计算机与现代化 ›› 2022, Vol. 0 ›› Issue (12): 102-110.

• 信息安全 • 上一篇    下一篇

一种基于路径跟踪反馈的SDN网络可信传输方案

  

  1. (1.南京航空航天大学计算机科学与技术学院,江苏南京211106;2.上海航天电子技术研究所,上海201109)
  • 出版日期:2023-01-04 发布日期:2023-01-04
  • 作者简介:高枫(1997—),男,江苏靖江人,硕士研究生,研究方向:软件定义网络,可信计算,E-mail: 1367078791@qq.com; 通信作者:庄毅(1956—),女,教授,博士生导师,研究方向:网络安全,分布计算,E-mail: zy16@nuaa.edu.cn。
  • 基金资助:
    国家自然科学基金资助项目(61572253)

A Trusted Transmission Scheme of SDN Based on Path Tracking Feedback

  1. (1. College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106, China;
    2. Shanghai Aerospace Electronic Technology Institute, Shanghai 201109, China)
  • Online:2023-01-04 Published:2023-01-04

摘要: 针对软件定义网络(SDN)中的转发设备存在不可避免的漏洞和后门、缺乏主动监测或被动检查网络行为的机制等问题,提出一种基于路径跟踪反馈的SDN网络可信传输方案,设计基于跟踪反馈的传输路径可信验证机制,依据反馈信息分析节点的可信性,以此评估路径的可信度;同时,提出一种基于路径跟踪反馈的不相交多路径可信路由算法DMTRA-PTF,能够通过路径跟踪反馈和可信评估引导新的路径及时规避恶意交换机节点,构造不相交多路径路由方案以增强SDN网络传输服务的可信性。对比实验结果表明,路径跟踪反馈机制能够以较小的性能代价准确识别恶意交换机,提出的可信路由算法能够以此为后续路由动态规划不相交多条可信路径,有效提升网络整体的可信性。

关键词: 路径跟踪反馈, 软件定义网络, 可信性分析, 多路径, 可信传输

Abstract: To address the problems with software defined network, such as the inevitable loopholes in the forwarding equipment and the lack of mechanisms for the controller to actively check network behaviors, a trusted transmission scheme of the SDN based on path tracking feedback is proposed. A transmission path trust verification mechanism based on tracking feedback is proposed in the scheme. Based on the feedback information, the credibility of the node is analyzed and the credibility of the path is evaluated. At the same time, a disjoint multi-path trusted routing algorithm DMTRA-PTF based on path tracking feedback is proposed to avoid malicious switch nodes through path tracking feedback and trusted evaluation, so as to construct disjoint multipath routing scheme to enhance the reliability of SDN transmission service. The experimental results show that the path tracking feedback mechanism can accurately identify the malicious switch with a small performance cost, and the trusted routing algorithm proposed in this paper can dynamically plan disjoint multiple trusted paths for subsequent routes, which can effectively improve the credibility of the whole network.

Key words: path tracking feedback, software defined network, trustworthiness analysis, multipath; , trusted transmission