实现基于openflow的分布式防火墙

S. Kaur, K. Kaur, Vipin Gupta
{"title":"实现基于openflow的分布式防火墙","authors":"S. Kaur, K. Kaur, Vipin Gupta","doi":"10.1109/INCITE.2016.7857611","DOIUrl":null,"url":null,"abstract":"SDN is an emerging technology which is going to drive next generation networks. Lot of companies and organizations has started using SDN applications. It is giving network administrators the flexibility in implementing their networks. But at the same time, it is bringing new security issues. To secure SDN networks, we need strong firewall application. Already some firewall applications are there but they suffer from certain shortcomings. One of the main drawbacks of existing firewall solutions is that they suffer from single point of failure due to their centralized nature and overloading of rules in single device. Other drawback of existing firewall is that they are mostly layer 2 firewalls. In this paper, we are implementing Distributed Firewall where every OpenFlow switch in a network can acts as a firewall. Plus this firewall will be capable of handling TCP, UDP and ICMP Traffic. We have tested this firewall using Mininet Emulator installed in Ubuntu 14.04 Linux installed under VirtualBox virtualization solution. We are using python based POX controller. This work is extension of our earlier work on programmable firewalls.","PeriodicalId":59618,"journal":{"name":"下一代","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2016-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":"{\"title\":\"Implementing openflow based distributed firewall\",\"authors\":\"S. Kaur, K. Kaur, Vipin Gupta\",\"doi\":\"10.1109/INCITE.2016.7857611\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"SDN is an emerging technology which is going to drive next generation networks. Lot of companies and organizations has started using SDN applications. It is giving network administrators the flexibility in implementing their networks. But at the same time, it is bringing new security issues. To secure SDN networks, we need strong firewall application. Already some firewall applications are there but they suffer from certain shortcomings. One of the main drawbacks of existing firewall solutions is that they suffer from single point of failure due to their centralized nature and overloading of rules in single device. Other drawback of existing firewall is that they are mostly layer 2 firewalls. In this paper, we are implementing Distributed Firewall where every OpenFlow switch in a network can acts as a firewall. Plus this firewall will be capable of handling TCP, UDP and ICMP Traffic. We have tested this firewall using Mininet Emulator installed in Ubuntu 14.04 Linux installed under VirtualBox virtualization solution. We are using python based POX controller. This work is extension of our earlier work on programmable firewalls.\",\"PeriodicalId\":59618,\"journal\":{\"name\":\"下一代\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"12\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"下一代\",\"FirstCategoryId\":\"1092\",\"ListUrlMain\":\"https://doi.org/10.1109/INCITE.2016.7857611\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"下一代","FirstCategoryId":"1092","ListUrlMain":"https://doi.org/10.1109/INCITE.2016.7857611","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 12

摘要

SDN是推动下一代网络发展的新兴技术。许多公司和组织已经开始使用SDN应用程序。它为网络管理员实现其网络提供了灵活性。但与此同时,它也带来了新的安全问题。为了保证SDN网络的安全,我们需要强大的防火墙应用。已经有一些防火墙应用程序,但它们存在某些缺点。现有防火墙解决方案的主要缺点之一是,由于其集中性和单个设备中的规则过载,它们遭受单点故障的困扰。现有防火墙的另一个缺点是它们大多是第2层防火墙。在本文中,我们正在实现分布式防火墙,其中网络中的每个OpenFlow交换机都可以充当防火墙。此外,该防火墙将能够处理TCP, UDP和ICMP流量。我们使用Mininet模拟器测试了这个防火墙,安装在Ubuntu 14.04 Linux上,安装在VirtualBox虚拟化解决方案下。我们正在使用基于python的POX控制器。这项工作是我们早期可编程防火墙工作的扩展。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Implementing openflow based distributed firewall
SDN is an emerging technology which is going to drive next generation networks. Lot of companies and organizations has started using SDN applications. It is giving network administrators the flexibility in implementing their networks. But at the same time, it is bringing new security issues. To secure SDN networks, we need strong firewall application. Already some firewall applications are there but they suffer from certain shortcomings. One of the main drawbacks of existing firewall solutions is that they suffer from single point of failure due to their centralized nature and overloading of rules in single device. Other drawback of existing firewall is that they are mostly layer 2 firewalls. In this paper, we are implementing Distributed Firewall where every OpenFlow switch in a network can acts as a firewall. Plus this firewall will be capable of handling TCP, UDP and ICMP Traffic. We have tested this firewall using Mininet Emulator installed in Ubuntu 14.04 Linux installed under VirtualBox virtualization solution. We are using python based POX controller. This work is extension of our earlier work on programmable firewalls.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
6212
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信