Supercharge Your Innovation With Domain-Expert AI Agents!

Security service function chain design method and system based on software defined security

A security service and software-defined technology, applied in the field of information security, can solve problems such as difficulty in improving the flexibility and efficiency of network security protection, and achieve the effect of virtualization

Pending Publication Date: 2022-02-11
GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +2
View PDF0 Cites 3 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] Therefore, the technical problem to be solved by the present invention is to overcome the defects in the prior art that it is difficult to improve the flexibility and efficiency of network security protection, thereby providing a security service function chain design method and system based on software-defined security

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Security service function chain design method and system based on software defined security
  • Security service function chain design method and system based on software defined security
  • Security service function chain design method and system based on software defined security

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0020] The technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Apparently, the described embodiments are some of the embodiments of the present invention, but not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0021] In the description of the present invention, it should be noted that the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer" etc. The indicated orientation or positional relationship is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the referred device or element must have a specific orientation, ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention provides a security service function chain design method and system based on software defined security. The method comprises the following steps: acquiring a user security service demand; constructing a security service chain strategy according to a user security service demand; selecting a passing virtual security device for the security service chain, and performing mapping from a logic data packet to a physical forwarding path; and analyzing to obtain the flow instruction, and performing flow redirection operation in a flow table issuing mode. A security service function chain is constructed according to user requirements, security resource scheduling is realized according to the load condition of a host machine, and a security service function chain rule classifies network flows in an OpenFlow flow table mode and sequentially redirects the network flows to corresponding security equipment, so dynamic control of the network flows is realized. Tests show that the mechanism can effectively realize security service virtualization, and a flexible and dynamic security protection mechanism is provided according to security service requirements.

Description

technical field [0001] The invention relates to the field of information security, in particular to a method and system for designing a security service function chain based on software-defined security. Background technique [0002] The service chain (SC) of the traditional network pulls the network data flow satisfying specific attributes through a service sequence composed of multiple business function service nodes, which provides traditional networks with means of preventing and controlling malicious attacks. The software-defined security (Software Defined Security, SDS) architecture decouples the control plane and data plane of network security devices. The bottom layer is abstracted as resources in the security resource pool, and the top layer implements flexibility by elastically orchestrating security services in a software-defined manner. safety protection. [0003] However, with the rapid development of cloud computing and software-defined network (Software Defin...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L9/40
CPCH04L63/20H04L63/10
Inventor 马媛媛管小娟吕卓
Owner GLOBAL ENERGY INTERCONNECTION RES INST CO LTD
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More