Stateful Distributed Firewall as a Service in SDN

Ali Zeineddine,Wassim El-Hajj

2018 4th IEEE Conference on Network Softwarization and Workshops (NetSoft)(2018)

引用 3|浏览9
暂无评分
摘要
Software-defined networking (SDN) is a newly emerging approach in computer networking which abstracts network control functionalities and enables its direct programmability at the management plane. A new framework of communication between the control-plane and the data-plane is gaining a lot of attraction recently, which combines the advantages of the proactive approach, in pre-installing the flow rules in the data-plane, and the advantages of the reactive approach, in its ability to dynamically react to network events. This hybrid approach utilizes the potential of the SDN switches to recognize and host state machines. While the trending success of SDN is set to continue, this evolving network paradigm requires a new set of tools and strategies to secure the network elements against intrusions and at the same time maintain its efficiency and reliability. In this paper, we take advantage of the hybrid approach of network controllability and management to offload the processing of stateful applications from the control-plane to the data-plane and propose our framework, SDFS, which optimizes a distributed stateful application in the data-plane to transform the SDN network into one big firewall. While maintaining modularity of the framework, SDFS offers an optimized processing burden distribution of the stateful application in the data-plane among the switches in the network with inherent fault-tolerance mechanisms that eliminate the need for immediate controller intervention even in cases of network failure or attacks.
更多
查看译文
关键词
SDN,distributed stateful applications,burden distribution,high-availability
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要