电信科学 ›› 2021, Vol. 37 ›› Issue (3): 66-74.doi: 10.11959/j.issn.1000-0801.2021048

• 专题:内生安全 • 上一篇    下一篇

网络空间内生安全试验场管理技术

朱泓艺, 陆肖元, 李毅   

  1. 上海宽带技术及应用工程研究中心,上海 200436
  • 修回日期:2021-03-14 出版日期:2021-03-20 发布日期:2021-03-01
  • 作者简介:朱泓艺(1990- ),男,博士,上海宽带技术及应用工程研究中心副研究员,主要研究方向为下一代无线通信技术、边缘计算、智能网联汽车及信息安全技术等。
    陆肖元(1975- ),男,上海宽带技术及应用工程技术研究中心教授级高级工程师,上海浦东临港智慧城市发展中心主任,主要研究方向为宽带网络与智慧城市应用等。
    李毅(1965- ),男,上海宽带技术及应用工程研究中心主任、博士生导师,主要研究方向为宽带网络与大数据技术及应用等。
  • 基金资助:
    国家重点研发计划项目(2020YFB1805101);上海市科技创新行动计划高新技术领域项目(20511102102)

Management technologies of cyberspace endogenous safety and security test site

Hongyi ZHU, Xiaoyuan LU, Yi LI   

  1. Shanghai Engineering Research Center for Broadband Technologies and Applications, Shanghai 200436, China
  • Revised:2021-03-14 Online:2021-03-20 Published:2021-03-01
  • Supported by:
    The National Key Research and Development Program of China(2020YFB1805101);Shanghai Science and Technology Innovation Action Plan(20511102102)

摘要:

网络靶场(CR)已被广泛认可为一种研究网络攻防技术与网络架构脆弱性的有效途径,网络空间内生安全试验场是一种面向网络空间内生安全技术的网络靶场,近年来受到了高度关注。基于以5G发展为核心的网络空间新形势,提出了面向虚实结合网络环境的试验场管理技术,设计了基于内生安全软件定义网络控制器的试验场管理架构。同时提出了一种内生安全网络控制系统的架构设计,采用中间层转发代理实现数据安全隔离,支持多种异构开源控制器。最后,基于一种试验场组网方案提出试验场场景重构与资源编排方法。

关键词: 网络空间, 内生安全, 网络靶场, 软件定义网络

Abstract:

The cyber range has been widely recognized as an effective way to study the technologies of network attack/defense and the vulnerability of network architecture.The endogenous safety and security test site that receives high attention recently is a type of cyber range for cyber space endogenous safety and security technologies.Based on the new situation of cyberspace with 5G development, a test site management technology for virtual-real network settings was proposed, and a test site management architecture based on the endogenously secured software defined network controller was designed.A design of the endogenously secured network control system was also proposed, which used a middle layer forwarding agent to achieve data isolation and supported multiple heterogeneous open-source controllers.Finally, a test site scenario reconfiguration and resource orchestration method was proposed based on a test site networking scheme.

Key words: cyberspace, endogenous safety and security, cyber range, software defined network

中图分类号: 

No Suggested Reading articles found!