Security resource scheduling method based on software defined network, software defined network and medium

By setting up a controller cluster and backup controller in a distributed software-defined network, and using improved frequent mode maximum value algorithm and cyclic graph neural network model for network analysis and risk assessment, the problem of significantly increasing network fault diagnosis and security defense difficulties caused by 5G virtualization technology is solved, and flexible allocation and stable operation of network resources are achieved.

CN120416892APending Publication Date: 2025-08-01XINJIANG UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510545965.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

5G virtualization technology has led to a significant increase in the difficulty of network fault diagnosis and security defense, and traditional security equipment is difficult to effectively protect 5G systems.

Method used

By setting up a controller cluster and backup controller in a distributed software-defined network, the current flow table information, slice resource status and load information are obtained, and the improved frequent mode maximum value algorithm and cyclic graph neural network model are used for correlation analysis and risk assessment, and the expected isolation information and resource adjustment scheme are determined to realize flexible resource allocation and security management of the network.

Benefits of technology

It improves network resource utilization, ensures the resource requirements of key slices and controllers, realizes stable operation and rapid failure recovery of the network, and improves network security and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416892A_ABST
    Figure CN120416892A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and provides a security resource scheduling method based on a software defined network, the software defined network and a medium, and the method comprises the steps: firstly obtaining current flow table information, current slice resource state information and current slice load information of a current time period; then determining target flow table information, target slice resource state information and target slice load information of a target time period; and then determining predicted isolation information by integrating the information, and further determining a resource adjustment scheme, first control information of the controller cluster and second control information of the backup controller. According to the invention, the resources can be flexibly allocated according to the actual security condition and resource requirements of the network, and the resource requirements of the key slice and the controller are ensured to be met at the same time. Meanwhile, the controller cluster and the backup controller can be guided to accurately control and manage the network, it is ensured that a resource adjustment scheme is effectively executed, meanwhile, the backup controller can be rapidly switched to when needed, and stable operation of the network is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a security resource scheduling method, a software-defined network, and a medium based on a software-defined network. Background Art

[0002] In the era of 5G full connection, profound changes have occurred in the mobile communication architecture. SDN (Software Defined Network) realizes the complete separation of the data plane and the control plane, and can flexibly perform operations such as path calculation and bandwidth allocation according to the upper-layer service requirements; NFV (Network Function Virtualization) is applied to the core network, carrying and developing proprietary communication service services, enabling the functions of network devices to get rid of the dependence on proprietary hardware, reducing the operation investment cost, and improving the network management efficiency. As 5G virtualization technologies, SDN and NFV solve the hardware performance problem from the software level, and improve the system performance and reduce the operation cost at the cost of increased software complexity. However, they also cause the disappearance of the defense boundary, making it difficult to use traditional security devices such as intrusion detection systems and firewalls for 5G system protection, and the security risks faced by 5G are more severe than those of traditional communication technologies.

[0003] In the traditional communication field, when traffic congestion or a fault occurs in the A-area network, troubleshooting the routers, switches, and related systems in the A area can locate the problem. However, in the 5G era, when the same problem occurs in the A-area network, in addition to local packet forwarding hardware failures, it is also very likely to involve problems with the SDN controller and the hardware or systems of other area networks associated with the A-area network, which greatly increases the difficulty of network fault diagnosis and security defense. Summary of the Invention

[0004] In view of this, the present invention provides a security resource scheduling method, a software-defined network, and a medium based on a software-defined network, aiming to solve the problem that the 5G virtualization technology greatly increases the difficulty of network fault diagnosis and security defense.

[0005] The first aspect of the present invention provides a security resource scheduling method based on a software-defined network, which is applied to a distributed software-defined network; a controller cluster and at least one backup controller are provided in the distributed software-defined network; the controller cluster includes multiple SDN controllers; the method includes:

[0006] Obtain the current flow table information, the current slice resource status information, and the current slice load information in the current time period;

[0007] Determine the target flow table information, the target slice resource status information, and the target slice load information in the target time period according to the current flow table information, the current slice resource status information, and the current slice load information;

[0008] Determine the estimated isolation information according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, and the target slice load information;

[0009] Determine a resource adjustment plan, first control information of the controller cluster, and second control information of the backup controller according to the estimated isolation information.

[0010] In a possible implementation manner, determining the target flow table information, the target slice resource status information, and the target slice load information for a target time period according to the current flow table information, the current slice resource status information, and the current slice load information includes:

[0011] Perform an association analysis on the current flow table information, the current slice resource status information, and the current slice load information to obtain an association rule;

[0012] Input the current flow table information, the current slice resource status information, the current slice load information, and the association rule into a pre-established prediction model to obtain the target flow table information, the target slice resource status information, and the target slice load information.

