FORTRESS: An Efficient and Distributed Firewall for Stateful Data Plane SDN

被引:19
|
作者
Caprolu, Maurantonio [1 ]
Raponi, Simone [1 ]
Di Pietro, Roberto [1 ]
机构
[1] HBKU, Div Informat & Comp Technol ICT, CSE, Doha, Qatar
关键词
SECURITY; NETWORK;
D O I
10.1155/2019/6874592
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Software Defined Networking (SDN) paradigm decouples the logic module from the forwarding module on traditional network devices, bringing a wave of innovation to computer networks. Firewalls, as well as other security appliances, can largely benefit from this novel paradigm. Firewalls can be easily implemented by using the default OpenFlow rules, but the logic must reside in the control plane due to the dynamic nature of their rules that cannot be handled by data plane devices. This leads to a nonnegligible overhead in the communication channel between layers, as well as introducing an additional computational load on the control plane. To address the above limitations, we propose the architectural design of FORTRESS: a stateful firewall for SDN networks that leverages the stateful data plane architecture to move the logic of the firewall from the control plane to the data plane. FORTRESS can be implemented according to two different architectural designs: Stand-Alone and Cooperative, each one with its own peculiar advantages. We compare FORTRESS against FlowTracker, the state-of-the-art solution for SDN firewalling, and show how our solution outperforms the competitor in terms of the number of packets exchanged between the control plane and the data plane-we require 0 packets for the Stand-Alone architecture and just 4 for the Cooperative one. Moreover, we discuss how the adaptability, elegant and modular design, and portability of FORTRESS contribute to make it the ideal candidate for SDN firewalling. Finally, we also provide further research directions.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Stateful Distributed Firewall as a Service in SDN
    Zeineddine, Ali
    El-Hajj, Wassim
    2018 4TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION AND WORKSHOPS (NETSOFT), 2018, : 212 - 216
  • [2] Implementation of SDN Stateful Firewall on Data Plane using Open vSwitch
    Krongbaramee, Pakapol
    Somchit, Yuthapong
    2018 15TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (JCSSE), 2018, : 110 - 114
  • [3] SDN-based Stateful Firewall for Cloud
    Li, Jian
    Jiang, Hao
    Jiang, Wei
    Wu, Jing
    Du, Wen
    2020 IEEE 6TH INT CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY) / 6TH IEEE INT CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING, (HPSC) / 5TH IEEE INT CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2020, : 157 - 161
  • [4] Traffic Management Applications for Stateful SDN Data Plane
    Cascone, Carmelo
    Pollini, Luca
    Sanvito, Davide
    Capone, Antonio
    2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 85 - 90
  • [5] An Efficient Dynamic Rule Placement for Distributed Firewall in SDN
    Chang, Yu-Wei
    Lin, Tsung-Nan
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [6] Fast failure detection and recovery in SDN with stateful data plane
    Cascone, Carmelo
    Sanvito, Davide
    Pollini, Luca
    Capone, Antonio
    Sanso, Brunilde
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2017, 27 (02)
  • [7] Performance Evaluation of Stateful Firewall-Enabled SDN with Flow-Based Scheduling for Distributed Controllers
    Senthil, P.
    Kavin, Balasubramanian Prabhu
    Srividhya, S. R.
    Ramachandran, V
    Kavitha, C.
    Lai, Wen-Cheng
    ELECTRONICS, 2022, 11 (19)
  • [8] Efficient caching through stateful SDN in named data networking
    Mahmood, A.
    Casetti, C.
    Chiasserini, C. F.
    Giaccone, P.
    Harri, J.
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2018, 29 (01):
  • [9] Efficient Data Plane Protection for SDN
    Merling, Daniel
    Braun, Wolfgang
    Menth, Michael
    2018 4TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION AND WORKSHOPS (NETSOFT), 2018, : 10 - 18
  • [10] An Anomaly Free Distributed Firewall System for SDN
    Sinha, Mitali
    Bera, Padmalochan
    Satpathy, Manoranjan
    2021 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA 2021), 2021,