An Approach for Software-Defined Networks Security

Saba Bashir Ahmed, Yasir Abdelgadir Mohamed · 2023

With Software-Defined Networking (SDN), two planes are created: one for control and the other for the data. This offers central control of the network. Control and data planes are merged onto a single device, unlike conventional networks. As the number of infiltration attempts soars, so does the efficacy of the security mechanisms in OpenFlow networks. The OpenFlow protocol, unlike more typical network protocols, ignores certain security concerns, making it difficult to strike a balance between security and speed. Using OpenFlow's firewall module, this research aims to develop a solution that improves SDN security and speed. To be able to detect traffic and enforce defined rules, the firewall application was developed on the SDN control layer as well as layers two, three, and four of the TCP/IP architecture. Using the open virtual switch and the floodlight SDN controller, we conducted tests. Before installing the firewall, the network connection was tested in two different ways. This time the firewall was turned on. The findings demonstrate that the SDN firewall established has a little impact on the SDN's operational efficiency. Round trip time (RTT) is almost identical, with a slightly longer delay time of 0.09 ms compared to the SDN without a firewall (0.068 to 0.069 ms), a little higher maximum throughput of 4.34 gbps compared to the SDN without a firewall (4.07 gbps), and no data loss in both circumstances. In other words, security is enhanced by packet processing, while speed is not adversely affected by matching rules. This research recommends the use of L3 learning switches to perform routing functions in distributed firewalls, in order to lessen the burden on the controller. On another controller, such as ONOS, opendaylight, or NOX/POX, the results may be compared and analyzed

Read the paper · More papers on PaperTik