FORTRESS: An Efficient and Distributed Firewall for Stateful Data Plane SDN

被引:19
|
作者
Caprolu, Maurantonio [1 ]
Raponi, Simone [1 ]
Di Pietro, Roberto [1 ]
机构
[1] HBKU, Div Informat & Comp Technol ICT, CSE, Doha, Qatar
关键词
SECURITY; NETWORK;
D O I
10.1155/2019/6874592
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Software Defined Networking (SDN) paradigm decouples the logic module from the forwarding module on traditional network devices, bringing a wave of innovation to computer networks. Firewalls, as well as other security appliances, can largely benefit from this novel paradigm. Firewalls can be easily implemented by using the default OpenFlow rules, but the logic must reside in the control plane due to the dynamic nature of their rules that cannot be handled by data plane devices. This leads to a nonnegligible overhead in the communication channel between layers, as well as introducing an additional computational load on the control plane. To address the above limitations, we propose the architectural design of FORTRESS: a stateful firewall for SDN networks that leverages the stateful data plane architecture to move the logic of the firewall from the control plane to the data plane. FORTRESS can be implemented according to two different architectural designs: Stand-Alone and Cooperative, each one with its own peculiar advantages. We compare FORTRESS against FlowTracker, the state-of-the-art solution for SDN firewalling, and show how our solution outperforms the competitor in terms of the number of packets exchanged between the control plane and the data plane-we require 0 packets for the Stand-Alone architecture and just 4 for the Cooperative one. Moreover, we discuss how the adaptability, elegant and modular design, and portability of FORTRESS contribute to make it the ideal candidate for SDN firewalling. Finally, we also provide further research directions.
引用
收藏
页数:16
相关论文
共 50 条
  • [41] Security Policy Violations in SDN Data Plane
    Li, Qi
    Chen, Yanyu
    Lee, Patrick P. C.
    Xu, Mingwei
    Ren, Kui
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2018, 26 (04) : 1715 - 1727
  • [42] SDN Partitioning: A Centralized Control Plane for Distributed Routing Protocols
    Caria, Marcel
    Jukan, Admela
    Hoffmann, Marco
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2016, 13 (03): : 381 - 393
  • [43] Validation of Distributed SDN Control Plane Under Uncertain Failures
    Xie, Junjie
    Guo, Deke
    Qian, Chen
    Liu, Lei
    Ren, Bangbang
    Chen, Honghui
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2019, 27 (03) : 1234 - 1247
  • [44] Renaissance: A Self-Stabilizing Distributed SDN Control Plane
    Canini, Marco
    Salem, Iosif
    Schiff, Liron
    Schiller, Elad M.
    Schmid, Stefan
    2018 IEEE 38TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2018, : 233 - 243
  • [45] A Distributed and Robust SDN Control Plane for Transactional Network Updates
    Canini, Marco
    Kuznetsov, Petr
    Levin, Dan
    Schmid, Stefan
    2015 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (INFOCOM), 2015,
  • [46] Towards Adaptive State Consistency in Distributed SDN Control Plane
    Sakic, Ermin
    Sardis, Fragkiskos
    Guck, Jochen W.
    Kellerer, Wolfgang
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [47] Proactive Load Shifting for Distributed SDN Control Plane Architecture
    Akanbi, Oluwatobi
    Aljaedi, Amer
    Zhou, Xiaobo
    2019 16TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2019,
  • [48] Profiling and SW/HW Co-design for Efficient SDN/OpenFlow Data Plane Realization
    Wang, Ching-Che
    Chen, Yi-Ta
    Lee, Ding-Yuan
    Kao, Sheng-Chun
    Wu, An-Yeu
    PROCEEDINGS OF 2017 IEEE 7TH INTERNATIONAL CONFERENCE ON ELECTRONICS INFORMATION AND EMERGENCY COMMUNICATION (ICEIEC), 2017, : 438 - 443
  • [49] SDN-aware federation of distributed data
    Koulouzis, Spiros
    Belloum, Adam S. Z.
    Bubak, Marian T.
    Zhao, Zhiming
    Zivkovic, Miroslav
    de Laat, Cees T. A. M.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2016, 56 : 64 - 76
  • [50] SDPA: Toward a Stateful Data Plane in Software-Defined Networking
    Sun, Chen
    Bi, Jun
    Chen, Haoxian
    Hu, Hongxin
    Zheng, Zhilong
    Zhu, Shuyong
    Wu, Chenghui
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (06) : 3294 - 3308