为解决高密度无线局域网中接入拥塞、资源失衡及流量混传导致的性能瓶颈问题,从接入层面、资源层面及流量层面分析无线局域网接入拥塞问题,并从3个层面提出基于软件定义网络(Software Defined Network,SDN)流量调度的应对策略。实践案...为解决高密度无线局域网中接入拥塞、资源失衡及流量混传导致的性能瓶颈问题,从接入层面、资源层面及流量层面分析无线局域网接入拥塞问题,并从3个层面提出基于软件定义网络(Software Defined Network,SDN)流量调度的应对策略。实践案例验证了该策略在提升网络吞吐量、降低传输时延方面具有明显成效。展开更多
目的/意义建设基于软件定义网络(software defined networking,SDN)架构的网络安全平台,以增强医院云计算安全防护。方法/过程基于SDN架构构建网络安全平台,并与入侵检测系统联动形成主动防御系统。对比分析平台应用前后租户横向攻击数...目的/意义建设基于软件定义网络(software defined networking,SDN)架构的网络安全平台,以增强医院云计算安全防护。方法/过程基于SDN架构构建网络安全平台,并与入侵检测系统联动形成主动防御系统。对比分析平台应用前后租户横向攻击数量、攻击成功率、策略无阻断业务数、勒索软件加密数据量和安全团队操作工时等指标,验证平台的有效性。结果/结论基于SDN架构的网络安全平台可有效识别并阻断恶意流量,增强对医院云计算的安全防护。展开更多
软件定义网络(software-defined networks,SDN)流量调度提升网络性能和资源利用率、实现节能和负载均衡至关重要.传统的多目标优化算法在高流量和网络动态性增加的情况下显著影响算法的收敛速度,难以满足复杂网络环境的多样化需求.针对...软件定义网络(software-defined networks,SDN)流量调度提升网络性能和资源利用率、实现节能和负载均衡至关重要.传统的多目标优化算法在高流量和网络动态性增加的情况下显著影响算法的收敛速度,难以满足复杂网络环境的多样化需求.针对此问题,提出了一种基于深度强化学习的流量预测在线路由算法——OTPR-DRL:根据流量特征预测关键流和普通流,结合网络状态和流量信息建立线性规划问题获得关键流路由的最优解.为满足普通流不同服务质量(quality of service,QoS)需求,引入通用效用函数实现多目标优化,通过多智能体和优先级经验回放机制为普通流选择路由.实验结果表明,在高流量强度下,OTPR-DRL与现有的算法相比,提高了收敛速度,至少降低了10.26%的网络传输时延,3.09%的丢包率,提高了1.70%的吞吐率.展开更多
Cyber-Physical System (CPS) devices are increasing exponentially. Lacking confidentiality creates a vulnerable network. Thus, demanding the overall system with the latest and robust solutions for the defence mechanism...Cyber-Physical System (CPS) devices are increasing exponentially. Lacking confidentiality creates a vulnerable network. Thus, demanding the overall system with the latest and robust solutions for the defence mechanisms with low computation cost, increased integrity, and surveillance. The proposal of a mechanism that utilizes the features of authenticity measures using the Destination Sequence Distance Vector (DSDV) routing protocol which applies to the multi-WSN (Wireless Sensor Network) of IoT devices in CPS which is developed for the Device-to-Device (D2D) authentication developed from the local-chain and public chain respectively combined with the Software Defined Networking (SDN) control and monitoring system using switches and controllers that will route the packets through the network, identify any false nodes, take preventive measures against them and preventing them for any future problems. Next, the system is powered by Blockchain cryptographic features by utilizing the TrustChain features to create a private, secure, and temper-free ledger of the transactions performed inside the network. Results are achieved in the legitimate devices connecting to the network, transferring their packets to their destination under supervision, reporting whenever a false node is causing hurdles, and recording the transactions for temper-proof records. Evaluation results based on 1000+ transactions illustrate that the proposed mechanism not only outshines most aspects of Cyber-Physical systems but also consumes less computation power with a low latency of 0.1 seconds only.展开更多
