As a novel architecture,software-defined networking(SDN) is viewed as the key technology of future networking.The core idea of SDN is to decouple the control plane and the data plane,enabling centralized,flexible,and ...As a novel architecture,software-defined networking(SDN) is viewed as the key technology of future networking.The core idea of SDN is to decouple the control plane and the data plane,enabling centralized,flexible,and programmable network control.Although local area networks like data center networks have benefited from SDN,it is still a problem to deploy SDN in wide area networks(WANs) or large-scale networks.Existing works show that multiple controllers are required in WANs with each covering one small SDN domain.However,the problems of SDN domain partition and controller placement should be further addressed.Therefore,we propose the spectral clustering based partition and placement algorithms,by which we can partition a large network into several small SDN domains efficiently and effectively.In our algorithms,the matrix perturbation theory and eigengap are used to discover the stability of SDN domains and decide the optimal number of SDN domains automatically.To evaluate our algorithms,we develop a new experimental framework with the Internet2 topology and other available WAN topologies.The results show the effectiveness of our algorithm for the SDN domain partition and controller placement problems.展开更多
随着信息通信技术的飞速发展,下一代通信网络(如5G/6G)对网络性能提出了更高的要求,特别是在低延迟、高带宽、海量设备接入和智能化管控等方面。文章分析了软件定义网络(Software Defined Network,SDN)在大带宽、低时延和大规模物联网...随着信息通信技术的飞速发展,下一代通信网络(如5G/6G)对网络性能提出了更高的要求,特别是在低延迟、高带宽、海量设备接入和智能化管控等方面。文章分析了软件定义网络(Software Defined Network,SDN)在大带宽、低时延和大规模物联网环境中的应用,提出了协议优化策略并采用理论建模与仿真实验相结合的方法,评估不同优化方案的效果。结果表明:SDN优化能有效降低网络延迟,提高带宽利用率,增强物联网设备管理能力。展开更多
Aiming at the problem that network topology changes frequently in SDN (Software Defined Network) environment and it is difficult to implement fine-grained access control, utilizing the characteristics of SDN transfer ...Aiming at the problem that network topology changes frequently in SDN (Software Defined Network) environment and it is difficult to implement fine-grained access control, utilizing the characteristics of SDN transfer control separation and software programming, the ABAC model (Attribute-Based Access Control) is extended by introducing security level, and the security level is defined for the attributes of subject and object to establish the access mapping relationship based on mandatory access rules. At the same time, with secure access path as SDN access control attribute, a dynamic generation method of access control path based on PSO (Particle Swarm Optimization) algorithm is designed to ensure the security of access data flow. The prototype system experiments show that the proposed method takes into account the fine-grained and dynamic requirements of SDN access control, and improves the access security of SDN while ensuring the access efficiency.展开更多
针对网络信息通信能力方面存在的不足,提出一种改进型软件定义网络(software defined network,SDN)控制器的网络安全通信技术研究方法。在网络布局中安装SDN控制器,以提高网络数据信息布局能力;通过改进型权关联图模型对提取到的数据信...针对网络信息通信能力方面存在的不足,提出一种改进型软件定义网络(software defined network,SDN)控制器的网络安全通信技术研究方法。在网络布局中安装SDN控制器,以提高网络数据信息布局能力;通过改进型权关联图模型对提取到的数据信息进行处理,利用用户行为数据中的加权图建立数据上下网络节点的关联关系;利用自动交换光网络技术,提高网络数据信息通信能力。试验结果表明,所提方法网络安全通信传输速率快,分类准确率高,最大可达到1。所提方法在提高SDN控制器的网络安全通信方面具有良好的效果和潜力。展开更多
