This paper puts forward the plan on constructing information security attack and defense platform based on cloud computing and virtualization, provides the hardware topology structure of the platform and technical fra...This paper puts forward the plan on constructing information security attack and defense platform based on cloud computing and virtualization, provides the hardware topology structure of the platform and technical framework of the system and the experimental process and technical principle of the platform. The experiment platform can provide more than 20 attack classes. Using the virtualization technology can build hypothesized target of various types in the laboratory and diversified network structure to carry out attack and defense experiment.展开更多
Based on the analysis of the security problems existing in the cloud platform of the data center, this paper proposes a set of cloud platform security protection scheme being with virtualization technology. This paper...Based on the analysis of the security problems existing in the cloud platform of the data center, this paper proposes a set of cloud platform security protection scheme being with virtualization technology. This paper focuses on the overall architecture of cloud platform as well as the design of virtualization security architecture. Meantime, it introduces the key technologies of VXLAN in detail. The scheme realizes flexible scheduling of security resources through virtual pooling of independent security gateway and virtual machine isolation through VXLAN technology. Moreover, it guides all horizontal traffic to independent security gateway for processing, unified management of security gateway through cloud platform by using Huawei NSH business chain technology. This scheme effectively solves the horizontal transmission of security threat among virtual machines, and realizes the fine security control and protection for the campus data center.展开更多
With ever-increasing applications of IoT, and due to the heterogeneous and bursty nature of these applications, scalability has become an important research issue in building cloud-based IoT/M2M systems. This research...With ever-increasing applications of IoT, and due to the heterogeneous and bursty nature of these applications, scalability has become an important research issue in building cloud-based IoT/M2M systems. This research proposes a dynamic SDN-based network slicing mechanism to tackle the scalability problems caused by such heterogeneity and fluctuation of IoT application requirements. The proposed method can automatically create a network slice on-the-fly for each new type of IoT application and adjust the QoS characteristics of the slice dynamically according to the changing requirements </span><span style="font-family:Verdana;">of an IoT application. Validated with extensive experiments, the proposed me</span><span style="font-family:Verdana;">chanism demonstrates better platform scalability when compared to a static slicing system.展开更多
随着网络攻击日益频繁和复杂,入侵检测系统(IDS)在网络安全防护中扮演着至关重要的角色。提出了一种基于EVE-NG(emulated virtual environment next generation)的虚拟网络实验平台,并使用Vue前端框架构建了高可用性的用户界面,用于模...随着网络攻击日益频繁和复杂,入侵检测系统(IDS)在网络安全防护中扮演着至关重要的角色。提出了一种基于EVE-NG(emulated virtual environment next generation)的虚拟网络实验平台,并使用Vue前端框架构建了高可用性的用户界面,用于模拟真实网络环境并进行入侵检测实验。通过在虚拟环境中灵活搭建多种网络拓扑和设备,学生能够模拟不同攻击场景,并通过友好的用户界面实时监控和分析检测系统性能。结果表明,该平台不仅降低了实验成本,提升了实验的灵活性和可重复性,还为网络安全虚拟仿真实验提供了高效的解决方案。展开更多
随着化工行业朝着智能化方向发展,化工反应系统频繁遭受网络攻击,产生了严重的后果。现有工控安全仿真研究大多单独在网络领域进行,缺少针对化工反应系统的工控安全仿真技术。因此,针对该问题,以化工反应系统中常见的连续搅拌式反应釜(c...随着化工行业朝着智能化方向发展,化工反应系统频繁遭受网络攻击,产生了严重的后果。现有工控安全仿真研究大多单独在网络领域进行,缺少针对化工反应系统的工控安全仿真技术。因此,针对该问题,以化工反应系统中常见的连续搅拌式反应釜(continuous stirred tank reactor,CSTR)为研究对象,提出一种针对CSTR的工控安全虚实融合仿真技术。首先建立CSTR控制系统模型,提出了基于攻击类型分析、攻击仿真方法、响应分析方法与攻击监测和控制方法的工控安全虚实融合仿真技术框架,利用CSTR工控安全仿真平台,实现了针对CSTR系统的攻击模拟和响应分析,并验证了提出的针对网络攻击的监测和控制方法,为推动网络安全在化工领域内的研究提供了借鉴。展开更多
快速发展的互联网技术推动着媒体行业的变革,进而催生出融媒云平台。融媒云平台通过整合多种媒体资源,可提供一站式的服务。但传统网络架构在很多方面面临挑战,如可扩展性、灵活性和安全性等。软件定义网络(Software Defined Networking...快速发展的互联网技术推动着媒体行业的变革,进而催生出融媒云平台。融媒云平台通过整合多种媒体资源,可提供一站式的服务。但传统网络架构在很多方面面临挑战,如可扩展性、灵活性和安全性等。软件定义网络(Software Defined Networking,SDN)技术的出现为解决这些问题提供了新的思路。SDN作为一种新型网络架构模型,通过分离控制平面和数据平面,可提供更加灵活、可编程的网络管理方式,非常适合应用于融媒体平台。简要介绍SDN技术,并就SDN在融媒云平台中的应用及相关案例进行分析,以供参考。展开更多
文摘This paper puts forward the plan on constructing information security attack and defense platform based on cloud computing and virtualization, provides the hardware topology structure of the platform and technical framework of the system and the experimental process and technical principle of the platform. The experiment platform can provide more than 20 attack classes. Using the virtualization technology can build hypothesized target of various types in the laboratory and diversified network structure to carry out attack and defense experiment.
