期刊文献+

基于SDN互联网出口安全资源池的建设与研究 被引量:1

Construction and research of internet exit security resource pool based on SDN
在线阅读 下载PDF
导出
摘要 [目的/意义]在企业业务应用推进数字化转型过程中,来自网络安全的挑战日趋严峻,为守住企业网络的第一道安全防线,基于软件定义网络(Software Defined Network,SDN)架构技术,提出大型企业互联网出口安全资源池解决方案.[方法/过程]基于对流量进行动态编排设计,使不同业务流量流经预定义设备,提升安全防护效能、池化管理对安全设备的统一调配,实现安全策略的自动化控制和精准安全防护.[结果/结论]互联网出口安全资源池解决方案,解决了传统网络安全架构的不足,满足了企业各类业务日益增长的网络安全需求,应用价值较高. [Purpose/Significance]In the process of promoting the digital transformation of enterprise business applications,the challenges from Network security are becoming more and more severe.In order to defend the first line of defense of enterprise Network,this paper proposes a solution for the security resource pooling of large enterprise Internet export based on Software Defined Network(SDN)architecture technology.[Results/Conclusion]Based on the dynamic orchestration and design of traffic,different business traffic flows through predefined devices to improve security protection efficiency;Pooling management implements unified deployment of security devices to realize automatic control of security policies and precise security protection.[Results/Conclusion]Based on the actual application results of enterprise Internet egress,the Internet egress security resource pool solution solves the shortcomings of traditional security architectures,meets the growing network security requirements of various enterprises,and has high application value.
作者 曹然 蔡佳明 潘萌 陈光 Cao Ran;Cai Jiaming;Pan Meng;Chen Guang(Kunlun Digital Technology Co.,Ltd.,Beijing 102200;Petrochina International Iraq FZE(West Quran),Bei jing 100034)
出处 《网络空间安全》 2022年第5期59-63,共5页 Cyberspace Security
关键词 软件定义网络架构 网络安全 业务链 安全资源池 网络服务报头 SDN architecture network security service chain security resource pool network service header
作者简介 曹然(1985-),男,汉族,河北石家庄人,北京信息工程学院,本科,昆仑数智科技有限责任公司,工程师,主要研究方向和关注领域:网络安全;蔡佳明(1977-),男,汉族,江苏盐城人,中国石油大学(华东),本科,中油国际(伊拉克)西古尔纳公司,工程师,主要研究方向和关注领域:计算机技术与应用;潘萌(1985-),女,汉族,河北保定人,唐山学院,本科,昆仑数智科技有限责任公司,工程师,主要研究方向和关注领域:网络安全;陈光(1987-),男,汉族,河北保定人,北京邮电大学,本科,昆仑数智科技有限责任公司,工程师,主要研究方向和关注领域:网络安全。
  • 相关文献

参考文献5

二级参考文献120

  • 1Mckeown N, Anderson T, Balakrishnan H, Parulkar G, Peterson L, Rexford J, Shenker S, Turner J. OpenFlow: Enabling innovation in campus networks. ACM SIGCOMM Computer Communication Review, 2008,38(2):69-74. [doi: 10.1145/1355734. 1355746].
  • 2Elliott C. GENI: Opening up new classes of experiments in global networking. IEEE Internet Computing, 2010,14(1):39-42.
  • 3Gavras A, Karila A, Fdida S, May M, Potts M. Future Internet research and experimentation: The FIRE initiative. ACM SIGCOMM Computer Communication Review, 2007,37(3):89-92. [doi: 10.114511273445.1273460].
  • 4JGN2plus. 2012. http://www.jgn.nict.go.jp/english/index.html.
  • 5SOFIA. 2012. http://fi.ict.ac.cn/research/sofia_overview.htm.
  • 6Yang L, Dantu R, Anderson T, Gopal R. Forwarding and Control Element Separation (ForCES) Framework. RFC 3746, 2004. http://tools.ietf.org/html/rfc3746.
  • 7Greenberg A, Hjalmtysson G, Maltz DA, Myers A, Rexford J, Xie G, Yan H, Zhan J, Zhang H. A clean slate 4D approach to network control and management. ACM SIGCOMM Computer Communication Review, 2005,35(5):41-54. [doi: 10.1145/1096536. 1096541].
  • 8Caesar M, Caldwell D, Feamster N, Rexford J, Shaikh A, Merwe J. Design and implementation of a routing control platform. In: Proc. of the 2rd USENIX Symp. on Networked Systems Design and Implementation (NSDI). Boston: USENIX Association, 2005. 15-28.
  • 9Casado M, Garfinkel T, Akella A, Freedman MJ, Boneh D, Mckeown N, Shenker S. SANE: A protection architecture for enterprise networks. In: Proc. of the 15th Conf. on USENIX Security Symp. Vancouver: USENIX Association, 2006. 137-151.
  • 10Casado M, Freedman MJ, Pettit J, Luo J, Mckeown N, Shenker S. Ethane: Taking control of the enterprise. In: Proc. of the SIGCOMM 2007. Kyoto: ACM Press, 2007. 1-12. [doi: 10.1145/1282380.1282382].

共引文献545

同被引文献8

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部