ip sOurCe address ValidatiOn sOlutiOn with Open FlOw extensiOn and OpenrOuter

Maciej Korczyński,Yevheniya Nosyk
2010-01-01
Abstract:Evaluation 66 Conclusion and Future Work 69 Acknowledgments 70 References 70Software-defined networking (SDN) has become a promising trend for future Internet development. Current researches mainly focus on flow management, security, and quality of service (QoS) using OpenFlow [1] switch in data center network or campus network. However, the number of OpenFlow application cases to resolve a real problem in a production network is still limited. In the production network, where routers are dominant, some of the challenges in the implementation and deployment of SDN are the integration of existing protocols inside a network device with new protocols, the tradeoff between hardware cost, and deployment profit of network evolution to SDN. In this chapter, by analyzing the challenges of the current OpenFlow in the production network, we propose three extensions of OpenFlow on FlowTable, control mode, and OpenFlow protocol. Based on these extensions, a commercial OpenFlow-enabled router, named OpenRouter, is designed and implemented using only available and existing hardware in a commercial router. OpenRouter brings the abilities of control openness; integration of inside/outside protocols; and flexibility of OpenFlow message structure, low-cost implementation, and deployment. We expect that OpenRouter may accelerate the large-scale application and deployment of OpenFlow in the production network. Currently, the Internet suffers source address spoofing–based attacks based on the observation from the The cooperative association for internet data analysis (CAIDA) data set [2]. Filtering traffic with forged source …
What problem does this paper attempt to address?