我国城市轨道交通业务逐步向云平台集中,对网络时延、可靠性和资源调度能力提出了更高要求,而传统网络架构在多业务并发和高负载场景下的灵活性不足,故障恢复时间较长。针对该问题,将软件定义网络(Software Defined Network,SDN)技术引...我国城市轨道交通业务逐步向云平台集中,对网络时延、可靠性和资源调度能力提出了更高要求,而传统网络架构在多业务并发和高负载场景下的灵活性不足,故障恢复时间较长。针对该问题,将软件定义网络(Software Defined Network,SDN)技术引入城市轨道交通中心云,构建基于Spine-Leaf拓扑的SDN网络架构,并结合OpenFlow流表控制与虚拟扩展局域网(Virtual Extensible Local Area Network,VXLAN)实现网络统一调度。研究结果表明,相较于传统网络架构,SDN技术能够有效提升城市轨道交通云平台的网络性能和运维效率,为轨道交通智能化发展提供有力支撑。展开更多
当前移动互联的社会背景与网络环境对移动数据的管理与相关网络的建设提出更高要求,中国移动需要采取合理措施持续优化数据中心与软件定义网络(software defined network,SDN),确保满足最新的移动互联发展需求。基于此,概述中国移动数...当前移动互联的社会背景与网络环境对移动数据的管理与相关网络的建设提出更高要求,中国移动需要采取合理措施持续优化数据中心与软件定义网络(software defined network,SDN),确保满足最新的移动互联发展需求。基于此,概述中国移动数据中心与SDN,深入探讨中国移动数据中心SDN架构构建策略与技术应用要点,以供相关人员参考。展开更多
The convergence of Software Defined Networking(SDN)in Internet of Vehicles(IoV)enables a flexible,programmable,and globally visible network control architecture across Road Side Units(RSUs),cloud servers,and automobil...The convergence of Software Defined Networking(SDN)in Internet of Vehicles(IoV)enables a flexible,programmable,and globally visible network control architecture across Road Side Units(RSUs),cloud servers,and automobiles.While this integration enhances scalability and safety,it also raises sophisticated cyberthreats,particularly Distributed Denial of Service(DDoS)attacks.Traditional rule-based anomaly detection methods often struggle to detectmodern low-and-slowDDoS patterns,thereby leading to higher false positives.To this end,this study proposes an explainable hybrid framework to detect DDoS attacks in SDN-enabled IoV(SDN-IoV).The hybrid framework utilizes a Residual Network(ResNet)to capture spatial correlations and a Bi-Long Short-Term Memory(BiLSTM)to capture both forward and backward temporal dependencies in high-dimensional input patterns.To ensure transparency and trustworthiness,themodel integrates the Explainable AI(XAI)technique,i.e.,SHapley Additive exPlanations(SHAP).SHAP highlights the contribution of each feature during the decision-making process,facilitating security analysts to understand the rationale behind the attack classification decision.The SDN-IoV environment is created in Mininet-WiFi and SUMO,and the hybrid model is trained on the CICDDoS2019 security dataset.The simulation results reveal the efficacy of the proposed model in terms of standard performance metrics compared to similar baseline methods.展开更多
文摘为解决高密度无线局域网中接入拥塞、资源失衡及流量混传导致的性能瓶颈问题,从接入层面、资源层面及流量层面分析无线局域网接入拥塞问题,并从3个层面提出基于软件定义网络(Software Defined Network,SDN)流量调度的应对策略。实践案例验证了该策略在提升网络吞吐量、降低传输时延方面具有明显成效。
文摘目的/意义建设基于软件定义网络(software defined networking,SDN)架构的网络安全平台,以增强医院云计算安全防护。方法/过程基于SDN架构构建网络安全平台,并与入侵检测系统联动形成主动防御系统。对比分析平台应用前后租户横向攻击数量、攻击成功率、策略无阻断业务数、勒索软件加密数据量和安全团队操作工时等指标,验证平台的有效性。结果/结论基于SDN架构的网络安全平台可有效识别并阻断恶意流量,增强对医院云计算的安全防护。
文摘软件定义网络(software-defined networks,SDN)流量调度提升网络性能和资源利用率、实现节能和负载均衡至关重要.传统的多目标优化算法在高流量和网络动态性增加的情况下显著影响算法的收敛速度,难以满足复杂网络环境的多样化需求.针对此问题,提出了一种基于深度强化学习的流量预测在线路由算法——OTPR-DRL:根据流量特征预测关键流和普通流,结合网络状态和流量信息建立线性规划问题获得关键流路由的最优解.为满足普通流不同服务质量(quality of service,QoS)需求,引入通用效用函数实现多目标优化,通过多智能体和优先级经验回放机制为普通流选择路由.实验结果表明,在高流量强度下,OTPR-DRL与现有的算法相比,提高了收敛速度,至少降低了10.26%的网络传输时延,3.09%的丢包率,提高了1.70%的吞吐率.
