{"title":"构建基于软件定义网络的交换机信息安全保护系统","authors":"Xueda Huang, Kuanlei Zheng, Sisi Chen, Zhaoren He","doi":"10.1002/ett.5033","DOIUrl":null,"url":null,"abstract":"<p>The communications industry has a new, forward-thinking architecture: software-defined networks (SDN). The inflexible structure of conventional networks severely hinders their ability to service modern organizations. The increased adaptability and transparency of SDN-powered networks makes them more vulnerable to security hazards like Distributed denial of service (DDoS) assaults. The switch information system introduces protection at the cost of some degree of adaptability. The information and software layers are potential entry points for DDoS assaults. The flow-based policies frequently collide at the application layer, giving rise to safety issues. The central nervous system of the network's components is the SDN controller located at the control layer. The centrally located controller interacts with networking hardware via switches. Attacks on control devices, switches, and communication channels can cause vulnerabilities in SDN networks. The study proposes Blockchain-SDN-based switch information security (BC-SDN-SIS) to address the information security problems. SDN applications operate at the highest level of SDN controllers, facilitating the easy rollout of new network services. The suggested design uses a distributed BC approach to guarantee confidentiality, anonymity, privacy, and scalability. The proposed BC-SDN-SIS model increases the accuracy ratio of 97.45%, precision ratio of 98.43, recall ratio of 97.34, effectiveness ratio of 97.6%, bandwidth of 2.5 Mbps, latency rate of .04 ms and F1-score ratio of 98.28% compared to other existing models.</p>","PeriodicalId":23282,"journal":{"name":"Transactions on Emerging Telecommunications Technologies","volume":"35 9","pages":""},"PeriodicalIF":2.5000,"publicationDate":"2024-08-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Construction of switch information security protection system based on software-defined networking\",\"authors\":\"Xueda Huang, Kuanlei Zheng, Sisi Chen, Zhaoren He\",\"doi\":\"10.1002/ett.5033\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>The communications industry has a new, forward-thinking architecture: software-defined networks (SDN). The inflexible structure of conventional networks severely hinders their ability to service modern organizations. The increased adaptability and transparency of SDN-powered networks makes them more vulnerable to security hazards like Distributed denial of service (DDoS) assaults. The switch information system introduces protection at the cost of some degree of adaptability. The information and software layers are potential entry points for DDoS assaults. The flow-based policies frequently collide at the application layer, giving rise to safety issues. The central nervous system of the network's components is the SDN controller located at the control layer. The centrally located controller interacts with networking hardware via switches. Attacks on control devices, switches, and communication channels can cause vulnerabilities in SDN networks. The study proposes Blockchain-SDN-based switch information security (BC-SDN-SIS) to address the information security problems. SDN applications operate at the highest level of SDN controllers, facilitating the easy rollout of new network services. The suggested design uses a distributed BC approach to guarantee confidentiality, anonymity, privacy, and scalability. The proposed BC-SDN-SIS model increases the accuracy ratio of 97.45%, precision ratio of 98.43, recall ratio of 97.34, effectiveness ratio of 97.6%, bandwidth of 2.5 Mbps, latency rate of .04 ms and F1-score ratio of 98.28% compared to other existing models.</p>\",\"PeriodicalId\":23282,\"journal\":{\"name\":\"Transactions on Emerging Telecommunications Technologies\",\"volume\":\"35 9\",\"pages\":\"\"},\"PeriodicalIF\":2.5000,\"publicationDate\":\"2024-08-20\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Transactions on Emerging Telecommunications Technologies\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://onlinelibrary.wiley.com/doi/10.1002/ett.5033\",\"RegionNum\":4,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"TELECOMMUNICATIONS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Transactions on Emerging Telecommunications Technologies","FirstCategoryId":"94","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/ett.5033","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"TELECOMMUNICATIONS","Score":null,"Total":0}
引用次数: 0
摘要
通信行业拥有一种全新的前瞻性架构:软件定义网络(SDN)。传统网络僵化的结构严重阻碍了它们为现代组织提供服务的能力。由 SDN 驱动的网络具有更强的适应性和透明度,因此更容易受到分布式拒绝服务 (DDoS) 攻击等安全隐患的影响。交换机信息系统以一定程度的适应性为代价引入保护。信息层和软件层是 DDoS 攻击的潜在切入点。基于流量的策略经常在应用层发生冲突,从而引发安全问题。网络组件的中枢神经系统是位于控制层的 SDN 控制器。位于中心位置的控制器通过交换机与网络硬件交互。对控制设备、交换机和通信通道的攻击会导致 SDN 网络出现漏洞。本研究提出了基于区块链-SDN的交换机信息安全(BC-SDN-SIS)来解决信息安全问题。SDN 应用程序在 SDN 控制器的最高层运行,便于轻松推出新的网络服务。建议的设计采用分布式 BC 方法,以保证保密性、匿名性、隐私性和可扩展性。与其他现有模型相比,建议的 BC-SDN-SIS 模型的准确率提高了 97.45%,精确率提高了 98.43%,召回率提高了 97.34%,有效率提高了 97.6%,带宽提高了 2.5 Mbps,延迟率提高了 0.04 ms,F1 分数提高了 98.28%。
Construction of switch information security protection system based on software-defined networking
The communications industry has a new, forward-thinking architecture: software-defined networks (SDN). The inflexible structure of conventional networks severely hinders their ability to service modern organizations. The increased adaptability and transparency of SDN-powered networks makes them more vulnerable to security hazards like Distributed denial of service (DDoS) assaults. The switch information system introduces protection at the cost of some degree of adaptability. The information and software layers are potential entry points for DDoS assaults. The flow-based policies frequently collide at the application layer, giving rise to safety issues. The central nervous system of the network's components is the SDN controller located at the control layer. The centrally located controller interacts with networking hardware via switches. Attacks on control devices, switches, and communication channels can cause vulnerabilities in SDN networks. The study proposes Blockchain-SDN-based switch information security (BC-SDN-SIS) to address the information security problems. SDN applications operate at the highest level of SDN controllers, facilitating the easy rollout of new network services. The suggested design uses a distributed BC approach to guarantee confidentiality, anonymity, privacy, and scalability. The proposed BC-SDN-SIS model increases the accuracy ratio of 97.45%, precision ratio of 98.43, recall ratio of 97.34, effectiveness ratio of 97.6%, bandwidth of 2.5 Mbps, latency rate of .04 ms and F1-score ratio of 98.28% compared to other existing models.
期刊介绍:
ransactions on Emerging Telecommunications Technologies (ETT), formerly known as European Transactions on Telecommunications (ETT), has the following aims:
- to attract cutting-edge publications from leading researchers and research groups around the world
- to become a highly cited source of timely research findings in emerging fields of telecommunications
- to limit revision and publication cycles to a few months and thus significantly increase attractiveness to publish
- to become the leading journal for publishing the latest developments in telecommunications