請用此 Handle URI 來引用此文件:
http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/74053| 標題: | SDN分散式防火牆高效規則部署 Efficient Algorithm for Distributed Firewall Architecture in SDN Environment |
| 作者: | Yu-Wei Chang 張育維 |
| 指導教授: | 林宗男 |
| 關鍵字: | 軟體定義網路,防火牆,網路,網路通訊協定,線性整數規劃, Software-Defined Network,Firewall,Internet,OpenFlow,Integer Linear Programming, |
| 出版年 : | 2019 |
| 學位: | 碩士 |
| 摘要: | 為了保護內部服務和主機不受網絡攻擊,防火牆是過濾網路攻擊封包的重要手段。典型的防火牆部署在內網的入口點。但是,隨著越來越多的雲端和物聯網等,網絡環境變得比以往更加靈活和動態。因此,有必要部署分散式防火牆才可以防護內網足夠的安全性。我們提出在軟件定義的網絡環境中分散式防火牆,並將防火牆規則的佈局表示為整數線性編程問題。儘管如此,整數線性規劃的複雜性通常是NP-Complete的。若是有大量規則或復雜的網絡拓撲,解決線性整數規劃將花費大量時間,這對於管理分散式防火牆是不可行的。因此,我們引入了Resource Constraint Splitting演算法以減少時間複雜度。關鍵步驟是將decision variable分離為不相關的子問題後並行解決。這種分散式防火牆在許多方面都是一項重大改進,包括更低的網路延遲和節省內網流量。 Mininet中的OpenFlow控制器的實驗結果表明,該方法在網絡吞吐量和延遲方面表現出比先前研究中的結果,能提供相同的保護與有更好的網絡性能。 To protect internal services and hosts from network attacks, a firewall is an essential component to enforce security policies on Internet connections. A typical firewall is deployed at the entry point of an autonomous system. However, network environments, such as the Cloud and the IoT, have become much more flexible and dynamic than ever. As a result, it is necessary to deploy a distributed firewall. We present a distributed firewall in a software-defined network environment and formulate the placement of firewall rules as an integer linear programming problem. Nonetheless, the complexity of the integer linear programming is usually NP-complete. With a large number of rules and a complex network topology, solving it will take a huge amount of time, which is infeasible for managing a distributed firewall. As a result, we introduce a resource constraint splitting algorithm to reduce the time complexity. The key idea is to separate the decision variables into disjoint subproblems and to solve them in parallel. This distributed firewall is a substantial improvement in many aspects, including higher levels of security, lower latency, and reduced traffic. Experimental results from an OpenFlow controller in Mininet demonstrate that this approach shows better network performance than that shown in previous studies in terms of network throughput and latency. |
| URI: | http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/74053 |
| DOI: | 10.6342/NTU201902946 |
| 全文授權: | 有償授權 |
| 顯示於系所單位: | 電信工程學研究所 |
文件中的檔案:
| 檔案 | 大小 | 格式 | |
|---|---|---|---|
| ntu-108-1.pdf 未授權公開取用 | 1.13 MB | Adobe PDF |
系統中的文件,除了特別指名其著作權條款之外,均受到著作權保護,並且保留所有的權利。
