Journal of Information Security Reserach ›› 2021, Vol. 7 ›› Issue (9): 861-870.

Previous Articles     Next Articles

Edge-Cloud Synergy Information Security Protection Method for Industrial Control System Based on SDN under DDoS Attack

  

  • Online:2021-09-13 Published:2021-09-13

DDoS攻击下基于SDN的工业控制系统边云协同信息安全防护方法

叶鑫豪 周纯杰 朱美潘 杨健晖   

  1. (华中科技大学人工智能与自动化学院,武汉 430074)
  • 通讯作者: 叶鑫豪
  • 作者简介:叶鑫豪 (1996-) 硕士研究生,主要研究方向为边云协同的信息物理融合系统安全响应. (806212938@qq.com) 周纯杰(1965-) 教授,博士生导师,主要研究方向为工业互联网技术与工业信息物理系统安全,工业控制系统的安全(功能安全、信息安全等)控制技术,人工智能技术与工业应用. (cjiezhou@hust.edu.cn) 朱美潘(1997-) 硕士研究生,主要研究方向为工业互联网及其安全防护. (909799705@qq.com) 杨健晖(1998-) 硕士研究生,主要研究方向为云计算环境下的工业控制系统安全防护. (1029137049@qq.com)

Abstract: Software-defined network (SDN) is a new type of network architecture, which is characterized by the separation of control and forwarding and supports programmatic control of the network. The combination of SDN and industrial control systems provides new ideas for solving the information security problems of industrial control systems, while also making DDoS attacks a major security threat to industrial control system networks. As a converted DDoS attack, overload attack uses the vulnerability of limited load in SDN controllers and switches to pose a threat to the entire SDN network. At the same time, due to the continuous growth of SDN network service demand and the diversity of network applications, the scale of SDN network is gradually changing from the initial single-controller network to the multi-controller network. Facing the increasingly complex network scale, it is difficult to effectively defend the attacks when resources on the edge are limited. Therefore, this article uses the resource advantage of cloud computing, based on SDN network, combined with port and address hopping and load balancing algorithms, and proposes an edge-cloud synergy information security protection method for industrial control system to effectively defend against DDoS attacks.

Key words: DDoS attacks, software-defined network, edge-cloud synergy, industrial control system, information security 

摘要: 软件定义网络(SDN)是一种新型网络架构,其特点是控制与转发分离并支持通过编程的方式对网络进行控制。SDN与工业控制系统的结合为解决工业控制系统信息安全问题提供了新的思路的同时也使得DDoS攻击成为工业控制系统网络的主要安全威胁。过载攻击作为一种转换的DDoS攻击,利用SDN控制器及交换机中负载受限这一漏洞,对整个SDN网络造成威胁。与此同时,由于SDN网络业务需求量的不断增长和网络应用的多样性,SDN网络规模正在由初期的单一控制器网络逐步向多控制器网络转变。面对日益复杂的网络规模,在边缘端资源受限的情况下难以进行有效防御。针对上述问题,利用云端资源优势,基于SDN网络,并结合端址跳变和负载均衡算法提出一种工业控制系统边云协同信息安全防护方法,有效防御DDoS攻击。

关键词: DDoS攻击, 软件定义网络, 边云协同, 工业控制系统, 信息安全