论文标题
基于SDN/NFV的5G和6G网络的信息安全监控和管理系统
An information security monitoring and management system for 5G and 6G Networks based on SDN/NFV
论文作者
论文摘要
提出了一种使用软件定义的网络和网络功能虚拟化(SDN/NFV)的方法,以实现5G和6G网络中的信息安全监控和管理系统。基于OpenFlow协议的SDN开关作为网络传感器提供。为了减少在逻辑上位于传感器上的所有流量过滤系统的大量规则中找到正确规则的子集的时间,提出了一种处理和过滤流量的方法,以5G和6G传输网络中的方式进行处理和过滤流量。该方法基于具有LPM算法的DPDK,并且能够在1 CPU Core上每秒处理多达8兆帕的;数据包处理采用O(1),其明显低于相似的算法。管理子系统由区域监测中心和主要监测中心组成。主监视中心包括主SDN控制器的主要群集以及主动/主动冗余方案。区域中心代表管理本地下属传感器的SDN软件控制器。所有管理中心都通过运输子系统互连并形成网络。为了提供容错,负载平衡和网络连接性,已开发了用于网络传感器负载平衡的算法。该算法导致一组总负载不超过SDN控制器的最大容量的最佳传感器组。
An approach to using the concept of Software-Defined Networking and Network Functions Virtualization (SDN/NFV) for the implementation of an information security monitoring and management system in 5G and 6G networks is proposed. SDN switches based on the OpenFlow protocol are offered as network sensors. In order to reduce the time for finding a subset of the right rules in the vast array of all rules on traffic filtering systems that are logically located on sensors, a method of processing and filtering traffic in 5G and 6G transport networks is proposed. This method is based on DPDK with the LPM algorithm and is capable of processing up to 8 megapackets per second on 1 CPU core; the packet processing takes O(1), which is significantly lower than with similar algorithms. The managing subsystem consists of regional monitoring centres and a main one. The main Monitoring Centre includes a main cluster of SDN controllers along with Active/Active redundancy scheme. The regional centres represent SDN software controllers that manage locally subordinate sensors. All the managing centres are interconnected via the Transport subsystem and form a network. An algorithm for network sensor load balancing between SDN controllers has been developed in order to provide fault tolerance, load balancing and network connectivity. The algorithm results in a set of optimal sensor groups with total load not exceeding the maximum capacity of the SDN controllers.