电信科学 ›› 2020, Vol. 36 ›› Issue (5): 16-24.doi: 10.11959/j.issn.1000-0801.2020144

• 专题:网络安全的智能化和高对抗性发展 • 上一篇    下一篇

一种域适配混合遗传算法及在安全服务链编排中的验证

姚晓辉1,2,李青2,孙焜焜3   

  1. 1 移动互联网系统与应用安全国家工程实验室,上海 201315
    2 中国电信股份有限公司研究院,上海 200122
    3 中国科学院信息工程研究所,北京 100093
  • 修回日期:2020-04-20 出版日期:2020-05-20 发布日期:2020-05-18
  • 作者简介:姚晓辉(1979- ),男,移动互联网系统与应用安全国家工程实验室、中国电信股份有限公司研究院高级工程师,主要从事企业信息系统规划、建设、实施及关键技术研究工作|李青(1973- ),男,中国电信股份有限公司研究院高级工程师,主要从事电信增值业务平台、云资源池集约化运营等技术研究及支撑工作|孙焜焜(1995- ),男,中国科学院信息工程研究所硕士生,主要研究方向为网络功能虚拟化、网络体系结构
  • 基金资助:
    国家重点研发计划基金资助项目(2017YFB0801801)

A domain adaptive hybrid genetic algorithm and its verification in security service function chain orchestration

Xiaohui YAO1,2,Qing LI2,Kunkun SUN3   

  1. 1 Mobile Internet System and Application Security National Engineering Laboratory,Shanghai 201315,China
    2 Research Institute of China Telecom Co.,Ltd.,Shanghai 200122,China
    3 Institute of Information Engineering,Chinese Academy of Science,Beijing 100093,China
  • Revised:2020-04-20 Online:2020-05-20 Published:2020-05-18
  • Supported by:
    The National Key Research and Development Program of China(2017YFB0801801)

摘要:

面对不断变化的网络需求,用户对传统网络的要求也越来越高,灵活性、扩展性、易用性等特征已成为现代网络的必备要素。提出了一种域适配混合遗传算法(domain adaptive hybrid genetic algorithm, DAHGA),可应用于云数据中心租户的安全服务链编排,实现租户云安全服务与策略的自动加载与激活,满足租户云安全“按需定制”需求。同时针对云安全服务链编排上各种提升VNF放置效率的算法进行了实验对比研究,充分验证了本文算法的有效性,为云业务无损安全服务链编排技术的实现提供了借鉴和参考。

关键词: 云安全, 安全域, 安全服务链, NFV, VNF, 遗传算法

Abstract:

Faced with changeful network demands,users have increasingly higher requirements for traditional network.Features such as flexibility,scalability and ease of use have become essential elements of modern network.A domain adaptive hybrid genetic algorithm (DAHGA) was proposed,which could be applied to the security service chain arrangement of cloud data center tenants,to achieve automatic loading and activation of tenant cloud security services and policies,to meet tenant cloud security “customization on demand” requirements.And conducts experimental comparison research on the effective placement efficiency of each VNF on the cloud security service chain orchestration was carried out,which fully validated the proposed algorithm.Effectiveness provides a reference and reference for the realization of cloud business non-destructive security service chain orchestration technology.

Key words: cloud security, security domain, security service chain, NFV, VNF, genetic algorithm

中图分类号: 

No Suggested Reading articles found!