信息安全研究 ›› 2024, Vol. 10 ›› Issue (10): 903-.

• 零信任安全专题 • 上一篇    下一篇

基于联邦学习的SDP信任评估模型设计

池亚平1,2刘佳辉2梁家铭1   

  1. 1(北京电子科技学院网络空间安全系北京100070)
    2(西安电子科技大学通信工程学院西安710071)
  • 出版日期:2024-10-15 发布日期:2024-10-15
  • 通讯作者: 池亚平 硕士,教授.主要研究方向为网络安全防护、云计算安全. chi_besti@163.com
  • 作者简介:池亚平 硕士,教授.主要研究方向为网络安全防护、云计算安全. chi_besti@163.com 刘佳辉 硕士.主要研究方向为云计算安全. yljiahui@126.com 梁家铭 硕士.主要研究方向为云计算安全. liangjm_3@126.com

Design of SDP Trust Evaluation Model Based on Federated Learning

Chi Yaping1,2, Liu Jiahui2, and Liang Jiaming1   

  1. 1(Cyberspace Security Department, Beijing Electronic Science and Technology Institute, Beijing 100070)
    2(School of Communication Engineering, Xidian University, Xi’an 710071)

  • Online:2024-10-15 Published:2024-10-15

摘要: 随着网络边界日益模糊,零信任作为网络安全防御的新范式应运而生.针对零信任安全架构在面对大数据时代所带来的海量上下文信息和多样化终端情境下,信任评估效率低且难以有效保护用户数据隐私的问题,提出了一种基于联邦学习的SDP信任评估模型及其部署方法.该模型通过去中心化思想,在不共享原始数据的情况下训练全局模型,保护各分布式SDP控制器节点的用户数据隐私.通过实验和对比分析,证明此零信任评估模型可有效分类恶意和合法数据流,并且效率优于同类文献方案.

关键词: 零信任, 软件定义边界, 联邦学习, 去中心化, 信任评估

Abstract: With the increasing blurring of network boundaries, zero trust has emerged as a new paradigm for network security defense. A federated learningbased SDP trust evaluation model and its deployment method are proposed to address the issues of low trust evaluation efficiency and difficulty in effectively protecting user data privacy in the face of massive contextual information and diverse terminal scenarios brought by the zero trust security architecture in the era of big data. This model adopts a decentralized approach to train a global model without sharing raw data, protecting the user data privacy of each distributed SDP controller node. Through experiments and comparative analysis, it has been proven that this zero trust evaluation model can effectively classify malicious and legitimate data streams, and its efficiency is superior to similar literature schemes.

Key words: zero trust, SDP, federated learning, decentralization, trust evaluation

中图分类号: