信息网络安全 ›› 2015, Vol. 15 ›› Issue (9): 191-195.doi: 10.3969/j.issn.1671-1122.2015.09.043

• 入选论文 • 上一篇    下一篇

云环境下软件定义入侵检测系统设计

周益周(), 王斌, 谢小权   

  1. 中国航天科工集团第二研究院七〇六所,北京 100854
  • 收稿日期:2015-07-15 出版日期:2015-09-30 发布日期:2015-11-13
  • 作者简介:

    作者简介: 周益周(1990-),男,山西,助理工程师,硕士,主要研究方向:信息安全;王斌(1981-),男,山西,高级工程师,博士,主要研究方向:可信计算;谢小权(1963-),男,江西,研究员,硕士,主要研究方向:信息安全。

Design of Software Defined Intrusion Detection System in Cloud

Yi-zhou ZHOU(), Bin WANG, Xiao-quan XIE   

  1. Institute 706, The Second Academy of China Aerospace Science and Industry Corporation, Beijing 100854, China
  • Received:2015-07-15 Online:2015-09-30 Published:2015-11-13

摘要:

云计算技术在近十年的发展中得到了学术界与产业界的广泛关注,其安全问题制约着云计算技术的发展,针对云中所面临的安全问题,往往采用多种安全手段结合的解决方案来保障其安全。在这些安全手段中,入侵检测是云安全解决方案中不可缺少的重要环节。文章针对使用软件定义网络(software defined network,SDN)技术的云平台,分析总结了入侵检测系统在云上部署时所面临的问题和对应的解决方案,提出了入侵检测系统的设计目标。同时基于SDN思想,设计了一个软件定义的入侵检测系统,该系统具有鲁棒性,可以降低云中的资源消耗,还能在虚拟机迁移后,使其依然处于系统的保护之下。

关键词: 云计算, 入侵检测系统, 软件定义网络

Abstract:

The technology of cloud computing has received the attention of academia and industry in the development of the last ten years, but the security problem restricts its development. Towards the security issues faced by the cloud, the cloud often use a variety of security means the combination of solutions to ensure its security. In these security measures, intrusion detection system (IDS) is an important and indispensable link in cloud security solutions. In this paper, towards to the cloud platform which used software defined network (SDN), and the intrusion detection system deployed on it. We analysis the issues the IDS faced and conclude the correspond solutions, put forward the design goal of the IDS, and designed a software defined IDS based on SDN. The system has robustness, it can save the cloud resource consumption, and after the virtual machine migration, it’s still under the protection of the IDS, finally realize the important modules of the system.

Key words: cloud computing, intrusion detection system, software defined network

中图分类号: