FORTRESS: An Efficient and Distributed Firewall for Stateful Data Plane SDN

被引:19
|
作者
Caprolu, Maurantonio [1 ]
Raponi, Simone [1 ]
Di Pietro, Roberto [1 ]
机构
[1] HBKU, Div Informat & Comp Technol ICT, CSE, Doha, Qatar
关键词
SECURITY; NETWORK;
D O I
10.1155/2019/6874592
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Software Defined Networking (SDN) paradigm decouples the logic module from the forwarding module on traditional network devices, bringing a wave of innovation to computer networks. Firewalls, as well as other security appliances, can largely benefit from this novel paradigm. Firewalls can be easily implemented by using the default OpenFlow rules, but the logic must reside in the control plane due to the dynamic nature of their rules that cannot be handled by data plane devices. This leads to a nonnegligible overhead in the communication channel between layers, as well as introducing an additional computational load on the control plane. To address the above limitations, we propose the architectural design of FORTRESS: a stateful firewall for SDN networks that leverages the stateful data plane architecture to move the logic of the firewall from the control plane to the data plane. FORTRESS can be implemented according to two different architectural designs: Stand-Alone and Cooperative, each one with its own peculiar advantages. We compare FORTRESS against FlowTracker, the state-of-the-art solution for SDN firewalling, and show how our solution outperforms the competitor in terms of the number of packets exchanged between the control plane and the data plane-we require 0 packets for the Stand-Alone architecture and just 4 for the Cooperative one. Moreover, we discuss how the adaptability, elegant and modular design, and portability of FORTRESS contribute to make it the ideal candidate for SDN firewalling. Finally, we also provide further research directions.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] Supporting Virtualized Network Functions with Stateful Data Plane Abstraction
    Bi, Jun
    Zhu, Shuyong
    Sun, Chen
    Yao, Guang
    Hu, Hongxin
    IEEE NETWORK, 2016, 30 (03): : 40 - 45
  • [32] Distributed and Efficient Network Hypervisor for SDN Virtualization
    Liao, Ling Xia
    Wang, Jian
    Chao, Han-Chieh
    Qin, Bin
    JOURNAL OF INTERNET TECHNOLOGY, 2021, 22 (03): : 625 - 636
  • [33] An Efficient Hierarchical Distributed SDN Controller Model
    Amiri, Esmaeil
    Alizadeh, Emad
    Raeisi, Khalilollah
    2019 IEEE 5TH CONFERENCE ON KNOWLEDGE BASED ENGINEERING AND INNOVATION (KBEI 2019), 2019, : 553 - 557
  • [34] Data Analysis of Network Parameters for Secure Implementations of SDN-Based Firewall
    Iqbal, Rizwan
    Hussain, Rashid
    Arif, Sheeraz
    Ansari, Nadia Mustaqim
    Shaikh, Tayyab Ahmed
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 77 (02): : 1575 - 1598
  • [35] Enabling Stateful Functions for Stream Processing in the Programmable Data Plane
    Ossen, Sabra
    Brasilino, Lucas R. B.
    Dalessandro, Luke
    Swany, Martin
    PROCEEDINGS OF THE 2ND WORKSHOP ON HIGH PERFORMANCE SERVERLESS COMPUTING, HIPS 2022, 2022, : 24 - 30
  • [36] Enhancing security of SDN focusing on control plane and data plane
    Celesova, Barbora
    Val'ko, Jozef
    Grezo, Rudolf
    Helebrandt, Pavol
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
  • [37] SDNsec: Forwarding Accountability for the SDN Data Plane
    Sasaki, Takayuki
    Pappas, Christos
    Lee, Taeho
    Hoefler, Torsten
    Perrig, Adrian
    2016 25TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN), 2016,
  • [38] Fault Tolerant Data Plane Using SDN
    Yamansavascilar, Baris
    Baktir, Ahmet Cihat
    Ozgovde, Atay
    Ersoy, Cem
    2017 25TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2017,
  • [39] Deep and Automated SDN Data Plane Analysis
    Saied, Wejdene
    Ben Souayeh, Nihel Ben Youssef
    Saadaoui, Amina
    Bouhoula, Adel
    2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 24 - 29
  • [40] The (Surprising) Computational Power of the SDN Data Plane
    Newport, Calvin
    Zhou, Wenchao
    2015 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (INFOCOM), 2015,