首页|面向智算融合网络的自主防御范式研究

面向智算融合网络的自主防御范式研究

扫码查看
随着数字经济时代算力供给模式的变革,以算力为核心的新型网络基础设施已成为实现算力资源共享、支撑数字经济转型的重要动力.在算力网络中,多元异构用户终端通过多种方式高频接入网络以随时随地获取算力服务,网络的开放性和动态性增大,算力网络将面临更严峻的安全挑战.然而,基于传统网络的安全防御模式通常针对具体安全问题静态式增补安全防护组件,无法主动适配用户需求灵活调整防御策略,难以应对算力网络中的安全风险.因此,本文面向新型算力网络安全需求,将安全功能作为网络内部属性,基于智算融合网络提出一种多维协同自主防御范式.结合智算融合网络"三层""三域"的设计思想,在"三层"中,以广义服务层定义安全固有服务,以映射适配层智慧适配安全功能,以融合组件层执行安全策略;在"三域"中,以实体域先导资源适配,以知识域驱动安全服务流程,以感控域实施具体安全技术,构建"检测""溯源""防御"三维一体的完整基础管控流程,其中安全策略与技术可根据场景扩展性与业务安全性进行灵活调整.最终,通过仿真实验对所提范式有效性进行了验证,为未来智算融合安全的进一步研究和应用提供参考.
Research on Autonomous Defense Paradigm for Smart Computing Integration Networks
With the transformation of the computing power supply pattern in the digital economy era,the new net-work infrastructure with computing power as the core has become an important driving force to realize the sharing of com-puting power resources and support the digital economy transformation.In the computing power network,multiple heteroge-neous user terminals access the network frequently in various ways to obtain computing power services anytime and any-where,which increases the openness and dynamics of the network.Hence,the computing power network will face more se-vere security challenges.However,the traditional network-based security defense pattern usually statically supplements se-curity protection components for specific security issues,which cannot actively adapt to user needs to adjust defense strate-gies flexibly,which is difficult to deal with security risks in computing-network integration scenarios.Therefore,facing the security requirements of the new computing power network,this paper regards security as the internal attribute of the net-work and proposes a multi-dimensional collaborative autonomous defense paradigm based on the smart computing integra-tion networks,which combines the design of"three layers"and"three domains"of the network.In the"three layers",this paper defines the security inherent service at the generalized service layer,adapts the security function at the mapping adap-tation layer,and executes the security strategy at the fusion component layer.In the"three domains",the resource adapta-tion is guided by the entity domain,the security service process is driven by the knowledge domain,and the specific securi-ty technologies are implemented by the sense control domain.It constructs a basic management and control process that in-tegrates"detection","trace",and"defense",in which security policies and technologies can be flexibly adjusted according to scenario scalability and business security.Finally,the proposed paradigm is verified through simulation experiments,and the results prove the effectiveness of the proposed paradigm and also provide a reference for further research and applica-tion of smart computing fusion security in the future.

smart computing integration networkscomputing power networkautonomous defensedefense para-digmnetwork attack

刘颖、夏雨、于成晓、张维庭、汪润虎、张宏科

展开 >

北京交通大学电子信息工程学院,北京 100044

鹏城实验室,广东深圳 518055

中国电子科技集团有限公司第二十八研究所,江苏南京 210007

智算融合网络 算力网络 自主防御 防御范式 网络攻击

鹏城实验室重大项目国家重点研发计划国家自然科学基金中国博士后科学基中国博士后科学基

2022ZD0115301622010292022M710007BX20220029

2024

电子学报
中国电子学会

电子学报

CSTPCD北大核心
影响因子:1.237
ISSN:0372-2112
年,卷(期):2024.52(5)