信息网络安全 ›› 2026, Vol. 26 ›› Issue (6): 925-943.doi: 10.3969/j.issn.1671-1122.2026.06.007

• 学术研究 • 上一篇    下一篇

基于路径定位与规模聚合的跨域网络防御策略一致性验证方法

刘馨璐1(), 常德显1,2, 张大伟1   

  1. 1 网络空间部队信息工程大学密码工程学院郑州 450001
    2 河南省信息安全重点实验室郑州 450001
  • 收稿日期:2025-11-24 出版日期:2026-06-10 发布日期:2026-07-27
  • 通讯作者: 刘馨璐 E-mail:347980008@qq.com
  • 作者简介:刘馨璐(2001—),女,辽宁,硕士研究生,主要研究方向为网络主动防御|常德显(1977—),男,河南,副教授,博士,主要研究方向为网络信息防御|张大伟(1996—),男,安徽,硕士研究生,主要研究方向为网络安全管理
  • 基金资助:
    中国博士后科学基金(GZC20240321)

A Consistency Verification Method for Cross-Domain Network Defense Strategies Based on Path Location and Scale Aggregation

LIU Xinlu1(), CHANG Dexian1,2, ZHANG Dawei1   

  1. 1 School of Cyptography Engineering, Cyberspace Force Information Engineering University, Zhengzhou 450001, China
    2 Henan Provincial Key Laboratory of Information Security, Zhengzhou 450001, China
  • Received:2025-11-24 Online:2026-06-10 Published:2026-07-27
  • Contact: LIU Xinlu E-mail:347980008@qq.com

摘要:

随着软件定义网络在云网融合的多域环境中泛化部署,跨域防御策略的一致性验证已成为保障网络服务质量与安全的关键挑战。传统全路径验证方法因计算与通信开销过大,缺乏动态适应性,难以适用于大规模云网环境下的轻量级验证场景。基于此文章提出一种轻量级跨域网络防御策略验证方法。首先,设计了一种基于深度强化学习与最优监控分配的混合算法,动态精准定位策略影响的关键路径与最小监控点集,避免了全网范围的下发与探测。其次,构建了多目标优化的任务调度模型,综合策略紧急度、重要性及网络负载等因素动态调整并验证优先级,实现验证资源的高效利用。实验结果表明,与现有方法相比,本文方法适用于大规模动态跨域SDN环境。

关键词: 跨域管理, 策略验证, 深度强化学习, 多目标优化

Abstract:

With the generalized deployment of software defined network in the multi-domain environment of cloud-network convergence, the consistency verification of cross-domain defense strategies has become a key challenge in ensuring the quality and security of network services. The traditional full-path verification method is difficult to be applied to lightweight verification scenarios in large-scale cloud network environments due to its excessive computational and communication overheads and lack of dynamic adaptability. This paper proposed a lightweight verification method for cross-domain network defense strategies. Firstly, a hybrid algorithm based on deep reinforcement learning and optimal monitoring allocation was designed to dynamically and accurately locate the critical path and the minimum monitoring point set affected by the strategy, avoiding the distribution and detection across the entire network. Secondly, a multi-objective optimization task scheduling model was constructed. The verification priority was dynamically adjusted by comprehensively considering factors such as the urgency, importance of the strategy, and network load to achieve efficient utilization of verification resources. The experimental results show that, compared with the existing methods, the method proposed in this paper is suitable for large-scale dynamic cross-domain SDN environments.

Key words: cross-domain management, strategy verification, deep reinforcement learning, multi-objective optimization

中图分类号: