{"title":"基于Open vSwitch的SDN状态防火墙在数据平面上的实现","authors":"Pakapol Krongbaramee, Yuthapong Somchit","doi":"10.1109/JCSSE.2018.8457354","DOIUrl":null,"url":null,"abstract":"A Software Defined Networking (SDN) has been deployed in the current network system. Together with Network Virtualization (NVF), it makes the network become more flexible. The firewall can be implemented in SDN. However, with the limitation of earlier version of OpenFlow protocol used in SDN, the stateful firewall could not be implemented with the SDN standard. The development of OpenFlow enables some features that can be used for implementing the stateful firewall. In this work, we implement the stateful firewall in the SDN switch on the data plane. The Open vSwitch is used. We also evaluate the performance of the SDN stateful firewall. The results show that our SDN stateful firewall can work correctly with small overhead increased in SDN switches.","PeriodicalId":338973,"journal":{"name":"2018 15th International Joint Conference on Computer Science and Software Engineering (JCSSE)","volume":"79 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"22","resultStr":"{\"title\":\"Implementation of SDN Stateful Firewall on Data Plane using Open vSwitch\",\"authors\":\"Pakapol Krongbaramee, Yuthapong Somchit\",\"doi\":\"10.1109/JCSSE.2018.8457354\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"A Software Defined Networking (SDN) has been deployed in the current network system. Together with Network Virtualization (NVF), it makes the network become more flexible. The firewall can be implemented in SDN. However, with the limitation of earlier version of OpenFlow protocol used in SDN, the stateful firewall could not be implemented with the SDN standard. The development of OpenFlow enables some features that can be used for implementing the stateful firewall. In this work, we implement the stateful firewall in the SDN switch on the data plane. The Open vSwitch is used. We also evaluate the performance of the SDN stateful firewall. The results show that our SDN stateful firewall can work correctly with small overhead increased in SDN switches.\",\"PeriodicalId\":338973,\"journal\":{\"name\":\"2018 15th International Joint Conference on Computer Science and Software Engineering (JCSSE)\",\"volume\":\"79 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"22\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 15th International Joint Conference on Computer Science and Software Engineering (JCSSE)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/JCSSE.2018.8457354\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 15th International Joint Conference on Computer Science and Software Engineering (JCSSE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/JCSSE.2018.8457354","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 22
摘要
当前网络系统中已经部署了SDN (Software Defined Networking)。它与网络虚拟化(NVF)一起使网络变得更加灵活。防火墙可以在SDN网络中实现。但是,由于SDN中使用的OpenFlow协议的早期版本的限制,无法使用SDN标准实现状态防火墙。OpenFlow的开发提供了一些可用于实现有状态防火墙的特性。在这项工作中,我们在数据平面的SDN交换机上实现了有状态防火墙。使用Open vSwitch。我们还评估了SDN状态防火墙的性能。结果表明,我们设计的SDN状态防火墙可以在SDN交换机增加少量开销的情况下正常工作。
Implementation of SDN Stateful Firewall on Data Plane using Open vSwitch
A Software Defined Networking (SDN) has been deployed in the current network system. Together with Network Virtualization (NVF), it makes the network become more flexible. The firewall can be implemented in SDN. However, with the limitation of earlier version of OpenFlow protocol used in SDN, the stateful firewall could not be implemented with the SDN standard. The development of OpenFlow enables some features that can be used for implementing the stateful firewall. In this work, we implement the stateful firewall in the SDN switch on the data plane. The Open vSwitch is used. We also evaluate the performance of the SDN stateful firewall. The results show that our SDN stateful firewall can work correctly with small overhead increased in SDN switches.