[0013] In a possible implementation manner, performing an association analysis on the current flow table information, the current slice resource status information, and the current slice load information to obtain an association rule includes:

[0014] Perform an association analysis on the current flow table information, the current slice resource status information, and the current slice load information according to the improved frequent pattern maximum value algorithm to obtain an association rule;

[0015] Among them, the improved frequent pattern maximum value algorithm realizes collaborative optimization based on the incremental difference set.

[0016] In a possible implementation manner, determining the estimated isolation information according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, and the target slice load information includes:

[0017] Determine the controller risk and the slice risk according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, the target slice load information, and the security risk assessment model;

[0018] Determine the estimated isolation information according to the controller risk, the slice risk, and the association rule.

[0019] In a possible implementation manner, determining the estimated isolation information according to the controller risk, the slice risk, and the association rule includes:

[0020] Determine a first isolation target and a second isolation target according to the controller risk and the slice risk; wherein, the risk of the first isolation target is higher than that of the second isolation target.

[0021] Determine a third isolation target according to the first isolation target and the association rule.

[0022] Determine the expected isolation information according to the first isolation target, the second isolation target and the third isolation target.

[0023] In a possible implementation manner, according to the expected isolation information, determine a resource adjustment plan, first control information of the controller cluster and second control information of the backup controller, including:

[0024] Determine the resource adjustment plan for each SDN controller and each network slice under each SDN controller according to the expected isolation information.

[0025] Determine the first control information of the controller cluster and the second control information of the backup controller according to the expected isolation information and the resource adjustment plan.

[0026] In a possible implementation manner, according to the expected isolation information and the resource adjustment plan, determine the first control information of the controller cluster and the second control information of the backup controller, including:

[0027] Determine the first control information of the controller cluster according to the resource adjustment plan and the expected isolation information of each network slice under each SDN controller.

[0028] Determine the second control information according to the expected isolation information of each SDN controller.

[0029] A second aspect of the present invention provides a security resource scheduling device based on software-defined network, which is applied to a distributed software-defined network; a controller cluster and at least one backup controller are arranged in the distributed software-defined network; the controller cluster includes a plurality of SDN controllers; the device includes:

[0030] An acquisition module, configured to acquire the current flow table information, the current slice resource status information and the current slice load information of the current time period.

[0031] A calculation module, configured to determine the target flow table information, the target slice resource status information and the target slice load information of the target time period according to the current flow table information, the current slice resource status information and the current slice load information.

[0032] An isolation module, configured to determine the expected isolation information according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information and the target slice load information.

[0033] A determination module, configured to determine a resource adjustment plan, first control information of a controller cluster, and second control information of a backup controller according to predicted isolation information.

[0034] A third aspect of the present invention provides a distributed software-defined network, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the security resource scheduling method based on the software-defined network in the first aspect above are implemented.

[0035] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the steps of the security resource scheduling method based on the software-defined network in the first aspect above are implemented.

[0036] The security resource scheduling method, software-defined network, and medium based on the software-defined network provided by the embodiments of the present invention first obtain current flow table information, current slice resource status information, and current slice load information in the current period; then determine target flow table information, target slice resource status information, and target slice load information in the target period according to the current flow table information, current slice resource status information, and current slice load information; then determine predicted isolation information according to the current flow table information, current slice resource status information, current slice load information, target flow table information, target slice resource status information, and target slice load information; and finally determine a resource adjustment plan, first control information of a controller cluster, and second control information of a backup controller according to the predicted isolation information. The present invention can flexibly allocate resources according to the actual security status and resource requirements of the network, improve the utilization rate of resources, and ensure that the resource requirements of critical slices and controllers are met. At the same time, it can guide the controller cluster and backup controller to accurately control and manage the network, ensure the effective execution of the resource adjustment plan, and quickly switch to the backup controller when needed to ensure the stable operation of the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0038] Figure 1 It is a flowchart of the implementation of the security resource scheduling method based on the software-defined network provided by the embodiments of the present invention;

[0039] Figure 2It is a schematic structural diagram of a security resource scheduling device based on a software-defined network provided by an embodiment of the present invention. Detailed implementation manners

[0040] In the following description, specific details such as specific system architectures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present invention. However, those skilled in the art should clearly understand that the present invention can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present invention.

[0041] Figure 1 It is an implementation flowchart of a security resource scheduling method based on a software-defined network provided by an embodiment of the present invention. As Figure 1 shown, in some embodiments, the security resource scheduling method based on a software-defined network is applied to a distributed software-defined network; a controller cluster and at least one backup controller are set in the distributed software-defined network; the controller cluster includes multiple SDN controllers; the method includes:

[0042] S110, obtaining current flow table information, current slice resource status information, and current slice load information for the current time period;

[0043] S120, determining target flow table information, target slice resource status information, and target slice load information for the target time period according to the current flow table information, current slice resource status information, and current slice load information;

[0044] S130, determining predicted isolation information according to the current flow table information, current slice resource status information, current slice load information, target flow table information, target slice resource status information, and target slice load information;

[0045] S140, determining a resource adjustment plan, first control information of the controller cluster, and second control information of the backup controller according to the predicted isolation information.

[0046] In an embodiment of the present invention, a flow table is a set of rules used by a data plane device (such as a switch) in SDN to forward data packets. Communication can be carried out between the SDN controller and the data plane device. Flow table information usually includes matching fields (such as source IP address, destination IP address, port number, protocol type, etc.), action fields (such as forwarding, discarding, modifying, etc.), as well as the priority of the flow table entry, counters (recording the number and bytes of the matched data packets), etc. In a 5G network, network slicing is to divide the physical network into multiple logically independent virtual networks. Resource information allocated to each slice, including the usage of bandwidth, computing resources, storage resources, etc., can be collected through a monitoring system. The slice load information reflects the business load conditions running on each slice. Slice load information can be obtained by monitoring metrics such as network traffic, the number of service requests, and the number of concurrent connections.

[0047] In an embodiment of the present invention, by predicting the information in the target period, preparations for resource allocation and scheduling can be made in advance. For example, if it is predicted that the load of a certain slice will increase significantly in the target period, more resources can be allocated to it in advance to avoid a decline in network performance due to insufficient resources.

[0048] In an embodiment of the present invention, when there are situations such as abnormal traffic, too high resource utilization rate, and abnormal flow table rules, the risk of the controller will be evaluated as relatively high. At this time, when there is a security risk in the network, by isolating high-risk components, other normal network parts can be protected to ensure the overall security and stability of the network. At the service level, once there are situations such as abnormal traffic, a faulty controller, or an overloaded slice in the network that may threaten the security of the critical service chain, the isolation process needs to be started. From the perspective of the service, usually the overloaded slice is preferably isolated because the slice, as the specific carrier of the service, isolating it can effectively block the spread of risks to the critical service chain as a whole. From the actual implementation level, since traffic is the direct medium for risk propagation, the object of isolation in actual operation is traffic. By accurately judging the expected isolation information, the specific traffic to be isolated can be accurately locked. Whether it is abnormal traffic, traffic related to faults, or traffic originating from an overloaded slice, it can be quickly identified and isolated, thus effectively cutting off the path of risk propagation and ensuring that the critical service chain will not be threatened.

[0049] In an embodiment of the present invention, for the components that need to be isolated, their resource allocation is reduced. Correspondingly, for other normally operating components, their resource allocation is reasonably adjusted according to their future load predictions. Among them, the first control information includes resource allocation adjustment commands, flow table rule modification commands, etc. that the controller needs to execute. The second control information is used to ensure the normal operation of the network when the backup controller can quickly take over the work of the primary controller when the primary controller fails or is isolated.

[0050] In the controller management system of software-defined networks, to achieve more efficient and stable network operation, the thinking mode of the human brain can be borrowed to construct a hierarchical management model. In this model, the first controller in the controller cluster is set as the fast-thinking layer, and the second controller (backup controller) is set as the slow-thinking layer. Fast thinking is an intuitive and automated immediate response mode, mainly relying on past experience and pattern matching, capable of making rapid responses; while slow thinking is a rational and analytical in-depth cognitive process, highly dependent on logic and concentration. In SDN controller management, the simulation and application of these two thinking modes form a unique hierarchical design. The fast-thinking layer undertakes the key responsibility of real-time rapid response in SDN. It uses lightweight rules, such as preset policies and traffic feature matching, to achieve millisecond-level abnormal response effects. Taking the DDoS interception scenario as an example, when abnormal traffic appears in the network, the fast-thinking layer can quickly identify the attack behavior based on the preset rules and traffic characteristics, and immediately take interception measures to ensure the real-time security of the network. The design of this layer aims to quickly handle common and urgent situations in the network, ensuring that the network can maintain its basic operating state when facing sudden problems. The slow-thinking layer focuses on long-term optimization analysis in SDN. This layer uses AI models to deeply analyze historical data to dynamically optimize the global routing strategy. By analyzing information such as historical traffic data and network topology changes, it predicts network bottlenecks and reconstructs the network architecture according to the prediction results. For example, by analyzing data during peak historical traffic periods, it anticipates possible bottleneck links in advance, and then adjusts the routing strategy to avoid network congestion and improve the overall network performance. The slow-thinking layer focuses on the long-term stable operation and performance optimization of the network, ensuring the efficiency of the network from a macro perspective.