Software-Defined Networking(SDN)improves network management by separating its control logic from the underlying hardware and integrating it into a logically centralized control unit,termed the SDN controller.SDN adapt...Software-Defined Networking(SDN)improves network management by separating its control logic from the underlying hardware and integrating it into a logically centralized control unit,termed the SDN controller.SDN adaptation is essential for wireless networks because it offers enhanced and data-intensive services.The initial intent of the SDN design was to have a physically centralized controller.However,network experts have suggested logically centralized and physically distributed designs for SDN controllers,owing to issues such as a single point of failure and scalability.This study addressed the security,scalability,reliability,and consistency issues associated with the design of distributed SDN controllers.Moreover,the security issues of an enterprise related to multiple physically distributed controllers in a software-defined wireless local area network(SD-WLAN)were emphasized,and optimal solutions were suggested.展开更多
探讨基于软件定义网络(Software Defined Network,SDN)的动态流量控制在通信网络安全中的应用。SDN将网络控制平面与数据平面分离,实现可编程和集中化管理。基于SDN的动态流量控制具有实时监测与响应、灵活流量调度、增强安全策略执行...探讨基于软件定义网络(Software Defined Network,SDN)的动态流量控制在通信网络安全中的应用。SDN将网络控制平面与数据平面分离,实现可编程和集中化管理。基于SDN的动态流量控制具有实时监测与响应、灵活流量调度、增强安全策略执行等优势,可用于网络攻击检测和防御、数据泄露防范及网络资源优化分配。通过实时监测异常流量、结合入侵检测系统/入侵防御系统(Intrusion Detection System/Intrusion Prevention System,IDS/IPS)、监控数据流量、加密与访问控制等手段提升安全性,同时实现流量负载均衡和资源分配优化,为通信网络安全提供有力保障。展开更多
为解决传统程控交换系统灵活性不足与软件定义网络(Software Defined Network,SDN)兼容性欠缺的双重问题,开展SDN与程控交换系统融合架构中的协议转换机制研究。剖析两类系统的协议差异,明确协议转换在语法、语义、时序3个维度的核心目...为解决传统程控交换系统灵活性不足与软件定义网络(Software Defined Network,SDN)兼容性欠缺的双重问题,开展SDN与程控交换系统融合架构中的协议转换机制研究。剖析两类系统的协议差异,明确协议转换在语法、语义、时序3个维度的核心目标,构建“控制层-转换层-接入层”3级融合架构。其中,转换层作为核心模块,采用“中间格式映射+状态机调度”的技术方案,通过协议字段映射表与转换优先级调度策略优化性能。实验结果表明,所提机制在1000并发呼叫请求下,协议转换延迟小于等于5 ms,转换成功率达99.8%,相比传统网关方案性能明显提升,能够满足融合架构对实时性与可靠性的需求,为电信网络向软件化转型提供技术支撑。展开更多
随着下一代通信网的发展,传统网络架构已无法满足日益增长的灵活性、可扩展性及管理需求。软件定义网络(Software Defined Network,SDN)作为一种新型网络架构,为6G网络提供了新的研究方向。文章分析SDN的基本架构和工作原理,并总结SDN...随着下一代通信网的发展,传统网络架构已无法满足日益增长的灵活性、可扩展性及管理需求。软件定义网络(Software Defined Network,SDN)作为一种新型网络架构,为6G网络提供了新的研究方向。文章分析SDN的基本架构和工作原理,并总结SDN技术的优化方法。在此基础上,结合Mininet仿真平台对SDN与传统网络架构在6G应用场景下的性能进行对比实验。结果表明,SDN在网络延迟、丢包率及资源利用率等关键性能指标上显著优于传统网络架构,为6G网络的部署提供了重要理论依据和实践指导。展开更多
软件定义网络(Software Defined Network,SDN)在通信网络中的应用日益广泛,但其集中控制架构也带来新的安全挑战。文章深入剖析SDN架构下通信网络面临的安全威胁,包括控制器单点故障、拒绝服务攻击等,南向接口虚假流表注入、协议漏洞利...软件定义网络(Software Defined Network,SDN)在通信网络中的应用日益广泛,但其集中控制架构也带来新的安全挑战。文章深入剖析SDN架构下通信网络面临的安全威胁,包括控制器单点故障、拒绝服务攻击等,南向接口虚假流表注入、协议漏洞利用等,北向接口应用程序漏洞、身份认证问题等,以及数据平面流量劫持、分布式拒绝服务攻击等。提出相应的安全防御机制,为构建安全可靠的基于SDN的通信网络提供理论依据与实践指导。展开更多
在智能电网通信架构持续演化的背景下,变电站对信息流控制系统提出高密度并发、精细调度与异常自愈等多重能力要求,推动软件定义网络(Software Defined Network,SDN)技术向变电站场景深入渗透。本研究构建一套基于SDN架构的变电站智能...在智能电网通信架构持续演化的背景下,变电站对信息流控制系统提出高密度并发、精细调度与异常自愈等多重能力要求,推动软件定义网络(Software Defined Network,SDN)技术向变电站场景深入渗透。本研究构建一套基于SDN架构的变电站智能化信息流控制系统,围绕转发结构重构、状态动态建模、资源分配优化与故障联动反馈4个维度展开系统性设计,形成由控制器统一调度、策略解析层动态编排、转发执行层实时响应的分层联控体系。测试结果表明,该系统在多个方面均优于传统架构,可为构建柔性可编程的变电站通信平台提供方法与路径。展开更多
