Unlock instant, AI-driven research and patent intelligence for your innovation.

A method for verifying the consistency of SDN network status in cloud environment

A technology of network status and verification method, applied in the field of virtual network security in cloud environment, can solve problems such as inability to ensure network status, complex attack defense at the forwarding layer, and inability to guarantee network status consistency.

Active Publication Date: 2020-07-31
SICHUAN UNIV
View PDF12 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, the correct strategy of the control layer cannot guarantee the correct forwarding status of the forwarding layer, so it is necessary to monitor the forwarding layer to ensure the normal data forwarding
The second category is to detect abnormal behaviors at the forwarding layer. The flexible mechanism of SDN makes the defense against attacks at the forwarding layer very complicated. At present, the research on the network status of the forwarding layer mainly focuses on the detection and verification of abnormal forwarding behaviors.
[0005] The defects of the existing research methods mainly include: 1) Focus on solving the inconsistency of the single-layer network state in SDN, or the inconsistency of the network state caused by a certain type of attack. Since there are many kinds of attacks in the network, one attack cannot guarantee the network state. Consistency; 2) Since the network state in the cloud environment is flexible and changeable, the inconsistency of the network state can be located by obtaining the network state for global comparison, which cannot ensure that the obtained network state is the latest, and the global comparison will bring huge 3) In the cloud environment, the network configuration is dispersed in multiple virtual network terminals, relying on the terminal host to implement network functions on the data plane, so the implementation mechanism of SDN in the cloud environment is different from that in the pure SDN environment , the core-based SDN development technology cannot be directly used on the cloud platform

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A method for verifying the consistency of SDN network status in cloud environment
  • A method for verifying the consistency of SDN network status in cloud environment
  • A method for verifying the consistency of SDN network status in cloud environment

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0021] The implementation principle of the present invention is as follows: in the network update request stage, the IP-MAC binding information, network topology state, switch link connection and port information of the virtual machine in the current network are obtained through the global network view of the controller, and the information is analyzed. form a constrained space.

[0022] Call the API interface to obtain the security policy in the network, and analyze it to form a security space. In the cloud platform, security policies are organized in the form of chains, each chain defines a series of rules, and each rule defines the matching packet set and related ACCEPT, DROP and actions to invoke other chains. The security chain parsing algorithm proposed by the present invention is as follows. The security chain parsing algorithm sequentially parses all the rules contained in a chain, and obtains the ACCEPT / DROP (S A / S D )space. The source information P of the packet...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method for verifying the consistency of an SDN network state in a cloud environment, which is verified from two aspects of network update request and response, including request verification, security rule verification and forwarding layer path verification; in the network update request stage, by analyzing The network state metadata forms a constraint space, and analyzes the security policy to form a security space, analyzes the network update request and performs rapid verification with the constraint space and the security space in turn, detects malicious requests in real time, and ensures that the controller maintains a correct global network view. The flow rule sent by the controller to the forwarding layer is consistent with the security policy; in the response phase of network status update, the SDN controller actively sends the detection packet to verify the flow forwarding path, and uses the OpenFlow group table method to add a label mark to the head of the detection packet The actual forwarding path of the data packet at the forwarding layer realizes lightweight data packet forwarding path verification and abnormal path location.

Description

technical field [0001] The invention relates to the technical field of virtual network security in a cloud environment, in particular to a method for verifying the state consistency of an SDN network in a cloud environment. Background technique [0002] Software Defined Networking (SDN) is a new network architecture that decouples the data plane from the control plane and logically implements centralized control and management. The emergence of SDN provides an effective solution for managing large-scale virtual networks in cloud environments. An important challenge in SDN is to ensure the consistency between the network functions defined by the high layer and the configuration of the underlying forwarding equipment, that is, to ensure that the network functions and policies configured at the control layer are implemented in the forwarding layer. SDN is a typical flow rule-driven network. The legitimacy and consistency of flow rules are the basis for ensuring the normal and ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L12/24H04L12/721H04L12/723H04L29/08H04L45/50
CPCH04L63/20H04L63/12H04L41/14H04L45/50H04L45/70H04L69/06H04L67/10
Inventor 陈兴蜀王小艳朱毅王毅桐滑强蔡顺婉
Owner SICHUAN UNIV