[0051] To achieve the balance between real-time performance and global optimization, the fast-thinking layer and the slow-thinking layer cooperate with each other through a cooperative arbitration mechanism. Among them, reinforcement learning feedback is an effective cooperation method. When dealing with real-time problems, the fast-thinking layer feeds relevant information back to the slow-thinking layer. The slow-thinking layer adjusts and optimizes the strategy based on this information and its own analysis results of historical data, and then feeds the optimized strategy back to the fast-thinking layer to guide its subsequent decisions. Through this cooperation mechanism, the fast-thinking layer and the slow-thinking layer of the SDN controller form an organic whole, constructing an autonomous network governance system that can not only handle immediate sudden problems in the network but also optimize the network from a long-term perspective, significantly improving the efficiency and stability of the network. In this master-slave distributed architecture, as the slow-thinking layer, the backup controller does not merely undertake the backup responsibility but plays an indispensable role in ensuring the long-term stability and optimization of the network, complementing the master controller as the fast-thinking layer and jointly promoting the efficient operation of the SDN network.

[0052] In some embodiments, determining the target flow table information, target slice resource status information, and target slice load information for a target period according to the current flow table information, current slice resource status information, and current slice load information includes: performing an association analysis on the current flow table information, current slice resource status information, and current slice load information to obtain an association rule; and inputting the current flow table information, current slice resource status information, current slice load information, and association rule into a pre-established prediction model to obtain the target flow table information, target slice resource status information, and target slice load information.

[0053] In the embodiments of the present invention, in the security resource scheduling scenario based on software-defined network, accurately predicting the target flow table information, target slice resource status information, and target slice load information for a target period is crucial for reasonably allocating resources and ensuring the secure and stable operation of the network. By performing an association analysis on the current flow table information, current slice resource status information, and current slice load information to obtain an association rule, and then using the prediction model to make a prediction in combination with these information and rules, the future state of the network can be grasped more accurately. Among them, the association analysis adopts an improved frequent pattern maximum algorithm based on incremental difference sets to achieve collaborative optimization, which can effectively mine the potential associations between data.

[0054] In the embodiments of the present invention, the prediction model is specifically a Long Short-Term Memory (LSTM) network model. Among them, the LSTM includes an input layer, an LSTM layer, and an output layer; the LSTM layer: contains multiple LSTM units, and each LSTM unit consists of an input gate, a forget gate, an output gate, and a memory unit. The features after encoding the association rule are used as part of the input sequence and input into the LSTM model together with the current flow table information, current slice resource status information, and current slice load information. The association rule features can provide additional prior knowledge for the LSTM model to help the model better understand the internal relationship between data. For example, when the association rule encoding feature indicates that "a high slice bandwidth utilization rate is related to a specific change in the flow table rule", the LSTM model will pay more attention to the co-variation between these two features when processing the input data, so as to more accurately capture the change pattern of the network state. In each gating mechanism of the LSTM unit, the association rule encoding feature will participate in the calculation together with other input features. For example, in the calculation of the forget gate, the association rule feature will affect the calculation of the forget coefficient, enabling the model to selectively forget or retain the information in the memory unit according to the association rule. If the association rule indicates that there is a strong association between certain flow table information and slice resource status information, then when processing this information, the forget gate may be more inclined to retain the relevant memory information to better predict the future network state.

[0055] In some embodiments, an association analysis is performed on the current flow table information, the current slice resource status information, and the current slice load information to obtain association rules, including: performing an association analysis on the current flow table information, the current slice resource status information, and the current slice load information according to the improved frequent pattern maximum algorithm to obtain association rules; wherein, the improved frequent pattern maximum algorithm realizes collaborative optimization based on the incremental difference set.

