Chinese Journal of Network and Information Security ›› 2017, Vol. 3 ›› Issue (10): 52-61.doi: 10.11959/j.issn.2096-109x.2017.00205

• Papers • Previous Articles     Next Articles

Implementation architecture of mimic security defense based on SDN

Zhen-peng WANG1,Hong-chao HU1(),Guo-zhen CHENG1,Chuan-hao ZHANG1,2   

  1. 1 National Digital Switching System Engineering &Technological R&D Center,Zhengzhou 450003,China
    2 Public Security Technology Department,Railway Police College,Zhengzhou 450053,China
  • Revised:2017-09-24 Online:2017-10-01 Published:2017-11-13
  • Supported by:
    The National Natural Science Foundation of China(61309020);The National Natural Science Foundation of China(61602509);The Foundation for Innovative Research Groups of the National Natural Science Foundation of China(61521003);The National Key Research and Development Program of China(2016YFB0800100);The National Key Research and Development Program of China(2016YFB0800101);The Key Technologies Research and Development Program of Henan Province of China(172102210615);The Key Technologies Research and Development Program of Henan Province of China(172102210441)

Abstract:

To deal with the attacks employing unknown security vulnerabilities or backdoors which are difficult for traditional defense techniques to eliminate,mimic security defense (MSD) that employs “dynamic,heterogeneity,redundancy (DHR)” mechanism can increase the difficulty and cost of attack and uncertainty of system so as to improve network security.Based on the software defined networking (SDN),an implementation architecture of MSD was proposed.First,diverse functional equivalent variants for the protected target were constructed,then leverage the rich programmability and flexibility of SDN to realize the dynamic scheduling and decision-making functions on SDN controller.Simulation and experimental results prove the availability and the intrusion tolerant ability of the architecture.

Key words: mimic security defense, software defined networking, active defense, dynamic heterogeneous redundancy

CLC Number: 

No Suggested Reading articles found!