软件定义网络(SDN)为网络赋予了可编程性,降低了网络管理的复杂性,促进了新型网络技术的发展。SDN交换机作为数据转发与策略执行的设备,其权限不应被未经授权的实体窃取。然而,SDN交换机并不总是执行控制器下发的命令,恶意攻击者通过侵蚀SDN交换机对网络进行隐秘而致命的攻击,严重影响用户的端到端通信质量。通信顺序进程(CSP)作为针对并发系统设计的建模语言,可对SDN交换机-交换机,以及交换机-主机间的交互进行准确的描述。文中使用CSP对SDN交换机、终端主机进行建模,对两种异常交换机定位方法进行理论分析,并在实例化的模型系统中认证检测方法在边缘交换机作为出口交换机恶意转发时的有效性,认证结果表明无法检测该异常行为。针对这一问题,提出了边缘交换机异常检测方法,主机记录统计信息并通过构造特殊的数据包触发packet_in消息完成与控制器之间的信息传递,控制器收集统计信息并利用边缘交换机与主机之间的统计信息一致性检测边缘交换机的异常传输行为。最后,基于ryu控制器在mininet平台上进行实验,实验结果表明,边缘交换机异常检测方法可以成功检测异常行为。
未来的网络通信需求动态多样,网络层功能也应适时而变,因此对网络可演进性的研究具有重要意义.多标识网络作为一种兼容性极强的网络架构,网络层功能十分丰富,但仍缺少网络演进性设计.本文为多标识网络设计了一种通过标识扩展来支持网络体系不断演进的方案,包括对标识空间进行形式化定义,设计标识回退候选标识的优先级排序算法以及设计支持标识扩展的路由转发协议;并且在ndnSIM网络仿真环境和多标识网络测试床中实现了上述方案,评估了标识扩展方案的可行性和性能.实验结果表明相比于标识扩展机制给网络架构带来的益处,其性能损失在可接受的范围内.
Cyber mimic defenses have recently emerged as a dynamic heterogeneity redundancy architecture, which adjust the asymmetry between defenders and attackers by reconfiguring the system according to the network scenario. Some studies have investigated the effectiveness of security models, however, there is still a lack of convincing and practical methods to assess CMD networks quantitatively. Thus, in this paper, we propose a two-dimension model that calculates those details as a digital result to compare different CMD networks. In addition, the proposed method demonstrates good scalability in different networks. Specifically, in the first dimension, i.e., attacking a single node, we elaborate on system configurations and employ the Generalized Stochastic Petri net model to capture the effectiveness of different behaviors from gamers. To quantify the impacts of those behaviors, we parameterized them using a Poisson process, common vulnerabilities and exposures, and the common vulnerability scoring system. In the second dimension, we adopt Markov chains and the Martingale theory to analyze the attack process along the attack chain. Finally, security metrics and countermeasures under different scenarios are presented to verify the effectiveness of CMD, which provides some guidance for designing future systems with acceptable cost.
The blockchain has a great vogue in recent years, and its core consensus algorithms also become the focus of research. At present, most of the research on consensus mechanisms are oriented to the public blockchain and based on existing consensus mechanisms or sophisticated distributed algorithms. Various application scenarios have been developed based on the consortium blockchain, while few researchers pay attention to customize consistency algorithms. Moreover, there is a trade-off between security and performance in designing consensus mechanisms. We propose a novel consensus algorithm called proof of vote (PoV), where the distributed nodes controlled by consortium members could reach consensus and come to a decentralized arbitration by voting. PoV separates the voting rights and bookkeeping rights with the essential idea of establishing different security identities for network nodes. Contrary to the third-party intermediary or uncontrollable public awareness, the production and verification of PoV blocks are decided by the voting results among the core consortium members. We theoretically prove that PoV blocks can reach transaction finality by only one confirmation. Compared with the total traffic complexity of BFT-based consensus, PoV has just that of O(3Nc), which is a great improvement when the number of nodes is over 100.
IP protocol is the core of TCP/IP network layer. However, since IP address and its Domain Name are allocated and managed by a single agency, there are risks of centralization. The semantic overload of IP address also reduces its scalability and mobility, which further hinders the security. This paper proposes a co-governing Multi-Identifier Network (MIN) architecture that constructs a network layer with parallel coexistence of multiple identifiers, including identity, content, geographic information, and IP address. On the management plane, we develop an efficient management system using consortium blockchain with voting consensus, so the network can simultaneously manage and support by hundreds or thousands of nodes with high throughput. On the data plane, we propose an algorithm merging hash table and prefix tree (HTP) for FIB, which avoids the false-negative error and can inter-translate different identifiers with tens of billions of entries. Further, we propose a scheme to transport IP packets using CCN as a tunnel for supporting progressive deployment. We deployed the prototype of MIN to the largest operators' network in Mainland China, Hongkong and Macao, and demonstrated that the network can register identifier under co-governing consensus algorithm, support VoD service very well.