[0056] In the embodiments of the present invention, the core improvement of the Frequent Pattern Max (FPMax) algorithm lies in directly mining the maximum frequent item sets, avoiding the generation of redundant sub-patterns. This feature enables it to more efficiently obtain key information when mining frequent patterns, reducing unnecessary waste of computing resources. The item header table is used to record the occurrence of each item in the data set, including information such as the position of the item in the transaction. The conditional pattern base is composed of the subsequences before a specific item in the transactions containing the item. During the mining process, the item header table can quickly locate the transactions containing a specific item, while the conditional pattern base provides a more focused data subset for mining frequent item sets. For example, for a data set containing numerous transactions, to mine the frequent item sets related to the item "high slice bandwidth usage", the transactions containing this item can be quickly found through the item header table, and then the relevant subsequences in these transactions can be extracted according to the conditional pattern base, narrowing the mining scope and improving the mining efficiency. During the process of generating candidate sets, according to the preset support threshold, for those candidate sets that are unlikely to become frequent item sets, pruning operations are directly performed, and subsequent processing such as support calculation is no longer carried out. For example, if a part of a candidate set has been determined to be a non-frequent item set, then the entire candidate set cannot be a frequent item set and can be directly discarded, greatly reducing the computational complexity.

[0057] In the embodiments of the present invention, in the scenario of streaming data, the data is continuously updated in real time. To adapt to this dynamic change, FPMax introduces windowing processing and combines it with a time decay model. Specifically, a time decay model such as an exponentially weighted sliding window can be adopted to reduce the weight of the support of old data according to a preset time decay coefficient. Through the time decay model, the algorithm can pay more attention to recent data and improve the adaptability of the mining results to the current network state. The data is divided into different windows in chronological order, and the data within each window is used as an independent data set for mining frequent item sets. As time goes by, new windows are continuously generated and old windows are eliminated. Within each window, the support of the data is adjusted in combination with the time decay model, and then frequent item set mining is performed. In this way, the algorithm can track the changes of the data in real time and discover new frequent patterns in a timely manner.

[0058] In the embodiments of the present invention, due to problems such as incremental update delay and memory fragmentation in the 5G streaming scenario, the present invention solves this problem through an incremental difference set and a hierarchical pruning strategy.

[0059] Among them, to solve the incremental update delay problem, only the difference transactions between the current window and the previous window are stored. Compared with storing all data, the memory occupancy is reduced by 60%. During the continuous update of network data, each data update does not mean that all data has changed. In most cases, only part of the data has changed. For example, in the flow table information, only some flow table entries may have been updated. By storing the incremental difference set, the algorithm only needs to focus on these changed parts, without having to repeatedly process all data, greatly reducing the memory occupancy and computational amount, and improving the real-time performance of incremental updates.

[0060] To cope with memory fragmentation and further optimize the mining efficiency, a hierarchical pruning strategy is adopted. The item sets are divided into different slices such as high, medium, and low according to the support degree, and the least recently used (LRU) elimination strategy is adopted for the low-support item sets. In the actual network environment, the low-support item sets often contribute less to mining key frequent patterns and occupy memory resources. Through the LRU elimination strategy, the low-support item sets that have not been used for a long time or have a low support degree are removed from the memory, releasing memory space, avoiding memory fragmentation, and at the same time improving the overall operation efficiency of the algorithm.

[0061] In some embodiments, according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, and the target slice load information, the predicted isolation information is determined, including: determining the controller risk and the slice risk according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, the target slice load information, and the security risk assessment model; determining the predicted isolation information according to the controller risk, the slice risk, and the association rule.

[0062] In the embodiments of the present invention, the security risk assessment model is a cyclic graph neural network model. It introduces a cyclic structure on the basis of the graph neural network. At different time steps, the node features can be updated to learn the dynamic changes of the relationships between SDN and SDN, SDN and slice, and slice and slice, improving the accuracy of risk determination.

[0063] Specifically, the SDN controller and slices can be regarded as nodes of different types respectively. Edges are defined according to the relationships between SDN and SDN, SDN and slices, and slices and slices. For example, if there is data interaction or collaborative working relationship between SDN controllers, there is an edge connecting them; if an SDN controller is responsible for managing a certain slice, there is an edge connecting this SDN controller and this slice; if there is resource sharing or data communication relationship between slices, there is also an edge connecting them.

[0064] For each node, the recurrent graph neural network model will collect the feature information of its neighbor nodes. During the aggregation process, the features of neighbor nodes will be weighted to different degrees according to the type and weight of the edges. For example, the weight of the edge between SDN and SDN is related to the data interaction frequency between them; the weight of the edge between SDN and slices is related to the management authority or resource allocation ratio of the SDN to the slices; the weight of the edge between slices and slices is related to the data traffic volume between them. The aggregated neighbor information is used to update the features of the current node. Generally, some non-linear functions are used to perform combined transformation on the aggregated information and the original features of the current node.

