDP-based SR) based on SDP trust enhancement architecture, then, two-level SDP AH trust verification mechanism and 4 trust management mechanisms including initial trust value, trust evaluation, trust renewal, trust inheritance are designed. In the trust evaluation mechanism as the core of the model, System cloud grey model (1,1) weighted Markov prediction model is introduced to obtain real-time trust based on the historical behavior of device nodes, and 4 indexes, namely benign message ratio, loyal forwarding ratio, forwarding ratio stationarity coefficient, packet rate stationarity coefficient, are introduced to distinguish malicious devices from normal devices. Finally, the simulation test results of 5 security functions and security costs show that the proposed architecture can solve port scanning, traffic monitoring, topology detection, loop attack, and DoS attack of SR network data plane with an average access delay cost of 2.84 s for each new network agent, and realize multi-faceted protection of SR network data plane.
段路由(SR)技术是一种源自多协议标签交换(MPLS)技术并基于软件定义网络(SDN)的新型网络功能技术。将SR与新型网络安全技术软件定义边界(SDP)相结合,有望解决传统问题,如数据监控、拒绝服务,以及SR数据平面面临的诸如环路攻击和标签检测等新威胁。本文聚焦于SR数据平面中接入设备的安全管理,首先基于SDP信任增强架构提出一种基于SDP的SR安全模型SbSR,然后设计了两级SDP AH信任验证机制以及包括初始信任值、信任评估、信任更新、信任继承在内的4种信任管理机制。在作为模型核心的信任评估机制中,引入系统云灰色模型(1,1)加权马尔可夫预测模型,基于设备节点的历史行为获取实时信任,并引入良性消息比率、忠诚转发比率、转发比率平稳系数、包率平稳系数这4个指标来区分恶意设备和正常设备。最后,5种安全功能和安全成本的仿真测试结果表明,所提出的架构能够解决SR网络数据平面的端口扫描、流量监控、拓扑检测、环路攻击和拒绝服务攻击问题,每个新网络代理的平均接入延迟成本为2.84秒,并实现对SR网络数据平面的多方面保护。