论文标题

软件定义安全服务的动态可部署性的方法和技术

Methods and Techniques for Dynamic Deployability of Software-Defined Security Services

论文作者

Doriguzzi-Corin, Roberto

论文摘要

随着新兴技术(例如软件定义的网络(SDN)和网络功能虚拟化(NFV)等新兴技术的最新趋势,数据中心和企业网络的系统管理员已经开始替换专用硬件的Middleboxs,并在服务器和最终主机上运行虚拟的网络功能。这种根本性的变化有助于提供高级和灵活的网络服务,最终帮助系统管理员和网络运营商应对服务需求和网络工作负载的快速变化。本文调查了在“软牌化”网络中配备网络安全服务的挑战,可以通过在高性能服务器或商品计算设备上运行的一组基于软件的网络功能来提供住宅和业务用户的安全性。该研究是从电信运营商的角度进行的,电信运营商的目标是保护客户免受网络威胁的侵害,同时又可以最大程度地提高配置服务的数量,从而获得收入。具体而言,本文提出的研究的总体目的是提出新技术来优化基于软件的安全服务的资源使用,因此增加了操作员的机会,以适应更多的服务请求,同时尊重其客户的网络安全水平。在这个方向上,本论文的贡献如下:(i)为安全服务的动态提供解决方案,可将计算和网络资源的利用最小化,以及(ii)基于深度学习和Linux内核技术的新方法,以降低基于软件的安全网络功能的CPU使用,以介绍基于软件的安全网络功能,并针对Separted Denial denial ofted oferted denial ofted nir extiral ofted nir exterted oftervential denial aintial aintial攻击(ddsos)。

With the recent trend of "network softwarisation", enabled by emerging technologies such as Software-Defined Networking (SDN) and Network Function Virtualisation (NFV), system administrators of data centres and enterprise networks have started replacing dedicated hardware-based middleboxes with virtualised network functions running on servers and end hosts. This radical change has facilitated the provisioning of advanced and flexible network services, ultimately helping system administrators and network operators to cope with the rapid changes in service requirements and networking workloads. This thesis investigates the challenges of provisioning network security services in "softwarised" networks, where the security of residential and business users can be provided by means of sets of software-based network functions running on high performance servers or on commodity compute devices. The study is approached from the perspective of the telecom operator, whose goal is to protect the customers from network threats and, at the same time, maximize the number of provisioned services, and thereby revenue. Specifically, the overall aim of the research presented in this thesis is proposing novel techniques for optimising the resource usage of software-based security services, hence for increasing the chances for the operator to accommodate more service requests while respecting the desired level of network security of its customers. In this direction, the contributions of this thesis are the following: (i) a solution for the dynamic provisioning of security services that minimises the utilisation of computing and network resources, and (ii) novel methods based on Deep Learning and Linux kernel technologies for reducing the CPU usage of software-based security network functions, with specific focus on the defence against Distributed Denial of Service (DDoS) attacks.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源