A Novel Method Against the Firewall Bypass Threat in OpenFlow Networks.

Yicong Zhang,Jie Li,Lin Chen,Yusheng Ji,Feilong Tang
DOI: https://doi.org/10.1109/wcsp.2017.8171014
2017-01-01
Abstract:Software-Defined Networking (SDN) is an innovational network architecture introduced a couple of years ago. It gives network administrators the ability to directly control the whole network by programming on a centralized controller, without manually configure each device. However, new security challenges come out with SDN development. One significant challenge is to design a secure firewall specifically designed for SDN, since the traditional firewall could be easily bypassed in SDN. To detect and prevent this bypass threat, we propose a novel detection method by modeling the network to a directed graph with two significant features. Then, we implement our method and conduct experiments. The result of experiments show that our method can actively and accurately detect bypass threats for OpenFlow networks.
What problem does this paper attempt to address?