Development and research of the PreFirewall network application for floodlight SDN controller

Sergey V. Morzhov, Mikhail A. Nikitinskiy · 2018 Moscow Workshop on Electronic and Networking Technologies (MWENT) · 2018

A firewall is a network security device that monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules. This set of predefined rules is often called security policy. Managing firewall rules, especially for large enterprise networks, is complicated and error-prone task. In addition, inserting or modifying a filtering rule requires careful analysis of the relationship between the inserting rule and other rules in order to determine the proper order of them. In this article, the authors analyze a network application developed for software defined network (SDN) controller. The application was designed to resolve various anomalies in the firewall rules set. This paper also contains a description of the experiments performed with the created network application using the Floodlight SDN OpenFlow controller. We also compared the developed network application with the external Floodlight firewall module. Some metrics data of this comparison are also given.

Read the paper · More papers on PaperTik