文摘Based on the analysis of the security problems existing in the cloud platform of the data center, this paper proposes a set of cloud platform security protection scheme being with virtualization technology. This paper focuses on the overall architecture of cloud platform as well as the design of virtualization security architecture. Meantime, it introduces the key technologies of VXLAN in detail. The scheme realizes flexible scheduling of security resources through virtual pooling of independent security gateway and virtual machine isolation through VXLAN technology. Moreover, it guides all horizontal traffic to independent security gateway for processing, unified management of security gateway through cloud platform by using Huawei NSH business chain technology. This scheme effectively solves the horizontal transmission of security threat among virtual machines, and realizes the fine security control and protection for the campus data center.
文摘With ever-increasing applications of IoT, and due to the heterogeneous and bursty nature of these applications, scalability has become an important research issue in building cloud-based IoT/M2M systems. This research proposes a dynamic SDN-based network slicing mechanism to tackle the scalability problems caused by such heterogeneity and fluctuation of IoT application requirements. The proposed method can automatically create a network slice on-the-fly for each new type of IoT application and adjust the QoS characteristics of the slice dynamically according to the changing requirements </span><span style="font-family:Verdana;">of an IoT application. Validated with extensive experiments, the proposed me</span><span style="font-family:Verdana;">chanism demonstrates better platform scalability when compared to a static slicing system.
文摘随着网络攻击日益频繁和复杂,入侵检测系统(IDS)在网络安全防护中扮演着至关重要的角色。提出了一种基于EVE-NG(emulated virtual environment next generation)的虚拟网络实验平台,并使用Vue前端框架构建了高可用性的用户界面,用于模拟真实网络环境并进行入侵检测实验。通过在虚拟环境中灵活搭建多种网络拓扑和设备,学生能够模拟不同攻击场景,并通过友好的用户界面实时监控和分析检测系统性能。结果表明,该平台不仅降低了实验成本,提升了实验的灵活性和可重复性,还为网络安全虚拟仿真实验提供了高效的解决方案。
文摘随着化工行业朝着智能化方向发展,化工反应系统频繁遭受网络攻击,产生了严重的后果。现有工控安全仿真研究大多单独在网络领域进行,缺少针对化工反应系统的工控安全仿真技术。因此,针对该问题,以化工反应系统中常见的连续搅拌式反应釜(continuous stirred tank reactor,CSTR)为研究对象,提出一种针对CSTR的工控安全虚实融合仿真技术。首先建立CSTR控制系统模型,提出了基于攻击类型分析、攻击仿真方法、响应分析方法与攻击监测和控制方法的工控安全虚实融合仿真技术框架,利用CSTR工控安全仿真平台,实现了针对CSTR系统的攻击模拟和响应分析,并验证了提出的针对网络攻击的监测和控制方法,为推动网络安全在化工领域内的研究提供了借鉴。
文摘快速发展的互联网技术推动着媒体行业的变革,进而催生出融媒云平台。融媒云平台通过整合多种媒体资源,可提供一站式的服务。但传统网络架构在很多方面面临挑战,如可扩展性、灵活性和安全性等。软件定义网络(Software Defined Networking,SDN)技术的出现为解决这些问题提供了新的思路。SDN作为一种新型网络架构模型,通过分离控制平面和数据平面,可提供更加灵活、可编程的网络管理方式,非常适合应用于融媒体平台。简要介绍SDN技术,并就SDN在融媒云平台中的应用及相关案例进行分析,以供参考。