作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2021, Vol. 47 ›› Issue (12): 30-39. doi: 10.19678/j.issn.1000-3428.0061203

• 热点与综述 • 上一篇    下一篇

面向云网融合SaaS安全的虚拟网络功能映射方法

李凌书, 邬江兴   

  1. 解放军信息工程大学 国家数字交换系统工程技术研究中心, 郑州 450002
  • 收稿日期:2021-03-19 修回日期:2021-05-27 发布日期:2021-05-28
  • 作者简介:李凌书(1992-),男,博士研究生,主研方向为网络空间安全、云计算;邬江兴,教授、博士生导师。
  • 基金资助:
    国家自然科学基金(62002383);国家重点研发计划(2018YFB0804004)。

SaaS Security Oriented Virtual Network Function Embedding Method Under Cloud-Network Integration

LI Lingshu, WU Jiangxing   

  1. National Digital Switching System Engineering & Technological R&D Center, PLA Information Engineering University, Zhengzhou 450002, China
  • Received:2021-03-19 Revised:2021-05-27 Published:2021-05-28

摘要: 在云网融合背景下,承载软件即服务(SaaS)业务功能的云基础设施可能横跨多个数据中心和归属网络,难以保证云资源安全可控。为缩短SaaS业务服务的处理时延,设计基于冗余执行和交叉检验的SaaS组合服务模式,并对容器、Hypervisor和云基础设施的安全威胁进行建模,建立拟态化虚拟网络功能映射模型和安全性优化机制。在此基础上,提出基于近端策略优化的PJM算法。实验结果表明,与CCMF、JEGA和QVNE算法相比,PJM算法在满足安全性约束的条件下,能够降低约12.2%业务端到端时延。

关键词: 云计算, 软件即服务, 云网融合, 虚拟网络映射, 网络空间拟态防御, 服务功能链, 近端策略优化

Abstract: In the context of cloud-network integration, the cloud infrastructure carrying Software as a Service(SaaS) business functions may span multiple data centers and home networks, which adds difficulty to the security and controllability of cloud resources.In order to reduce the processing delay of SaaS business services, the SaaS composite service mode is designed based on redundant execution and cross inspection.The security threats of container, Hypervisor and cloud infrastructure are modeled, and the Mimetic Virtural Network Function Embedding(MVNE) model and the security optimization mechanism are established.On this basis, the PJM algorithm based on proximal strategy optimization is proposed.The experimental results show that, compared with CCMF, JEGA and QVNE algorithms, the PJM algorithm can reduce the end-to-end delay of services by about 12.2% under the security constraints.

Key words: cloud computing, Software as a Service(SaaS), cloud-network integration, Virtual Network Embedding(VNE), Cyber Mimic Defense(CMD), Service Function Chain(SFC), Proximal Policy Optimization(PPO)

中图分类号: