An Anomaly Free Distributed Firewall System for SDN

Mitali Sinha, Padmalochan Bera, Manoranjan Satpathy · 2021

Firewall is a core element of a network security system which takes care of the availability, privacy, and integrity of network resources. However, managing a system with large scale, heterogeneous policies is complex and error prone. In multi-firewall systems, it is very important to configure the policy rules in the relevant firewall to prevent malicious flow into the network. Any modification to a firewall rule or insertion of a new rule needs intra and inter firewall conflict resolution to find correct mapping of rule to firewall. In SDN, the controller generates flow rules for different switches depending on application requirements and network topologies. Firewall can be used as a first line of defense against different attacks to the data plane and the control plane of SDN. The state-of-art work on firewall implementation in SDN shows various anomalies that may introduce functional failures and security violations. In this paper, we have proposed a novel approach for distributed anomaly-free firewall implementation on SDN controller. Here, the controller receives the firewall policies of different domains through north bound API and resolves the intra and inter firewall conflicts and derives a single anomaly-free firewall policy at the controller level. When the controller receives a packet_in message from a switch at run time, it selects a conflict free rule from global policy and sends it to appropriate switches. We have evaluated our proposed distributed firewall system for different network topologies under different attacking scenarios, e.g., DDoS attacks and experimental results are reported. The results show the efficacy of our solution in terms of reduced malicious traffic flows, improvements in CPU utilization of controller, packet loss and response time of legitimate packets.

Read the paper · More papers on PaperTik