目前正在使用的网络架构已有30年的历史。在此架构下,交换机/路由器需要在超过6 000个分布式协议中使整个网络正常运行。这意味着只要有一个网元增加一种新的协议,其他网元都必须在结构上做出变更。SDN(Software Defined Network,软件...目前正在使用的网络架构已有30年的历史。在此架构下,交换机/路由器需要在超过6 000个分布式协议中使整个网络正常运行。这意味着只要有一个网元增加一种新的协议,其他网元都必须在结构上做出变更。SDN(Software Defined Network,软件定义网络)则打破了这种桎梏,它使得网络可编程,从而让网络在满足用户需求方面更具灵活性。SDN架构将控制和转发解耦,将控制功能集中到逻辑独立的控制环境之中,同时为应用层提供底层网络的抽象视图。结果就是SDN可以为用户提供可编程性极强的网络、网络自动化管理以及网络控制等功能,从而满足日益变化与丰富的网络需求。SDN控制器在SDN架构中的作用至关重要,它既要与基础设施层交互也需要与应用层经由API交互。首先分析了SDN架构的产生背景、原理和其发展现状;随后研究并分析了一个SDN控制器的开源项目Floodlight;最后通过对当前7种控制器的实验以及SDN相关原理对SDN控制器的特性进行了总结与分析。展开更多
基金supported by the National Natural Science Foundation of China(Nos.61432002,61370199,61370198,61300187,and 61402069)the Fundamental Research Funds for the Central Universities,China(Nos.DUT15QY20,DUT15TD29,and3132016029)the Prospective Research Project on Future Networks from Jiangsu Future Networks Innovation Institute,China
文摘As a novel architecture,software-defined networking(SDN) is viewed as the key technology of future networking.The core idea of SDN is to decouple the control plane and the data plane,enabling centralized,flexible,and programmable network control.Although local area networks like data center networks have benefited from SDN,it is still a problem to deploy SDN in wide area networks(WANs) or large-scale networks.Existing works show that multiple controllers are required in WANs with each covering one small SDN domain.However,the problems of SDN domain partition and controller placement should be further addressed.Therefore,we propose the spectral clustering based partition and placement algorithms,by which we can partition a large network into several small SDN domains efficiently and effectively.In our algorithms,the matrix perturbation theory and eigengap are used to discover the stability of SDN domains and decide the optimal number of SDN domains automatically.To evaluate our algorithms,we develop a new experimental framework with the Internet2 topology and other available WAN topologies.The results show the effectiveness of our algorithm for the SDN domain partition and controller placement problems.
文摘随着信息通信技术的飞速发展,下一代通信网络(如5G/6G)对网络性能提出了更高的要求,特别是在低延迟、高带宽、海量设备接入和智能化管控等方面。文章分析了软件定义网络(Software Defined Network,SDN)在大带宽、低时延和大规模物联网环境中的应用,提出了协议优化策略并采用理论建模与仿真实验相结合的方法,评估不同优化方案的效果。结果表明:SDN优化能有效降低网络延迟,提高带宽利用率,增强物联网设备管理能力。
文摘Aiming at the problem that network topology changes frequently in SDN (Software Defined Network) environment and it is difficult to implement fine-grained access control, utilizing the characteristics of SDN transfer control separation and software programming, the ABAC model (Attribute-Based Access Control) is extended by introducing security level, and the security level is defined for the attributes of subject and object to establish the access mapping relationship based on mandatory access rules. At the same time, with secure access path as SDN access control attribute, a dynamic generation method of access control path based on PSO (Particle Swarm Optimization) algorithm is designed to ensure the security of access data flow. The prototype system experiments show that the proposed method takes into account the fine-grained and dynamic requirements of SDN access control, and improves the access security of SDN while ensuring the access efficiency.
