Skip to main navigation Skip to search Skip to main content

Towards a security-enhanced firewall application for openflow networks

  • Juan Wang
  • , Yong Wang
  • , Hongxin Hu
  • , Qingxin Sun
  • , He Shi
  • , Longjie Zeng
  • Wuhan University
  • Ministry of Education of the People's Republic of China

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

30 Scopus citations

Abstract

Software-Defined Networking (SDN), which offers programmers network-wide visibility and direct control over the underlying switches from a logically-centralized controller, not only has a huge impact on the development of current networks, but also provides a promising way for the future development of Internet. SDN, however, also brings forth many new security challenges. One of such critical challenges is how to build a robust firewall application for SDN. Due to the stateless of SDN firewall based on OpenFlow, the first standard for SDN, and the lack of audit and tracking mechanisms for SDN controllers, the existing firewall applications in SDN can be easily bypassed by rewriting the flow entries in switches. Aiming at this threat, we introduce a systematic solution for conflict detection and resolution in OpenFlow-based firewalls through checking flow space and firewall authorization space. Unlike FortNOX [1], our approach can check the conflicts between the firewall rules and flow policies based on the entire flow paths within an OpenFlow network. We also add intra-table dependency checking for flow tables and firewall rules. Finally, we discuss a proof-of-concept implementation of our approach, and our experimental results demonstrate our approach can effectively hinder the bypass threat in real OpenFlow networks.

Original languageEnglish
Title of host publicationCyberspace Safety and Security - 5th International Symposium, CSS 2013, Proceedings
Pages92-103
Number of pages12
DOIs
StatePublished - 2013
Event5th International Symposium on Cyberspace Safety and Security, CSS 2013 - Zhangjiajie, China
Duration: Nov 13 2013Nov 15 2013

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8300 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference5th International Symposium on Cyberspace Safety and Security, CSS 2013
Country/TerritoryChina
CityZhangjiajie
Period11/13/1311/15/13

Keywords

  • Firewall
  • Openflow
  • SDN
  • Security

Fingerprint

Dive into the research topics of 'Towards a security-enhanced firewall application for openflow networks'. Together they form a unique fingerprint.

Cite this