ESMD-Flow: An intelligent flow forwarding scheme with endogenous security based on Mimic defense in space-air-ground integrated network
The Space-Air-Ground Integrated Network (SAGIN) realizes the integration of space, air, and ground networks, obtaining the global communication coverage. Software-Defined Networking (SDN) architecture in SAGIN has become a promising solution to guarantee the Quality of Service (QoS). However, the cu...
Gespeichert in:
Veröffentlicht in: | China communications 2022-01, Vol.19 (1), p.40-51 |
---|---|
Hauptverfasser: | , , , , |
Format: | Artikel |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The Space-Air-Ground Integrated Network (SAGIN) realizes the integration of space, air, and ground networks, obtaining the global communication coverage. Software-Defined Networking (SDN) architecture in SAGIN has become a promising solution to guarantee the Quality of Service (QoS). However, the current routing algorithms mainly focus on the QoS of the service, rarely considering the security requirement of flow. To realize the secure transmission of flows in SAGIN, we propose an intelligent flow forwarding scheme with endogenous security based on Mimic Defense (ESMD-Flow). In this scheme, SDN controller will evaluate the reliability of nodes and links, isolate malicious nodes based on the reliability evaluation value, and adapt multipath routing strategy to ensure that flows are always forwarded along the most reliable multiple paths. In addition, in order to meet the security requirement of flows, we introduce the programming data plane to design a multiprotocol forwarding strategy for realizing the multiprotocol dynamic forwarding of flows. ESMD-Flow can reduce the network attack surface and improve the secure transmission capability of flows by implementing multipath routing and multi-protocol hybrid forwarding mechanism. The extensive simulations demonstrate that ESMD-Flow can significantly improve the average path reliability for routing and increase the difficulty of network eavesdropping while improving the network throughput and reducing the average packet delay. |
---|---|
ISSN: | 1673-5447 |
DOI: | 10.23919/JCC.2022.01.004 |