• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

DDPG-SDPCR: A DDPG-based Software Defined Perimeter Components Redeployment

Vol. 18, No. 9, September 30, 2024
10.3837/tiis.2024.09.014, Download Paper (Free):

Abstract

In wide area SDP networks, the failure of SDP components caused by malicious attacks will be accompanied by different deployment locations, profoundly affecting network service latency. However, traditional deployment methods based on prior knowledge are no longer applicable to dynamic SDP networks. This article proposes a dynamic and dimensionally variable deployment mechanism DDPG-SDPCR for SDP components based on DDPG, which enhances the network's endogenous security capability and improves attack tolerance. Based on this, we constructed corresponding mathematical models for latency, load balancing, and attack tolerance. The DDPG-SDPCR mechanism dynamically deploys new SDP nodes to replace faulty nodes based on the real-time status of the network, thereby achieving imperceptible attack tolerance for users. We have implemented a wide area SDP prototype with endogenous security capabilities and evaluated it under different network topologies, traffic sizes, and network attacks. The evaluation results indicate that under high traffic conditions, our proposed redeployment mechanism outperforms the baseline by 36.42% in latency, and only increases by 19.24% compared to the non attacked situation.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
Z. Zhang, Q. Ren, J. Lu, Y. Hu, H. Chen, "DDPG-SDPCR: A DDPG-based Software Defined Perimeter Components Redeployment," KSII Transactions on Internet and Information Systems, vol. 18, no. 9, pp. 2739-2763, 2024. DOI: 10.3837/tiis.2024.09.014.

[ACM Style]
Zheng Zhang, Quan Ren, Jie Lu, Yuxiang Hu, and Hongchang Chen. 2024. DDPG-SDPCR: A DDPG-based Software Defined Perimeter Components Redeployment. KSII Transactions on Internet and Information Systems, 18, 9, (2024), 2739-2763. DOI: 10.3837/tiis.2024.09.014.

[BibTeX Style]
@article{tiis:101212, title="DDPG-SDPCR: A DDPG-based Software Defined Perimeter Components Redeployment", author="Zheng Zhang and Quan Ren and Jie Lu and Yuxiang Hu and Hongchang Chen and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2024.09.014}, volume={18}, number={9}, year="2024", month={September}, pages={2739-2763}}