基金funded by Ajman University,AU-Funded Research Grant 2023-IRG-ENIT-22.
文摘Cyber-Physical System (CPS) devices are increasing exponentially. Lacking confidentiality creates a vulnerable network. Thus, demanding the overall system with the latest and robust solutions for the defence mechanisms with low computation cost, increased integrity, and surveillance. The proposal of a mechanism that utilizes the features of authenticity measures using the Destination Sequence Distance Vector (DSDV) routing protocol which applies to the multi-WSN (Wireless Sensor Network) of IoT devices in CPS which is developed for the Device-to-Device (D2D) authentication developed from the local-chain and public chain respectively combined with the Software Defined Networking (SDN) control and monitoring system using switches and controllers that will route the packets through the network, identify any false nodes, take preventive measures against them and preventing them for any future problems. Next, the system is powered by Blockchain cryptographic features by utilizing the TrustChain features to create a private, secure, and temper-free ledger of the transactions performed inside the network. Results are achieved in the legitimate devices connecting to the network, transferring their packets to their destination under supervision, reporting whenever a false node is causing hurdles, and recording the transactions for temper-proof records. Evaluation results based on 1000+ transactions illustrate that the proposed mechanism not only outshines most aspects of Cyber-Physical systems but also consumes less computation power with a low latency of 0.1 seconds only.
文摘我国城市轨道交通业务逐步向云平台集中,对网络时延、可靠性和资源调度能力提出了更高要求,而传统网络架构在多业务并发和高负载场景下的灵活性不足,故障恢复时间较长。针对该问题,将软件定义网络(Software Defined Network,SDN)技术引入城市轨道交通中心云,构建基于Spine-Leaf拓扑的SDN网络架构,并结合OpenFlow流表控制与虚拟扩展局域网(Virtual Extensible Local Area Network,VXLAN)实现网络统一调度。研究结果表明,相较于传统网络架构,SDN技术能够有效提升城市轨道交通云平台的网络性能和运维效率,为轨道交通智能化发展提供有力支撑。
文摘当前移动互联的社会背景与网络环境对移动数据的管理与相关网络的建设提出更高要求,中国移动需要采取合理措施持续优化数据中心与软件定义网络(software defined network,SDN),确保满足最新的移动互联发展需求。基于此,概述中国移动数据中心与SDN,深入探讨中国移动数据中心SDN架构构建策略与技术应用要点,以供相关人员参考。
基金extend their appreciation to the Princess Nourah bint Abdulrahman University Researchers Supporting Project number(PNURSP2026R760)Princess Nourah bint Abdulrahman University,Riyadh,Saudi Arabia.The authors also extend their appreciation to the Deanship of Research and Graduate Studies at King Khalid University for funding this work through small group research under grant number RGP2/714/46.
文摘The convergence of Software Defined Networking(SDN)in Internet of Vehicles(IoV)enables a flexible,programmable,and globally visible network control architecture across Road Side Units(RSUs),cloud servers,and automobiles.While this integration enhances scalability and safety,it also raises sophisticated cyberthreats,particularly Distributed Denial of Service(DDoS)attacks.Traditional rule-based anomaly detection methods often struggle to detectmodern low-and-slowDDoS patterns,thereby leading to higher false positives.To this end,this study proposes an explainable hybrid framework to detect DDoS attacks in SDN-enabled IoV(SDN-IoV).The hybrid framework utilizes a Residual Network(ResNet)to capture spatial correlations and a Bi-Long Short-Term Memory(BiLSTM)to capture both forward and backward temporal dependencies in high-dimensional input patterns.To ensure transparency and trustworthiness,themodel integrates the Explainable AI(XAI)technique,i.e.,SHapley Additive exPlanations(SHAP).SHAP highlights the contribution of each feature during the decision-making process,facilitating security analysts to understand the rationale behind the attack classification decision.The SDN-IoV environment is created in Mininet-WiFi and SUMO,and the hybrid model is trained on the CICDDoS2019 security dataset.The simulation results reveal the efficacy of the proposed model in terms of standard performance metrics compared to similar baseline methods.