Network-wide Virtual Firewall using SDN/OpenFlow

被引:0
|
作者
Bakker, Jarrod N. [1 ]
Welch, Ian [1 ]
Seah, Winston K. G. [1 ]
机构
[1] Victoria Univ Wellington, Sch Engn & Comp Sci, Wellington, New Zealand
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional firewalls are used to enforce network security policies at boundaries within a network. However, this can leave hosts vulnerable to attacks that originate from within the network they are part of. We leverage the flexibility of Software Defined Networking to turn the network infrastructure into a virtual firewall thus improving security across an entire network. We present ACLSwitch, a network-wide virtual firewall that utilises the OpenFlow protocol to filter traffic across a network comprised of OpenFlow switches. We also define "policy domains" that allow different filtering configurations to be applied to different switches of the network. The solution allows rules to be distributed across a network without the need for a human operator to send the rules to switches separately, yet it is flexible enough to allow subsets of the switches to enforce different security policies.
引用
收藏
页码:62 / 68
页数:7
相关论文
共 50 条
  • [31] Network-Wide Optimization of Traffic Signals Using Mixed Integer Programming
    Kamal, Md. Abdus Samad
    Imura, Jun-ichi
    Hayakawa, Tomohisa
    Ohata, Akira
    Aihara, Kazuyuki
    JOURNAL OF ROBOTICS AND MECHATRONICS, 2014, 26 (05) : 607 - 615
  • [32] Network-wide optimal scheduling of transit systems using genetic algorithms
    Chakroborty, Partha
    Deb, Kalyanmoy
    Srinivas, B.
    Computer-Aided Civil and Infrastructure Engineering, 1998, 13 (05): : 363 - 376
  • [33] Development of a network-wide harmonic control scheme using an active filter
    Kennedy, Karen
    Lightbody, Gordon
    Yacamini, Robert
    Murray, Michael
    Kennedy, John
    IEEE TRANSACTIONS ON POWER DELIVERY, 2007, 22 (03) : 1847 - 1856
  • [34] Estimating Erratic Measurement Errors in Network-Wide Traffic Flow via Virtual Balance Sensors
    Zheng, Zhenjie
    Wang, Zhengli
    Fu, Hao
    Ma, Wei
    TRANSPORTATION SCIENCE, 2025,
  • [35] URBAN NETWORK-WIDE TRAFFIC VARIABLES AND THEIR RELATIONS
    ARDEKANI, S
    HERMAN, R
    TRANSPORTATION SCIENCE, 1987, 21 (01) : 1 - 16
  • [36] Efficient Network-wide Flow Record Generation
    Sommers, Joel
    Bowden, Rhys
    Eriksson, Brian
    Barford, Paul
    Roughan, Matthew
    Duffield, Nick
    2011 PROCEEDINGS IEEE INFOCOM, 2011, : 2363 - 2371
  • [37] A test for network-wide trends in rainfall extremes
    Burauskaite-Harju, Agne
    Grimvall, Anders
    von Bromssen, Claudia
    INTERNATIONAL JOURNAL OF CLIMATOLOGY, 2012, 32 (01) : 86 - 94
  • [38] Network-Wide Power Management in Computer Networks
    Niewiadomska-Szynkiewicz, Ewa
    Sikora, Andrzej
    Arabas, Piotr
    Kamola, Mariusz
    Malinowski, Krzysztof
    Jaskola, Przemyslaw
    Marks, Michal
    2013 22ND ITC SPECIALIST SEMINAR ON ENERGY EFFICIENT AND GREEN NETWORKING (SSEEGN), 2013, : 25 - 30
  • [39] Application of Virtual Firewall in Computer Network Security
    Xia, Fei
    Hu, Jian
    2020 IEEE CONFERENCE ON TELECOMMUNICATIONS, OPTICS AND COMPUTER SCIENCE (TOCS), 2020, : 42 - 48
  • [40] Routing-Oblivious Network-Wide Measurements
    Ben-Basat, Ran
    Einziger, Gil
    Feibish, Shir Landau
    Moraney, Jalil
    Tayh, Bilal
    Raz, Danny
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2021, 29 (06) : 2386 - 2398