A novel method against the firewall bypass threat in OpenFlow networks

Yicong Zhang, Jie Li, Lin Chen, Yusheng Ji, Feilong Tang

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

Software-Defined Networking (SDN) is an innovational network architecture introduced a couple of years ago. It gives network administrators the ability to directly control the whole network by programming on a centralized controller, without manually configure each device. However, new security challenges come out with SDN development. One significant challenge is to design a secure firewall specifically designed for SDN, since the traditional firewall could be easily bypassed in SDN. To detect and prevent this bypass threat, we propose a novel detection method by modeling the network to a directed graph with two significant features. Then, we implement our method and conduct experiments. The result of experiments show that our method can actively and accurately detect bypass threats for OpenFlow networks.

Original languageEnglish
Title of host publication2017 9th International Conference on Wireless Communications and Signal Processing, WCSP 2017 - Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1-6
Number of pages6
ISBN (Electronic)9781538620625
DOIs
StatePublished - 7 Dec 2017
Externally publishedYes
Event9th International Conference on Wireless Communications and Signal Processing, WCSP 2017 - Nanjing, China
Duration: 11 Oct 201713 Oct 2017

Publication series

Name2017 9th International Conference on Wireless Communications and Signal Processing, WCSP 2017 - Proceedings
Volume2017-January

Conference

Conference9th International Conference on Wireless Communications and Signal Processing, WCSP 2017
Country/TerritoryChina
CityNanjing
Period11/10/1713/10/17

Fingerprint

Dive into the research topics of 'A novel method against the firewall bypass threat in OpenFlow networks'. Together they form a unique fingerprint.

Cite this