The current infrastructure and technology system of the Internet are facing major challenges in terms of intelligence, diversification, personalization, robustness, and efficiency. It is urgent to change the network infrastructure and build a polymorphic definable and intelligent network. This paper studies and judges the development trend of network technologies in China and abroad, proposes the development goal of polymorphic definable and intelligent network, and extracts a list of key cutting-edge technologies for foresight. Based on these, the development roadmap of polymorphic definable and intelligent network in China for 2035 is constructed. China should prospect the research and development of key technologies including network architecture, addressing and routing, full-dimensional definability, network intelligence, and network robust control, and guide the development of relevant industries through the key contents including core chips, products, and systems. Demonstration projects can be deployed to promote the implementation of intelligent network business, including projects concerning information infrastructure, vertical industry network, space–earth integrated network, ubiquitous interconnection of human and things. In addition, this paper proposes some suggestions on the guarantee measures of polymorphic definable and intelligent network in China from the aspects of policy guarantee, scientific research platform support and joint research, international communication expansion, and human resource cultivation and employment.
The Internet has become the essential infrastructure of modern society, while the centralized domain name system (DNS) is unable to provide high-quality services and secure government.Facing this challenge, we propose a reconfigurable multi-identifier network architecture and develop the prototype of the multi-identifier system.We optimize the network security using consortium blockchain, improve the forwarding speed using HPT for FIB, and enhance the scalability through tunnel algorithm.Experiments and testing of this prototype on the network of the two largest telecommunication service providers in China demonstrate that the system is robust enough to support real-world traffic.It can also be applied to sovereign network and other private networks with multiple identifiers, which may become a Chinese solution of the network security to the world.
The Internet has become the most important infrastructure of modern society, while the existing IP network is unable to provide high-quality service. The unilateralism IP network is unable to satisfy the Co-managing and Co-governing demands to Cyberspace for most Nations in the world as well. Facing this challenge, we propose a novel Decentralized Multilateral Co-Governing Post-IP Internet architecture. To verify its effectiveness, we develop the prototype on the operator's networks including China Mainland, Hong Kong, and Macao. The experiments and testing results show that this architecture is feasible for co-existing of Content-Centric Networking and IP network, and it might become a Chinese Solution to the world.
Side channel attack is the primary way to leak information between tenants in current cloud computing environment. However, existing Service Function Chain (SFC) deployment methods do not fully consider the side channel attack problem faced by the Virtual Network Function (VNF) in the multi-tenant environment. A SFC deployment method is proposed against side channel attack. A tenant classification strategy based on average time and a deployment strategy considering historical information are introduced. Under the resource constraints of the SFC, the optimization model is established with the goal of minimizing the number of servers that the tenant can cover. And a deployment algorithm is designed based on the greedy choice. The experimental results show that, compared with other deployment methods, this method can significantly improve the difficulty and cost of malicious tenant to realize co-residence, and reduces the risk of side channel attack faced by tenants.
In order to improve the utilization of the infrastructure resource and efficiently deploy the service function chain dynamically in network function virtualization, the orchestration management domain needs to monitor the network resources and virtual network function status in real time, but real-time monitoring will bring large communication overhead. An intelligent distributed monitoring strategy with minimal network communication overhead was proposed. The improved label propagation algorithm intelligently subnets and selects agent monitoring nodes to achieve efficient monitoring of resource and virtual function status and minimize monitoring information communication overhead. The simulation results show that the monitoring strategy proposed reduces the monitoring information communication overhead in the network by about 13%.
Taking into account the energy optimization and performance enhancement of the Content Centric Networking (CCN) comprehensively, an energy optimized implicit collaborative caching scheme for CCN is proposed. In terms of the caching decision, energy saving account is utilized as the judgement, which is carried out on consumer's remote nodes preferentially, and the data packet is utilized to carry the information of recent upstream caching hops, so as to realize the implicit collaboration, thus reducing the caching space competition pressure of the consumers' near nodes, improving the caching difference between nearby nodes. As for the caching replacement, the caching content with the minimum energy saving account is selected to be replaced, achieving the optimal energy consumption optimization effect. Simulation results show that, the caching scheme achieves better cache hit ratio and average routing hops, meanwhile, it reduces the network energy consumption effectively.
为提高软件定义的内容中心网络(SD-CCN)分域多控制器架构中的路由传输效率,减轻控制器的负载压力,设计了软件定义的内容中心网络的多域分段路由机制(MDSR).将基于内容名称的路由查找在控制平面执行,数据平面转换为基于节点标签的路由查找,上行链路经过的每个域的控制器选取最优路径并下发分段标签序列引导各自的域内路由,通过跨域节点对域标签的识别实现域间路由中继,从而以少量控制信息实现对上行链路的整体控制.仿真结果表明,本路由机制相比于随机转发等传统路由机制提高了缓存命中率,降低了平均请求时延及平均路由跳数.
