Firewall as a service in SDN OpenFlow network

被引:0
|
作者
Arins, Andis [1 ]
机构
[1] Univ Latvia, Fac Comp, Riga, Latvia
关键词
BGP; latency; BGP experimentation;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Protecting publicly available servers in internet today is a serious challenge, especially when encountering Distributed denial-of-service (DDoS) attacks. In traditional internet, there is narrow scope of choices one can take when ingress traffic overloads physical connection limits. This paper proposes Firewall as a service in internet service providers (ISP) networks allowing end users to request and install match-action rules in ISPs edge routers. In proposed scenario, ISP runs Software Defined Networking environment where control plane is separated from data plane utilizing OpenFlow protocol and ONOS controller. For interaction between end-users and SDN Controller author defines an Application Programming Interface (API) over a secure SSL/TLS connection. The Controller is responsible for translating high-level logics in low-level rules in OpenFlow switches. This study runs experiments in OpenFlow test-bed researching a mechanism for end-user to discard packets on ISP edge routers thus minimizing their uplink saturation and staying on-line.
引用
收藏
页数:5
相关论文
共 50 条
  • [21] An analytical model for delay bound of OpenFlow based SDN using network calculus
    Koohanestani, Amir Khorsandi
    Osgouei, Amin Ghalami
    Saidi, Hossein
    Fanian, Ali
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2017, 96 : 31 - 38
  • [22] Pushing SDN to the End-Host, Network Load Balancing using OpenFlow
    Al-Najjar, Anees
    Layeghy, Siamak
    Portmann, Marius
    2016 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATION WORKSHOPS (PERCOM WORKSHOPS), 2016,
  • [23] Implementation of OpenFlow based cognitive radio network architecture: SDN&R
    Namal, Suneth
    Ahmad, Ijaz
    Saud, Saad
    Jokinen, Markku
    Gurtov, Andrei
    WIRELESS NETWORKS, 2016, 22 (02) : 663 - 677
  • [24] Cost-effective N:1 Firewall Array via subnet-level load balancing by SDN/OpenFlow switches
    Quispe, Christian I.
    Santivanez, Cesar A.
    2018 IEEE ANDESCON, 2018,
  • [25] SDN/OpenFlow测试技术探讨
    顾彬
    电信网技术, 2013, (03) : 69 - 75
  • [26] SDN and OpenFlow Evolution: A Standards Perspective
    Tourrilhes, Jean
    Sharma, Puneet
    Banerjee, Sujata
    Pettit, Justin
    COMPUTER, 2014, 47 (11) : 22 - 29
  • [27] Firewall application for Floodlight SDN controller
    Morzhov, Sergey
    Alekseev, Igor
    Nikitinskiy, Mikhail
    2016 INTERNATIONAL SIBERIAN CONFERENCE ON CONTROL AND COMMUNICATIONS (SIBCON), 2016,
  • [28] SDN Interactive Manager: An OpenFlow-Based SDN Manager
    Isolani, Pedro Heleno
    Wickboldt, Juliano Araujo
    Both, Cristiano Bonato
    Rochol, Juergen
    Granville, Lisandro Zambenedetti
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 1157 - 1158
  • [29] Firewall and Load balancing as an application of SDN
    Zope, Nayana
    Pawar, Sanjay
    Saquib, Zia
    2016 CONFERENCE ON ADVANCES IN SIGNAL PROCESSING (CASP), 2016, : 354 - 359
  • [30] A Verification Method of SDN Firewall Applications
    Kang, Miyoung
    Choi, Jin-Young
    Kang, Inhye
    Kwak, Hee Hwan
    Ahn, So Jin
    Shin, Myung-Ki
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2016, E99B (07) : 1408 - 1415