Flowtracker: A SDN Stateful Firewall Solution with Adaptive Connection Tracking and Minimized Controller Processing

Thuy Vinh Tran, Heejune Ahn

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

13 Scopus citations

Abstract

The introduction of Software Defined Networking (SDN) enables possibilities for the next generation of network where the network logic operation is separated from the constraints of underlying hardware. However, the new architecture of SDN also exposes many security risks such as controller DoS attack, configuration channel compromise. This paper analyzes the challenges of stateful firewall realization in SDN environment and presents FlowTracker - a novel stateful firewall solution focusing on maintaining the accuracy and agility of stateful firewall with reduced controller processing and communication overhead between control and data plane. The GENI test bed experiments validates FlowTracker its stateful packet tracking and acceptable level of latency increase.

Original languageEnglish
Title of host publication2016 1st International Conference on Software Networking, ICSN 2016
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781509016761
DOIs
StatePublished - 29 Jun 2016
Event1st International Conference on Software Networking, ICSN 2016 - Jeju Island, Korea, Republic of
Duration: 23 May 201626 May 2016

Publication series

Name2016 1st International Conference on Software Networking, ICSN 2016

Conference

Conference1st International Conference on Software Networking, ICSN 2016
Country/TerritoryKorea, Republic of
CityJeju Island
Period23/05/1626/05/16

Keywords

  • connection tracking
  • Firewall
  • GENI testbed
  • Overflow
  • POX controller
  • SDN
  • Stateful firewall

Fingerprint

Dive into the research topics of 'Flowtracker: A SDN Stateful Firewall Solution with Adaptive Connection Tracking and Minimized Controller Processing'. Together they form a unique fingerprint.

Cite this