ID 原文 译文
46226 软件定义网络(SDN, software-defined networking)将传统网络控制平面与转发平面分离,形成集中式的控制器,开放了网络编程接口,简化网络管理,促进网络创新,优化网络运行。 Software-defined network (SDN) separated the traditional control plane from the data plane, formed a centralized controller, opened up the network programming interface, simplified network management, promoted network innovation and optimized network operation.
46227 然而,SDN 的“三层两接口” 架构增加了网络攻击表面,导致诸多新的安全问题。 However, SDN's “three-layer two-interface” architecture increased the net-work attack surface, resulting in many new security issues.
46228 首先,介绍 SDN 发展、特点及其工作原理,继而从应用层、北向接口、控制层、南向接口、数据层等 5 个层次归纳存在的安全问题,分析产生的原因; The development, characteristics and working principle of SDN were first introduced, and the existing security problems from the application layer, the northbound interface, the control plane, the southbound interface, the data plane were summarized respectively.
46229 其次,针对各类安全问题讨论最新研究进展及现有解决方案; Secondly, the latest research progress and existing solutions were discussed.
46230 最后,总结 SDN 当前和未来的安全挑战,并展望未来 SDN 安全发展方向。 Finally, SDN current and future security challenges were summarized, and the future SDN security development direction was looked forward to.
46231 攻击图是一种预判攻击者对目标网络发动攻击的方式和过程,指导防御方对网络中的节点采取针对性防御措施,提高网络安全性的技术。 Attack graph technology was a measure to predict the pattern and process used by attacker to compromise the target network, so as to guide defender to take defensive measures and improve network security.
46232 首先介绍了攻击图的基本构成,列举了攻击图的几种类型及其各自的优缺点, The basic component,types of attack graphs and respective advantages and disadvantages of each type were reviewed.
46233 然后介绍了攻击图技术目前在风险评估和网络加固、入侵检测和告警关联等方面的应用现状以及现有的几种攻击图生成和分析工具, The application status of attack graph technology in risk assessment and network hardening, intrusion detection and alarm correlation, and other aspects were introduced. Several kinds of existing attack graph generation and analysis tools were also presented.
46234 最后指出了攻击图技术面临的挑战和未来可能的研究方向。 At last a survey of some challenges and research trends in future research work was provided.
46235 提出一种基于拍卖模型的移动社交网络数据转发激励机制—AMIM。 A data forwarding incentive mechanism based on auction model in mobile social network was proposed.