Network-wide Virtual Firewall using SDN/OpenFlow

被引:0
|
作者
Bakker, Jarrod N. [1 ]
Welch, Ian [1 ]
Seah, Winston K. G. [1 ]
机构
[1] Victoria Univ Wellington, Sch Engn & Comp Sci, Wellington, New Zealand
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional firewalls are used to enforce network security policies at boundaries within a network. However, this can leave hosts vulnerable to attacks that originate from within the network they are part of. We leverage the flexibility of Software Defined Networking to turn the network infrastructure into a virtual firewall thus improving security across an entire network. We present ACLSwitch, a network-wide virtual firewall that utilises the OpenFlow protocol to filter traffic across a network comprised of OpenFlow switches. We also define "policy domains" that allow different filtering configurations to be applied to different switches of the network. The solution allows rules to be distributed across a network without the need for a human operator to send the rules to switches separately, yet it is flexible enough to allow subsets of the switches to enforce different security policies.
引用
收藏
页码:62 / 68
页数:7
相关论文
共 50 条
  • [41] Optimal Endorsement for Network-Wide Distributed Blockchains
    Lotfimahyari, Iman
    Giaccone, Paolo
    IEEE SYSTEMS JOURNAL, 2023, 17 (03): : 4775 - 4785
  • [42] Mining Dynamic Network-Wide Traffic States
    Paz, Alexander
    Gaviria, Carlos
    Arteaga, Cristian
    Torres-Jimenez, Jose
    2018 21ST INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS (ITSC), 2018, : 999 - 1004
  • [43] Sluice: Network-Wide Data Plane Programming
    Natesh, Vikas
    Kannan, Pravein Govindan
    Sivaraman, Anirudh
    Netravali, Ravi
    PROCEEDINGS OF THE 2019 ACM SIGCOMM CONFERENCE POSTERS AND DEMOS (SIGCOMM '19), 2019, : 156 - 158
  • [44] Enhanced SDN Security using Firewall in a Distributed scenario
    Satasiya, Dhaval
    Raviya, Rupal
    Kumar, Hiresh
    PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION CONTROL AND COMPUTING TECHNOLOGIES (ICACCCT), 2016, : 588 - 592
  • [45] Network-wide cooperative computing architecture (NCCA)
    Yamashita, H.
    Suguri, T.
    Kinoshita, Sh.
    NTT R and D, 1998, 47 (02): : 139 - 148
  • [46] BoLTE: Efficient Network-wide LTE Broadcasting
    Sivaraj, Rajarajan
    Arslan, Mustafa
    Sundaresan, Karthikeyan
    Rangaraja, Sampath
    Mohapatra, Prasant
    2017 IEEE 25TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2017,
  • [47] Exploring Network-Wide Flow Data With Flowyager
    Saidi, Said Jawad
    Maghsoudlou, Aniss
    Foucard, Damien
    Smaragdakis, Georgios
    Poese, Ingmar
    Feldmann, Anja
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (04): : 1988 - 2006
  • [48] On demand network-wide VPN deployment in GPRS
    Xenakis, C
    Merakos, L
    IEEE NETWORK, 2002, 16 (06): : 28 - 37
  • [49] Snowcap: Synthesizing Network-Wide Configuration Updates
    Schneider, Tibor
    Birkner, Ruediger
    Vanbever, Laurent
    SIGCOMM '21: PROCEEDINGS OF THE 2021 ACM SIGCOMM 2021 CONFERENCE, 2021, : 33 - 49
  • [50] Network-wide measurement of GPRS bandwidth and latency
    Pfitzinger, Bernd
    Baumann, Tommy
    Emde, Andreas
    Gruender, Torsten
    Macos, Dragan
    Jestaedt, Thomas
    PROCEEDINGS OF THE 52ND ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2019, : 7521 - 7528