Software Defined Networking Reactive Stateful Firewall
نویسندگان
چکیده
Network security is a crucial issue of Software Defined Networking (SDN). It is probably, one of the key features for the success and for the future pervasion of the SDN technology. In this perspective, we propose a SDN reactive stateful firewall. Our solution is integrated into the SDN architecture. It filters TCP communications according to the network security policies. It records and processes the different states of a connection and interprets their possible transitions into OpenFlow (OF) rules. The proposition uses a reactive behavior in order to reduce the number of OpenFlow rules in the data plane device and to mitigate some DOS attacks like SYN Flooding. The firewall processes the Finite State Machine of TCP so as to withdraw useless traffic not corresponding to TCP transitions’ conditions. Through our work, we put in light the advantages of our solution. In terms of cost efficiency, it empowers the behavior of Openflow compatible devices to make them behaving like stateful firewalls. Therefore, organizations do not need to spend money and resources on buying and maintaining conventional firewalls. Furthermore, we propose an orchestrator to spread and to reinforce the security policies in the whole network with a fine grained strategy. It is thereupon able to secure the network by filtering the traffic related to an application, a node, a subnetwork connected to a data plane device, a sub SDN network connected to a controller, traffic between different links, etc. The deployment of the firewall rules becomes flexible according to a holistic network view provided by the management plane. In addition, the solution enlarges the security perimeter inside the network itself by securing accesses between its nodes.
منابع مشابه
Enabling security functions with SDN: A feasibility study
Software-defined networking (SDN) is being strongly considered as the next promising networking platform, and studies regarding SDN have been actively conducted accordingly. However, the security of SDN remains undefined and unknown when considering the enhancement of network security in SDN. In this paper, we verify whether SDN can enhance network security. Specifically, the idea of enabling s...
متن کاملTowards Secured Firewalls for Software Defined Networks
Software-Defined Networking (SDN) offers programmers network-wide visibility and direct control over the underlying switches from a logically-centralized controller. SDN provides a promising way for the future development of Internet. SDN, however, also has some new security challenges. A critical challenge among them is how to build a reliable firewall application for SDN. Due to the stateless...
متن کاملTowards a Stateful Forwarding Abstraction to Implement Scalable Network Functions in Software and Hardware
An effective packet processing abstraction that leverages software or hardware acceleration techniques can simplify the implementation of high-performance virtual network functions. In this paper, we explore the suitability of SDN switches’ stateful forwarding abstractions to model accelerated functions in both software and hardware accelerators, such as optimized software switches and FPGA-bas...
متن کاملAccelerating the Performance of Software Tunneling Using a Receive Offload-Aware Novel L4 Protocol
An L2-in-L3 tunneling technology plays an important role in network virtualization based on the concept of Software-Defined Networking (SDN). VXLAN (Virtual eXtensible LAN) and NVGRE (Network Virtualization using Generic Routing Encapsulation) protocols are being widely used in public cloud datacenters. These protocols resolve traditional VLAN problems such as a limitation of the number of virt...
متن کاملSFA: Stateful Forwarding Abstraction in SDN Data Plane
Software Defined Networking (SDN) is a new network architecture where network control is decoupled from forwarding and is directly programmable. However, existing techniques provide limited support for stateful forwarding in SDN data plane. Relying on the controller for all state maintaining gives rise to scalability and performance issues. In this paper, we present Stateful Forwarding Abstract...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016