Comparison of SDN Controllers for Constructing Security Functions
Dobrin Dobrev, D.R. Avresky · 2019
The comparison analyses in this paper is based on Virtual Security Functions, Openflow, Software Define Networks (SDN), Mininet, Pox Controller, Floodlight Controller and Virtual Switches. By using Openflow protocol in the virtualized environment of SDN, we are capable of analyzing the data streams in the network environment. By creating different Virtual Security Functions (VSF), we have the possibility to increase network security, avoid loops and eliminating broadcast storms. In this paper, the process of loop elimination is achieved by automatically reconfiguring the security function by creating spanning tree. The benefit is that different devices like switches, firewalls, will be replaced by the SDN controller and the entire platform is virtualized. The target is to increase availability (based on the classical model of security) by presenting functions that avoid loops and Storm attacks in the network. In addition, VSF will allow to eliminate different attacks, such as: Congestion driven attacks; Distributed Denial-of-Service (DDoS); Layer 2 attacks. All those functions can be run in parallel and we can increase the availability.