Network-wide Virtual Firewall using SDN/OpenFlow

被引:0
|
作者
Bakker, Jarrod N. [1 ]
Welch, Ian [1 ]
Seah, Winston K. G. [1 ]
机构
[1] Victoria Univ Wellington, Sch Engn & Comp Sci, Wellington, New Zealand
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional firewalls are used to enforce network security policies at boundaries within a network. However, this can leave hosts vulnerable to attacks that originate from within the network they are part of. We leverage the flexibility of Software Defined Networking to turn the network infrastructure into a virtual firewall thus improving security across an entire network. We present ACLSwitch, a network-wide virtual firewall that utilises the OpenFlow protocol to filter traffic across a network comprised of OpenFlow switches. We also define "policy domains" that allow different filtering configurations to be applied to different switches of the network. The solution allows rules to be distributed across a network without the need for a human operator to send the rules to switches separately, yet it is flexible enough to allow subsets of the switches to enforce different security policies.
引用
收藏
页码:62 / 68
页数:7
相关论文
共 50 条
  • [21] Diagnosing network-wide traffic anomalies
    Lakhina, A
    Crovella, M
    Diot, C
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2004, 34 (04) : 219 - 230
  • [22] Packet_In message based DDoS attack detection in SDN network using OpenFlow
    You, Xiang
    Feng, Yaokai
    Sakurai, Kouichi
    2017 FIFTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING (CANDAR), 2017, : 522 - 528
  • [23] Cooperative Network-wide Flow Selection
    Basat, Ran Ben
    Einziger, Gil
    Tayh, Bilal
    2020 IEEE 28TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (IEEE ICNP 2020), 2020,
  • [24] iNaaS : OpenStack and SDN/OpenFlow based network virtualization with OpenIRIS
    Shin, Y. Y.
    Kang, S. H.
    Kwak, J. Y.
    Yang, S. H.
    2015 17TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2015, : 517 - 520
  • [25] A tool for tracing network data plane via SDN/OpenFlow
    Yangyang WANG
    Jun BI
    Keyao ZHANG
    ScienceChina(InformationSciences), 2017, 60 (02) : 74 - 86
  • [26] A tool for tracing network data plane via SDN/OpenFlow
    Wang, Yangyang
    Bi, Jun
    Zhang, Keyao
    SCIENCE CHINA-INFORMATION SCIENCES, 2017, 60 (02)
  • [27] Lightweight Network-Wide Telemetry Without Explicitly Using Probe Packets
    Pan, Tian
    Song, Enge
    Jia, Chenhao
    Cao, Wendi
    Huang, Tao
    Liu, Bin
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 1354 - 1355
  • [28] A tool for tracing network data plane via SDN/OpenFlow基于SDN/OpenFlow 追踪网络数据平面的工具
    Yangyang Wang
    Jun Bi
    Keyao Zhang
    Science China Information Sciences, 2017, 60
  • [29] Analyzing network-wide patterns of rail transit delays using Bayesian network learning
    Ulak, Mehmet Baran
    Yazici, Anil
    Zhang, Yun
    TRANSPORTATION RESEARCH PART C-EMERGING TECHNOLOGIES, 2020, 119
  • [30] One-way delay estimation using network-wide measurements
    Gurewitz, Omer
    Cidon, Israel
    Sidi, Moshe
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2006, 52 (06) : 2710 - 2724