[0065] In the embodiment of the present invention, the RGNN will automatically adjust the weights of the edges and other parameters in the model according to the information in the data, so that the model can adaptively learn the dynamic changes of the relationships, providing strong support for accurately determining the controller risk and slice risk.

[0066] In some embodiments, according to the controller risk, slice risk and association rules, the expected isolation information is determined, including: determining a first isolation target and a second isolation target according to the controller risk and slice risk; wherein the risk of the first isolation target is higher than that of the second isolation target; determining a third isolation target according to the first isolation target and the association rules; determining the expected isolation information according to the first isolation target, the second isolation target and the third isolation target.

[0067] In the embodiments of the present invention, a security risk assessment model is used to quantitatively evaluate the risks of the controller and slices. This model comprehensively considers data from multiple dimensions such as abnormal network traffic, abnormal resource utilization, and abnormal rule changes. For example, for a controller, when the CPU usage rate continuously exceeds 90%, the memory usage rate approaches 100%, and there are a large number of abnormal modifications to the flow table rules in a short period of time, its risk value will increase significantly. Based on the risk quantification results, controllers and slices with a high degree of risk are determined as the first isolation targets. These objects pose a greater threat to network security and may have been attacked or are about to cause serious failures. For example, if a certain controller frequently experiences packet loss and service interruptions occur in multiple slices it manages, this controller should be listed as the first isolation target. Controllers and slices with relatively low risks but still outside the normal range are determined as the second isolation targets. Although they have not yet had a serious impact on the network, they still pose potential risks and need to be monitored and isolated. According to the specific situation of the first isolation targets, association rules are used to infer other objects that may be affected by them, and these objects are determined as the third isolation targets. If malicious traffic injection occurs in a slice among the first isolation targets, based on the analysis of the data interaction relationship between slices in the association rules, other slices that have frequent data transmissions with this slice should be listed as the third isolation targets. Even if these slices do not currently show obvious risk signs, considering the potential threat propagation, isolating them helps prevent the spread of risks. Finally, by comprehensively considering the first isolation targets, the second isolation targets, and the third isolation targets, the specific objects to be isolated are identified. According to the actual situation and security requirements of the network, appropriate isolation methods are determined. For the high-risk first isolation targets, a method of completely disconnecting the network connection may be adopted to quickly cut off the risk propagation path; for the second isolation targets, a method of restricting access permissions may be adopted first, such as only allowing specific management traffic to pass through, and observing and monitoring them; for the third isolation targets, a method of partial isolation or enhanced monitoring can be selected according to the risk level and the scope of business impact. For example, for slices indirectly associated with the first isolation targets, the traffic of some non-critical services can be temporarily restricted while closely monitoring their operating status. The determined isolation scope and isolation methods are integrated to form the expected isolation information. The expected isolation information should include a detailed list of isolated objects, such as specific controller numbers, slice identifiers, network link addresses, etc.; clear isolation operation steps and time arrangements, such as which objects to isolate first and which objects to isolate later, and the expected time to complete the isolation operation; the expected isolation information also includes subsequent processing measures after isolation, such as fault troubleshooting, data backup, and security detection of the isolated objects, so that the network can be quickly restored to normal operation after the risks are eliminated.

[0068] In some embodiments, determining a resource adjustment plan, first control information of a controller cluster, and second control information of a backup controller according to predicted isolation information includes: determining a resource adjustment plan for each SDN controller and each network slice under each SDN controller according to the predicted isolation information; and determining the first control information of the controller cluster and the second control information of the backup controller according to the predicted isolation information and the resource adjustment plan.

[0069] In the embodiments of the present invention, in an SDN cluster, different SDN controllers manage different network slices. When a certain controller fails or is resource-constrained, cross-controller resource migration is required. Part of the slices managed by the failed controller are migrated to other controllers with lighter loads to achieve balanced resource allocation. For some slices with similar service requirements or resource usage characteristics, resource sharing and collaboration can be carried out. For example, two slices for video transmission can share a part of the bandwidth resource and dynamically adjust their respective bandwidth allocations according to the real-time requirements of the service. During the peak period of video playback, the two slices can reasonably allocate the shared bandwidth resource according to the actual traffic situation to ensure the smoothness of video playback. Different resource allocation strategies are formulated according to the requirement characteristics of different services. For services with high real-time requirements, such as voice calls and video conferences, high-quality resources are preferentially allocated to meet their low-latency and high-bandwidth requirements; for services with relatively low real-time requirements, such as file transfer and data backup, the resource allocation standard can be appropriately reduced on the premise of meeting the basic service requirements, and more resources are left for critical services.

