首页 | 本学科首页   官方微博 | 高级检索  
     

面向云网融合SaaS安全的虚拟网络功能映射方法
引用本文:李凌书,邬江兴. 面向云网融合SaaS安全的虚拟网络功能映射方法[J]. 计算机工程, 2021, 47(12): 30-39. DOI: 10.19678/j.issn.1000-3428.0061203
作者姓名:李凌书  邬江兴
作者单位:解放军信息工程大学 国家数字交换系统工程技术研究中心,郑州 450002
基金项目:国家自然科学基金(62002383);国家重点研发计划(2018YFB0804004)。
摘    要:在云网融合背景下,承载软件即服务(SaaS)业务功能的云基础设施可能横跨多个数据中心和归属网络,难以保证云资源安全可控。为缩短SaaS业务服务的处理时延,设计基于冗余执行和交叉检验的SaaS组合服务模式,并对容器、Hypervisor和云基础设施的安全威胁进行建模,建立拟态化虚拟网络功能映射模型和安全性优化机制。在此基础上,提出基于近端策略优化的PJM算法。实验结果表明,与CCMF、JEGA和QVNE算法相比,PJM算法在满足安全性约束的条件下,能够降低约12.2%业务端到端时延。

关 键 词:云计算  软件即服务  云网融合  虚拟网络映射  网络空间拟态防御  服务功能链  近端策略优化
收稿时间:2021-03-19
修稿时间:2021-05-27

SaaS Security Oriented Virtual Network Function Embedding Method Under Cloud-Network Integration
LI Lingshu,WU Jiangxing. SaaS Security Oriented Virtual Network Function Embedding Method Under Cloud-Network Integration[J]. Computer Engineering, 2021, 47(12): 30-39. DOI: 10.19678/j.issn.1000-3428.0061203
Authors:LI Lingshu  WU Jiangxing
Affiliation:National Digital Switching System Engineering & Technological R&D Center, PLA Information Engineering University, Zhengzhou 450002, China
Abstract:In the context of cloud-network integration, the cloud infrastructure carrying Software as a Service(SaaS) business functions may span multiple data centers and home networks, which adds difficulty to the security and controllability of cloud resources.In order to reduce the processing delay of SaaS business services, the SaaS composite service mode is designed based on redundant execution and cross inspection.The security threats of container, Hypervisor and cloud infrastructure are modeled, and the Mimetic Virtural Network Function Embedding(MVNE) model and the security optimization mechanism are established.On this basis, the PJM algorithm based on proximal strategy optimization is proposed.The experimental results show that, compared with CCMF, JEGA and QVNE algorithms, the PJM algorithm can reduce the end-to-end delay of services by about 12.2% under the security constraints.
Keywords:cloud computing  Software as a Service(SaaS)  cloud-network integration  Virtual Network Embedding(VNE)  Cyber Mimic Defense(CMD)  Service Function Chain(SFC)  Proximal Policy Optimization(PPO)  
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机工程》浏览原始摘要信息
点击此处可从《计算机工程》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号