• 中国精品科技期刊
  • CCF推荐A类中文期刊
  • 计算领域高质量科技期刊T1类
高级检索

面向SDN的脆弱性扩散形式化建模与扩散因素分析

王健, 赵国生, 赵中楠, 李可

王健, 赵国生, 赵中楠, 李可. 面向SDN的脆弱性扩散形式化建模与扩散因素分析[J]. 计算机研究与发展, 2018, 55(10): 2256-2268. DOI: 10.7544/issn1000-1239.2018.20180447
引用本文: 王健, 赵国生, 赵中楠, 李可. 面向SDN的脆弱性扩散形式化建模与扩散因素分析[J]. 计算机研究与发展, 2018, 55(10): 2256-2268. DOI: 10.7544/issn1000-1239.2018.20180447
Wang Jian, Zhao Guosheng, Zhao Zhongnan, Li Ke. Formal Modeling and Factor Analysis for Vulnerability Propagation Oriented to SDN[J]. Journal of Computer Research and Development, 2018, 55(10): 2256-2268. DOI: 10.7544/issn1000-1239.2018.20180447
Citation: Wang Jian, Zhao Guosheng, Zhao Zhongnan, Li Ke. Formal Modeling and Factor Analysis for Vulnerability Propagation Oriented to SDN[J]. Journal of Computer Research and Development, 2018, 55(10): 2256-2268. DOI: 10.7544/issn1000-1239.2018.20180447
王健, 赵国生, 赵中楠, 李可. 面向SDN的脆弱性扩散形式化建模与扩散因素分析[J]. 计算机研究与发展, 2018, 55(10): 2256-2268. CSTR: 32373.14.issn1000-1239.2018.20180447
引用本文: 王健, 赵国生, 赵中楠, 李可. 面向SDN的脆弱性扩散形式化建模与扩散因素分析[J]. 计算机研究与发展, 2018, 55(10): 2256-2268. CSTR: 32373.14.issn1000-1239.2018.20180447
Wang Jian, Zhao Guosheng, Zhao Zhongnan, Li Ke. Formal Modeling and Factor Analysis for Vulnerability Propagation Oriented to SDN[J]. Journal of Computer Research and Development, 2018, 55(10): 2256-2268. CSTR: 32373.14.issn1000-1239.2018.20180447
Citation: Wang Jian, Zhao Guosheng, Zhao Zhongnan, Li Ke. Formal Modeling and Factor Analysis for Vulnerability Propagation Oriented to SDN[J]. Journal of Computer Research and Development, 2018, 55(10): 2256-2268. CSTR: 32373.14.issn1000-1239.2018.20180447

面向SDN的脆弱性扩散形式化建模与扩散因素分析

基金项目: 国家自然科学基金项目(61403109, 61202458);高等学校博士学科点专项科研基金项目(20112303120007);黑龙江省自然科学基金项目(F2017021);黑龙江省教育厅科研基金项目(12541169);哈尔滨市科技创新人才研究专项资金项目(2016RAQXJ036)
详细信息
  • 中图分类号: TP393

Formal Modeling and Factor Analysis for Vulnerability Propagation Oriented to SDN

  • 摘要: SDN将传统网络控制面与转发面解耦,在实施集中化管控的同时引入诸多新的安全和管理问题.脆弱点类型在SDN各层及南北向接口存在差异性,且传播趋势不同.针对脆弱性在SDN层内及层间的扩散效果及抑制策略问题,提出了一种基于Bio-PEPA的SDN脆弱性扩散形式化模型.1)对Bio-PEPA基础语义进行讨论,阐明其适用于具有明显分层架构的SDN及具有动态性的脆弱性扩散过程;2)探讨SDN中各层存在的脆弱性问题,并对SDN中存在的脆弱性以层为单位进行建模,通过对SDN层内及层间脆弱性扩散过程构建形式化模型,进而分析SDN内脆弱性在水平(层内)及垂直(层间)2个维度内的扩散机理,从而更好地抑制脆弱性在SDN内的扩散;3)通过仿真实验得出可以通过降低连接转化率、提升检测转化率及修复转化率来有效抑制SDN的脆弱性扩散.
    Abstract: Software defined network (SDN) is one of the most popular network technologies nowadays. SDN decouples the traditional control plane from the forwarding plane, resulting in many new security and management issues while performing centralized control. Meanwhile, the types of vulnerabilities are diverse in each layer and north-south trending interfaces of SDN, and the spread trend is quite different. Aiming at the effect of vulnerability propagation in/between layers of SDN as well as its suppression strategy, a formal model of vulnerability propagation for SDN based on Bio-PEPA is proposed in this paper. First of all, the basic syntax of Bio-PEPA is discussed, and its applicability to SDN with obvious hierarchical structure and the vulnerability propagation process with dynamic characteristic is illustrated. Then, the vulnerabilities existing in each layer of SDN are explored and modeled in terms of layers. Besides, by constructing a formal model for the process of vulnerability propagation in/between layers of SDN, the mechanism of vulnerability propagation is analyzed in two levels, horizontal (in layers) and vertical (between layers). In this way, the vulnerability propagation of SDN can be better suppressed. Finally, the simulation results show that the vulnerability propagation of SDN can be effectively retained by reducing the connection conversion rate, improving the detection conversion rate and repairing conversion rate. Our works provide a reference for the law of vulnerability propagation of SDN, so as to improve the security of SDN.
  • 期刊类型引用(4)

    1. 李晶,张滨. 基于并行挖掘大数据的无损云取证模型仿真. 计算机仿真. 2021(02): 9-12+277 . 百度学术
    2. 王丹,丁兆锟,周锋,赵燕. 基于司法鉴定合法性原则的DMA技术内存取证方法. 电子技术与软件工程. 2021(02): 227-228 . 百度学术
    3. 冯馨玥,杨秋松,石琳,王青,李明树. 基于动态策略学习的关键内存数据访问监控. 计算机研究与发展. 2019(07): 1470-1487 . 本站查看
    4. 刘雪花,丁丽萍,刘文懋,郑涛,李彦峰,吴敬征. 一种基于软件定义安全和云取证趋势分析的云取证方法. 计算机研究与发展. 2019(10): 2262-2276 . 本站查看

    其他类型引用(8)

计量
  • 文章访问数: 
  • HTML全文浏览量:  0
  • PDF下载量: 
  • 被引次数: 12
出版历程
  • 发布日期:  2018-09-30

目录

    /

    返回文章
    返回