[0070] In some embodiments, determining the first control information of the controller cluster and the second control information of the backup controller according to the predicted isolation information and the resource adjustment plan includes: determining the first control information of the controller cluster according to the resource adjustment plan and the predicted isolation information of each network slice under each SDN controller; and determining the second control information according to the predicted isolation information of each SDN controller.

[0071] In the embodiments of the present invention, the resource adjustment plan determines the changes in resource allocation for each SDN controller and each network slice under each SDN controller. The decision-making module sends the first control information to the controller cluster according to these adjustments. For a specific network slice under a certain SDN controller, if the resource adjustment plan requires an increase in its bandwidth, the first control information will contain corresponding instructions to inform the controller to allocate more bandwidth resources for the specified slice. If a slice is listed as an expected isolation object, the first control information will contain special processing instructions for this slice. For the slice to be isolated soon, the instructions may require the controller to stop allocating new resources to it and gradually reclaim the allocated resources. For example, if slice B is listed as an expected isolation object due to potential risks, the first control information will instruct the controller to stop allocating new computing resources for slice B and gradually reclaim the used memory resources within a certain period of time to reduce the impact of failures or risks on the entire system. The second control information is mainly for the backup controller. According to the expected isolation information of each SDN controller, the operations that the backup controller needs to perform are determined, and corresponding instructions are generated. If a certain SDN controller fails or has a high risk and is listed as an expected isolation object, the second control information will instruct the backup controller to make preparations for taking over. When the primary SDN controller S1 fails and is expected to be isolated, the second control information will notify the backup controller R1 to prepare to take over the work of S1, including obtaining the backup data of S1 and initializing relevant configurations, etc.

[0072] In some embodiments, in addition to backing up the SDN controllers in the first isolation target, if there are remaining computing resources, the backup controller will also back up the data of the SDN controllers in the second isolation target and the third isolation target to ensure a quick switch in case of a failure. In addition, the SDN controllers in the first isolation target, the second isolation target, and the third isolation target can be weighted and scored according to the importance of the slices and services they carry, the resource quantity, and the preset priority scores of the three types of isolation targets, and compared with the preset threshold according to the results of the weighted scoring, and the data of the SDN controllers higher than the threshold will be backed up.

[0073] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0074] Figure 2 is a schematic structural diagram of a security resource scheduling device based on software-defined network provided by the embodiments of the present invention. As Figure 2 shown, the security resource scheduling device 2 based on software-defined network includes:

[0075] An acquisition module 210, configured to acquire current flow table information, current slice resource status information, and current slice load information for the current time period;

[0076] A calculation module 220, configured to determine target flow table information, target slice resource status information, and target slice load information for a target time period according to the current flow table information, the current slice resource status information, and the current slice load information;

[0077] An isolation module 230, configured to determine predicted isolation information according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, and the target slice load information;

[0078] A determination module 240, configured to determine a resource adjustment plan, first control information for a controller cluster, and second control information for a backup controller according to the predicted isolation information.

[0079] Optionally, the calculation module 220 is configured to perform correlation analysis on the current flow table information, the current slice resource status information, and the current slice load information to obtain a correlation rule; input the current flow table information, the current slice resource status information, the current slice load information, and the correlation rule into a pre-established prediction model to obtain the target flow table information, the target slice resource status information, and the target slice load information.

[0080] Optionally, the calculation module 220 is configured to perform correlation analysis on the current flow table information, the current slice resource status information, and the current slice load information according to an improved frequent pattern maximum value algorithm to obtain a correlation rule; wherein, the improved frequent pattern maximum value algorithm realizes collaborative optimization based on an incremental difference set.

[0081] Optionally, the isolation module 230 is configured to determine controller risk and slice risk according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, the target slice load information, and a security risk assessment model; determine the predicted isolation information according to the controller risk, the slice risk, and the correlation rule.

[0082] Optionally, the isolation module 230 is configured to determine a first isolation target and a second isolation target according to the controller risk and the slice risk; wherein, the risk of the first isolation target is higher than that of the second isolation target; determine a third isolation target according to the first isolation target and the correlation rule; determine the predicted isolation information according to the first isolation target, the second isolation target, and the third isolation target.

[0083] Optionally, a determination module 240 is configured to determine a resource adjustment plan for each SDN controller and each network slice under each SDN controller according to the predicted isolation information; and determine first control information of the controller cluster and second control information of the backup controller according to the predicted isolation information and the resource adjustment plan.