文摘针对网络信息通信能力方面存在的不足,提出一种改进型软件定义网络(software defined network,SDN)控制器的网络安全通信技术研究方法。在网络布局中安装SDN控制器,以提高网络数据信息布局能力;通过改进型权关联图模型对提取到的数据信息进行处理,利用用户行为数据中的加权图建立数据上下网络节点的关联关系;利用自动交换光网络技术,提高网络数据信息通信能力。试验结果表明,所提方法网络安全通信传输速率快,分类准确率高,最大可达到1。所提方法在提高SDN控制器的网络安全通信方面具有良好的效果和潜力。
文摘Software-Defined Networking(SDN)improves network management by separating its control logic from the underlying hardware and integrating it into a logically centralized control unit,termed the SDN controller.SDN adaptation is essential for wireless networks because it offers enhanced and data-intensive services.The initial intent of the SDN design was to have a physically centralized controller.However,network experts have suggested logically centralized and physically distributed designs for SDN controllers,owing to issues such as a single point of failure and scalability.This study addressed the security,scalability,reliability,and consistency issues associated with the design of distributed SDN controllers.Moreover,the security issues of an enterprise related to multiple physically distributed controllers in a software-defined wireless local area network(SD-WLAN)were emphasized,and optimal solutions were suggested.
文摘为解决传统程控交换系统灵活性不足与软件定义网络(Software Defined Network,SDN)兼容性欠缺的双重问题,开展SDN与程控交换系统融合架构中的协议转换机制研究。剖析两类系统的协议差异,明确协议转换在语法、语义、时序3个维度的核心目标,构建“控制层-转换层-接入层”3级融合架构。其中,转换层作为核心模块,采用“中间格式映射+状态机调度”的技术方案,通过协议字段映射表与转换优先级调度策略优化性能。实验结果表明,所提机制在1000并发呼叫请求下,协议转换延迟小于等于5 ms,转换成功率达99.8%,相比传统网关方案性能明显提升,能够满足融合架构对实时性与可靠性的需求,为电信网络向软件化转型提供技术支撑。
文摘随着下一代通信网的发展,传统网络架构已无法满足日益增长的灵活性、可扩展性及管理需求。软件定义网络(Software Defined Network,SDN)作为一种新型网络架构,为6G网络提供了新的研究方向。文章分析SDN的基本架构和工作原理,并总结SDN技术的优化方法。在此基础上,结合Mininet仿真平台对SDN与传统网络架构在6G应用场景下的性能进行对比实验。结果表明,SDN在网络延迟、丢包率及资源利用率等关键性能指标上显著优于传统网络架构,为6G网络的部署提供了重要理论依据和实践指导。
文摘软件定义网络(Software Defined Network,SDN)在通信网络中的应用日益广泛,但其集中控制架构也带来新的安全挑战。文章深入剖析SDN架构下通信网络面临的安全威胁,包括控制器单点故障、拒绝服务攻击等,南向接口虚假流表注入、协议漏洞利用等,北向接口应用程序漏洞、身份认证问题等,以及数据平面流量劫持、分布式拒绝服务攻击等。提出相应的安全防御机制,为构建安全可靠的基于SDN的通信网络提供理论依据与实践指导。
文摘在智能电网通信架构持续演化的背景下,变电站对信息流控制系统提出高密度并发、精细调度与异常自愈等多重能力要求,推动软件定义网络(Software Defined Network,SDN)技术向变电站场景深入渗透。本研究构建一套基于SDN架构的变电站智能化信息流控制系统,围绕转发结构重构、状态动态建模、资源分配优化与故障联动反馈4个维度展开系统性设计,形成由控制器统一调度、策略解析层动态编排、转发执行层实时响应的分层联控体系。测试结果表明,该系统在多个方面均优于传统架构,可为构建柔性可编程的变电站通信平台提供方法与路径。
文摘目前正在使用的网络架构已有30年的历史。在此架构下,交换机/路由器需要在超过6 000个分布式协议中使整个网络正常运行。这意味着只要有一个网元增加一种新的协议,其他网元都必须在结构上做出变更。SDN(Software Defined Network,软件定义网络)则打破了这种桎梏,它使得网络可编程,从而让网络在满足用户需求方面更具灵活性。SDN架构将控制和转发解耦,将控制功能集中到逻辑独立的控制环境之中,同时为应用层提供底层网络的抽象视图。结果就是SDN可以为用户提供可编程性极强的网络、网络自动化管理以及网络控制等功能,从而满足日益变化与丰富的网络需求。SDN控制器在SDN架构中的作用至关重要,它既要与基础设施层交互也需要与应用层经由API交互。首先分析了SDN架构的产生背景、原理和其发展现状;随后研究并分析了一个SDN控制器的开源项目Floodlight;最后通过对当前7种控制器的实验以及SDN相关原理对SDN控制器的特性进行了总结与分析。