A method for verifying the consistency of SDN network status in cloud environment
A technology of network status and verification method, applied in the field of virtual network security in cloud environment, can solve problems such as inability to ensure network status, complex attack defense at the forwarding layer, and inability to guarantee network status consistency.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0021] The implementation principle of the present invention is as follows: in the network update request stage, the IP-MAC binding information, network topology state, switch link connection and port information of the virtual machine in the current network are obtained through the global network view of the controller, and the information is analyzed. form a constrained space.
[0022] Call the API interface to obtain the security policy in the network, and analyze it to form a security space. In the cloud platform, security policies are organized in the form of chains, each chain defines a series of rules, and each rule defines the matching packet set and related ACCEPT, DROP and actions to invoke other chains. The security chain parsing algorithm proposed by the present invention is as follows. The security chain parsing algorithm sequentially parses all the rules contained in a chain, and obtains the ACCEPT / DROP (S A / S D )space. The source information P of the packet...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