[0084] Optionally, the determination module 240 is configured to determine first control information of the controller cluster according to the resource adjustment plan and the predicted isolation information of each network slice under each SDN controller; and determine second control information according to the predicted isolation information of each SDN controller.

[0085] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

Claims

1. A security resource scheduling method based on software-defined network, characterized in that Applied to a distributed software-defined network; in the distributed software-defined network, a controller cluster and at least one backup controller are set up; The controller cluster includes multiple SDN controllers; the method includes: Obtain the current flow table information, the current slice resource status information, and the current slice load information in the current time period; Determine the target flow table information, the target slice resource status information, and the target slice load information in the target time period according to the current flow table information, the current slice resource status information, and the current slice load information; Determine the expected isolation information according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, and the target slice load information; Determine a resource adjustment plan, the first control information of the controller cluster, and the second control information of the backup controller according to the expected isolation information.

2. The security resource scheduling method based on software-defined network according to claim 1, characterized in that Determine the target flow table information, the target slice resource status information, and the target slice load information in the target time period according to the current flow table information, the current slice resource status information, and the current slice load information, including: Perform correlation analysis on the current flow table information, the current slice resource status information, and the current slice load information to obtain a correlation rule; Input the current flow table information, the current slice resource status information, the current slice load information, and the correlation rule into a pre-established prediction model to obtain the target flow table information, the target slice resource status information, and the target slice load information.

3. The security resource scheduling method based on software-defined network according to claim 2, wherein Perform correlation analysis on the current flow table information, the current slice resource status information, and the current slice load information to obtain a correlation rule, including: Perform correlation analysis on the current flow table information, the current slice resource status information, and the current slice load information according to the improved frequent pattern maximum algorithm to obtain a correlation rule; Among them, the improved frequent pattern maximum algorithm realizes collaborative optimization based on an incremental difference set.

4. The security resource scheduling method based on software-defined network according to claim 3, wherein Determine the expected isolation information according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, and the target slice load information, including: Determine the controller risk and the slice risk according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, the target slice load information, and a security risk assessment model; Determine the expected isolation information according to the controller risk, the slice risk, and the correlation rule.

5. The security resource scheduling method based on software-defined network according to claim 4, wherein Determine the expected isolation information according to the controller risk, the slice risk, and the correlation rule, including: Determine a first isolation target and a second isolation target according to the controller risk and the slice risk; among them, the risk of the first isolation target is higher than that of the second isolation target; Determine the third isolation target according to the first isolation target and the correlation rule; Determine the expected isolation information according to the first isolation target, the second isolation target, and the third isolation target.

6. The security resource scheduling method based on software-defined network according to claim 5, wherein Determine a resource adjustment plan, first control information of the controller cluster, and second control information of the backup controller according to the expected isolation information, including: Determine a resource adjustment plan for each SDN controller and each network slice under each SDN controller according to the expected isolation information; Determine the first control information of the controller cluster and the second control information of the backup controller according to the expected isolation information and the resource adjustment plan.

7. The security resource scheduling method based on software-defined network according to claim 1, characterized in that Determine the first control information of the controller cluster and the second control information of the backup controller according to the expected isolation information and the resource adjustment plan, including: Determine the first control information of the controller cluster according to the resource adjustment plan and the expected isolation information of each network slice under each SDN controller; Determine the second control information according to the expected isolation information of each SDN controller.

8. A security resource scheduling device based on software-defined network, characterized in that Applied to a distributed software-defined network; a controller cluster and at least one backup controller are provided in the distributed software-defined network; The controller cluster includes multiple SDN controllers; the device includes: An acquisition module, configured to acquire current flow table information, current slice resource status information, and current slice load information in a current time period; A calculation module, configured to determine target flow table information, target slice resource status information, and target slice load information in a target time period according to the current flow table information, the current slice resource status information, and the current slice load information; An isolation module, configured to determine expected isolation information according to the current flow table information, the current slice resource status information, the current slice load information, the target flow table information, the target slice resource status information, and the target slice load information; A determination module, configured to determine a resource adjustment plan, first control information of the controller cluster, and second control information of the backup controller according to the expected isolation information.

9. A distributed software-defined network, characterized in that, A controller cluster and at least one backup controller are provided in the distributed software-defined network; the controller cluster includes multiple SDN controllers; the security resource scheduling method based on a software-defined network according to any one of claims 1 to 8 above is applied to the distributed software-defined network.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the security resource scheduling method based on a software-defined network according to any one of claims 1 to 8 above are implemented.