为降低软件定义的内容中心网络(SD-CCN)的内容请求时延,减少网络拥塞,快速应对网络中的节点或链路故障,借用软件定义网络(SDN)流量工程中的分段路由思想设计了软件定义的内容中心网络的分段路由策略(SD-CCN-SR).通过控制器选取最优的缓存或内容源节点作为目的节点查找最优路径,向入口边界节点下发分段标签序列;将分段标签序列中的标签依次作为分段的目的节点进行最短路径转发,实现控制器通过少量控制信息对兴趣包上行链路的整体控制.仿真结果表明,本策略能够有效降低平均请求时延及平均路由跳数.
Aiming at the problem that current data center network transport mechanism lacks of comprehensive performance guarantee of soft real-time and high throughout for online data-intensive (OLDI) applications,this paper proposed LSTCP,a dynamic priority-based slack-aware transport control protocol for data center network that adopted the least slack first(LSF)scheduling strategy to prioritize flows.Based on the feedback of explicit congestion notification (ECN) mechanism,LSTCP dynamically adjusted congestion window according to the precedence of the flow and the extent of network congestion,thus implemented the priority scheduling for emergency flows and earlier deadline flows.Experiment results show that LSTCP reduces the AFCT(average flow completion time) of short flows and guarantees the throughput of long flows compared with the traditional deadline-aware TCP.
Network function virtualization technology improves the flexibility of service function chains' deployment.However,the virtual network functions are under the pressure of uncertain failures and malicious attacks.The existing redundant backup methods can solve the problem of VNF failures to some extent,it does not consider the defects of node homogeneity in the face of malicious attacks.A deployment method considering the heterogeneity of nodes was proposed,guaranteeing the heterogeneity of nodes when perform redundant backup and remapping.Simulation experiments demonstrate that the proposed method significantly increases attacker's attack time cost under the cost of the request acceptance rate decreases by 3.8% and the bandwidth consumption increase by 9.2% comparing to the homogeneity backup method.
Building a service function chain (SFC) based on Virtual Network Functions (VNFs) greatly improves the flexibility of network service deployment. However, compared to highly reliable carrier-grade proprietary hardware, VNF is facing a series of failure risks. Although the existing backup methods can solve the problem of VNF failure to some extent, malicious attacks can't be stopped totally because there is no consideration of the homogeneity of the original node and the backup nod. In this paper, we propose a heterogeneous backup deployment scheme. It ensures the heterogeneity of backup server nodes and VNF nodes with the original one during backup. We designed and implemented the corresponding deployment algorithm. Simulation results show that compared with the backup method without considering heterogeneity, our method increases attacker's attack time cost by 13.2% under the cost that the request acceptance rate decreases by 4.81%.
To deal with the high resolution latencies in current existing mapping system, a hierarchical mapping system is proposed based on active degree. In the system, the mappings between the identifiers and locators are divided into three levels: active level, neutral level, and constant level. Based on these, a three tiers system architecture for mapping entries storing and resolving is designed. Stored mapping entries in different levels vary with the different active degrees of the remote communication terminal, and flow from one level to another. In order to minimize the mapping resolution latency, the construction model is proposed, which models the system construction process as a Markov Decision Process (MDP). Moreover, a Markov decision construction algorithm is proposed, which improves reinforcement learning to get the global optimal or near-optimal construction strategy. The simulation results show that the system has low resolve latency and good adaptability for network topology dynamic changes.
With the increase of network traffic, commercial servers where virtual network functions are deployed often take the unbalanced load. To solve this problem, a virtual network function migration strategy based on resource utility maximization was proposed to realize maximal utility of the network resources. Firstly, this paper modeled the problem as a resources utility maximization problem according to different requirements of different virtual network functions for the resources. Secondly, the Upper Confidence Tree algorithm based on maximum value was designed to solve the model. Finally, the simulation results show the effectiveness and reliability of the proposed strategy. The results show that our method can improve the utilization rate of the server resources by about 22%, which is higher than the other method by about 11%.
To identify the key node is very important to improve the operation efficiency and computing capability in the industry control network, so it is important to strengthen the identification of key nodes. As a type of complex network, there exists many disadvantages in identification method of the key node in industrial control network, such as insensitive to the network size, unable to obtain the nodes weights and so on. In this paper we optimized the degree and betweenness, proposed the degree index and betweenness index, and got the weights of the nodes in the networks by these two synthesized indexes. Finally, through the ranking of nodes weights, digging out one or more the most important nodes, which are the key nodes of the network. The method can quantify the important extent of nodes and avoid sidedness of single evaluation method. Experiments showed that the method is feasible and efficient, computing ability get well improved.
流数估计是网络管控的重要参考尺度,对网络流量全局特征信息的深入挖掘具有重要意义.针对目前已有的多种估计算法以过度消耗测量设备存储资源和计算资源提高估计精度的缺陷,采用报文抽样技术,提出一种新的迭代收敛型估计算法.实验测试表明,该算法在估计精度和内存消耗上优于EM算法,在迭代更新上优于Iteration算法.