SDFW: SDN-based Stateful Distributed Firewall

11/01/2018
by   Ankur Chowdhary, et al.
0

SDN provides a programmable command and control networking system in a multi-tenant cloud network using control and data plane separation. However, separating the control and data planes make it difficult for incorporating some security services (e.g., firewalls) into SDN framework. Most of the existing solutions use SDN switches as packet filters and rely on SDN controllers to implement firewall policy management functions, which is impractical for implementing stateful firewalls since SDN switches only send session's initial packets and statistical data of flows to their controllers. For a data center networking environment, applying a Distributed FireWall (DFW) system to prevent attacker's lateral movements is highly desired, in which designing and implementing an SDN-based Stateful DFW (SDFW) demand a scalable distributed states management solution at the data plane to track packets and flow states. Our performance results show that SDFW achieves scalable security against data plane attacks with a marginal performance hit 1.6 bandwidth.

READ FULL TEXT
research
11/01/2018

TRUFL: Distributed Trust Management framework in SDN

Software Defined Networking (SDN) has emerged as a revolutionary paradig...
research
01/20/2023

Defending SDN against packet injection attacks using deep learning

The (logically) centralised architecture of the software-defined network...
research
09/12/2023

RackBlox: A Software-Defined Rack-Scale Storage System with Network-Storage Co-Design

Software-defined networking (SDN) and software-defined flash (SDF) have ...
research
05/25/2022

P4Filter: A two level defensive mechanism against attacks in SDN using P4

The advancements in networking technologies have led to a new paradigm o...
research
01/14/2020

S3: A DFW-based Scalable Security State Analysis Framework for Large-Scale Data Center Networks

With an average network size approaching 8000 servers, datacenter networ...
research
09/04/2019

Q-DATA: Enhanced Traffic Flow Monitoring in Software-Defined Networks applying Q-learning

Software-Defined Networking (SDN) introduces a centralized network contr...
research
01/21/2020

LOcAl DEcisions on Replicated States (LOADER) in programmable data planes: programming abstraction and experimental evaluation

Programmable data planes recently emerged as a prominent innovation in S...

Please sign up or login with your details

Forgot password? Click here to reset