作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程

• 安全技术 • 上一篇    下一篇

基于组策略的SDN多粒度流量检测系统

杜瑞颖1a,胡力1a,陈晶1b,陈炯2   

  1. (1.武汉大学 a.空天信息安全与可信计算教育部重点实验室; b.软件工程国家重点实验室,武汉 430072; 2.湖北省人民检察院 检察技术信息处,武汉 430072)
  • 收稿日期:2016-02-24 出版日期:2017-04-15 发布日期:2017-04-14
  • 作者简介:杜瑞颖(1964—),女,教授、博士、博士生导师,主研方向为网络安全;胡力,硕士研究生;陈晶,副教授、博士生导师;陈炯,硕士研究生。
  • 基金资助:
    国家自然科学基金(61572380);最高人民检察院技术信息研究中心中央级公益性科研院所基本科研业务费专项资金(JBKY 20150620)。

Multi-granularity Traffic Detection System of Group Based Policy for SDN

DU Ruiying  1a,HU Li  1a,CHEN Jing  1b,CHEN Jiong  2   

  1. (1a.Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education; 1b.State Key Lab of Software Engineering,Wuhan University,Wuhan 430072,China; 2.Procuratorial Technical Information Office,The People’s Procuratorate of Hubei,Wuhan 430072,China)
  • Received:2016-02-24 Online:2017-04-15 Published:2017-04-14

摘要: 为提升软件定义网络(SDN)的网络控制力和安全性,通常利用SDN集中管控及流表控制特性开发大量安全应用,但此类安全应用实现功能单一、防护粒度粗,无法对整个网络形成综合防护。针对该问题,设计多粒度流量检测系统。借鉴组策略(GBP)的分组思想对基础设施层进行分组管理,基于模块链实现安全检测功能由硬件设备向软件服务的转型,定义安全检测模块的概念并将其划分为统计型检测、关联匹配型检测以及正则匹配型检测3类模块。利用GBP生成模块链,由模块链调动不同的安全检测模块组合,从而实现多粒度安全检测。通过实验验证了该系统在SDN环境下的可用性,并表明其具有检测粒度细、可扩展性好等特点。

关键词: 软件定义网络, 基于组策略, 模块链, 安全检测模块, 流量检测

Abstract: In order to improve the network control ability and security,researchers usually utilize the features of centralized control and flow table control of Software Defined Network(SDN) to develop a lot of security applications.However,those security applications concentrate on single function and have coarse protection granularity,which cannot form comprehensive protection for the whole network.Aiming at the problem,this paper designs multi-granularity traffic identification system.It manages the infrastructure layer by group based on the thinking of Group Based Policy(GBP),defines the notion of module chain to realize the transition from hardware to software service for security detection,defines the notion of security detection module and classifies it into three modules including statistical detection module,correlation matching module and regular expression matching module.DBP is used to generate module chain and then the different security detection combination module is mobilized by the module chain to implement multi-granularity security detection.The usability of the system in SDN environment is verified by experiments,and it has the characteristics of fine granularity and good expansibility.

Key words: Software Defined Network(SDN), Group Based Policy(GBP), module chain, security detection module, traffic detection

中图分类号: