Technology trends such as Software-Defined Networking (SDN) are transforming networking services in terms of flexibility and faster deployment times. SDN separates the control plane from the data plane with its centra...Technology trends such as Software-Defined Networking (SDN) are transforming networking services in terms of flexibility and faster deployment times. SDN separates the control plane from the data plane with its centralised architecture compared with the distributed approach used in other management systems. However, management systems are still required to adapt the new emerging SDN-like technologies to address various security and complex management issues. Simple Network Management Protocol (SNMP) is the most widespread management protocol implemented in a traditional Network Management System (NMS) but has some limitations with the development of SDN-like services. Hence, many studies have been undertaken to merge the SDN-like services with traditional network management systems. Results show that merging SDN with traditional NMS systems not only increases the average Management Information Base (MIB) polling time but also creates additional overheads on the network. Therefore, this paper proposes a dynamic scheme for MIB polling using an additional MIB controller agent within the SDN controller. Our results show that using the proposed scheme, the average polling time can be significantly reduced (i.e., faster polling of the MIB information) and also requires very low overhead because of the small sized OpenFlow messages used during polling.展开更多
The integrated information network is a large capacity information network that integrates various communication platforms on the ground, at sea, in the air and in the deep air through the inter-satellite and satellit...The integrated information network is a large capacity information network that integrates various communication platforms on the ground, at sea, in the air and in the deep air through the inter-satellite and satellite-ground links to acquire information accurately, process it quickly, and transmit it efficiently. The satellite communication, as an important part of integrated information networks, is one of main approaches to acquire, process and distribute communication information and resources. In this paper, based on current researches of the satellite communication network, we put forward a 3-layer satellite communication network model based on the Software Defined Network (SDN). Meanwhile, to improve current routing policies of the Low Earth Orbit (LEO) satellite communication network, we put forward an Adaptive Routing Algorithm (ARA) to sustain the shortest satellite communication link. Experiment results show that the proposed method can effectively reduce link distance and communication delay, and realize adaptive path planning.展开更多
The survivability of computer systems should be guaranteed in order to improve its operation efficiency,especially for the efficiency of its critical functions.This paper proposes a decentralized mechanism based on So...The survivability of computer systems should be guaranteed in order to improve its operation efficiency,especially for the efficiency of its critical functions.This paper proposes a decentralized mechanism based on Software-Defined Architecture(SDA).The concepts of critical functions and critical states are defined,and then,the critical functional parameters of the target system are collected and analyzed.Experiments based on the analysis results are performed for reconfiguring the implementations of the whole system.A formal model is presented for analyzing and improving the survivability of the system,and the problem investigated in this paper is reduced to an optimization problem for increasing the system survival time.展开更多
入侵检测作为软件定义网络(software defined networks,SDN)架构的关键安全防护手段,能有效保障SDN安全稳定运行。通过汇总基于机器学习、基于深度学习、基于强化学习和基于信息熵的入侵检测方法,总结并分析SDN环境中仍存在的问题总结...入侵检测作为软件定义网络(software defined networks,SDN)架构的关键安全防护手段,能有效保障SDN安全稳定运行。通过汇总基于机器学习、基于深度学习、基于强化学习和基于信息熵的入侵检测方法,总结并分析SDN环境中仍存在的问题总结并分析了SDN环境中仍存在的问题:单控制器易受网络威胁、缺乏可扩展性、缺乏缓解和预防的方法、缺乏低速率DDoS的攻击检测、缺乏用于训练的SDN特定数据集、应用层的防御方法较少,并指出了未来的研究方向。展开更多
在智能电网通信架构持续演化的背景下,变电站对信息流控制系统提出高密度并发、精细调度与异常自愈等多重能力要求,推动软件定义网络(Software Defined Network,SDN)技术向变电站场景深入渗透。本研究构建一套基于SDN架构的变电站智能...在智能电网通信架构持续演化的背景下,变电站对信息流控制系统提出高密度并发、精细调度与异常自愈等多重能力要求,推动软件定义网络(Software Defined Network,SDN)技术向变电站场景深入渗透。本研究构建一套基于SDN架构的变电站智能化信息流控制系统,围绕转发结构重构、状态动态建模、资源分配优化与故障联动反馈4个维度展开系统性设计,形成由控制器统一调度、策略解析层动态编排、转发执行层实时响应的分层联控体系。测试结果表明,该系统在多个方面均优于传统架构,可为构建柔性可编程的变电站通信平台提供方法与路径。展开更多
文摘Technology trends such as Software-Defined Networking (SDN) are transforming networking services in terms of flexibility and faster deployment times. SDN separates the control plane from the data plane with its centralised architecture compared with the distributed approach used in other management systems. However, management systems are still required to adapt the new emerging SDN-like technologies to address various security and complex management issues. Simple Network Management Protocol (SNMP) is the most widespread management protocol implemented in a traditional Network Management System (NMS) but has some limitations with the development of SDN-like services. Hence, many studies have been undertaken to merge the SDN-like services with traditional network management systems. Results show that merging SDN with traditional NMS systems not only increases the average Management Information Base (MIB) polling time but also creates additional overheads on the network. Therefore, this paper proposes a dynamic scheme for MIB polling using an additional MIB controller agent within the SDN controller. Our results show that using the proposed scheme, the average polling time can be significantly reduced (i.e., faster polling of the MIB information) and also requires very low overhead because of the small sized OpenFlow messages used during polling.
基金supported in part by the National Natural Science Foundation of China (No. 61571104)the Sichuan Science and Technology Program (No. 2018JY0539)+2 种基金the Key projects of the Sichuan Provincial Education Department (No. 18ZA0219)the Fundamental Research Funds for the Central Universities (No. ZYGX2017KYQD170)the Innovation Funding (No. 2018510007000134)
文摘The integrated information network is a large capacity information network that integrates various communication platforms on the ground, at sea, in the air and in the deep air through the inter-satellite and satellite-ground links to acquire information accurately, process it quickly, and transmit it efficiently. The satellite communication, as an important part of integrated information networks, is one of main approaches to acquire, process and distribute communication information and resources. In this paper, based on current researches of the satellite communication network, we put forward a 3-layer satellite communication network model based on the Software Defined Network (SDN). Meanwhile, to improve current routing policies of the Low Earth Orbit (LEO) satellite communication network, we put forward an Adaptive Routing Algorithm (ARA) to sustain the shortest satellite communication link. Experiment results show that the proposed method can effectively reduce link distance and communication delay, and realize adaptive path planning.
文摘The survivability of computer systems should be guaranteed in order to improve its operation efficiency,especially for the efficiency of its critical functions.This paper proposes a decentralized mechanism based on Software-Defined Architecture(SDA).The concepts of critical functions and critical states are defined,and then,the critical functional parameters of the target system are collected and analyzed.Experiments based on the analysis results are performed for reconfiguring the implementations of the whole system.A formal model is presented for analyzing and improving the survivability of the system,and the problem investigated in this paper is reduced to an optimization problem for increasing the system survival time.
文摘入侵检测作为软件定义网络(software defined networks,SDN)架构的关键安全防护手段,能有效保障SDN安全稳定运行。通过汇总基于机器学习、基于深度学习、基于强化学习和基于信息熵的入侵检测方法,总结并分析SDN环境中仍存在的问题总结并分析了SDN环境中仍存在的问题:单控制器易受网络威胁、缺乏可扩展性、缺乏缓解和预防的方法、缺乏低速率DDoS的攻击检测、缺乏用于训练的SDN特定数据集、应用层的防御方法较少,并指出了未来的研究方向。
文摘在智能电网通信架构持续演化的背景下,变电站对信息流控制系统提出高密度并发、精细调度与异常自愈等多重能力要求,推动软件定义网络(Software Defined Network,SDN)技术向变电站场景深入渗透。本研究构建一套基于SDN架构的变电站智能化信息流控制系统,围绕转发结构重构、状态动态建模、资源分配优化与故障联动反馈4个维度展开系统性设计,形成由控制器统一调度、策略解析层动态编排、转发执行层实时响应的分层联控体系。测试结果表明,该系统在多个方面均优于传统架构,可为构建柔性可编程的变电站通信平台提供方法与路径。