期刊文献+

基于OpenFlow的软件定义网络防火墙设计 被引量:1

Design of the Firewall for Software Defined Network Based on OpenFlow
下载PDF
导出
摘要 本文介绍了传统网络防火墙在软件定义网络(SDN)中存在的问题,设计了一种基于OpenFlow的SDN防火墙。这种防火墙通过SDN控制器启动,用户可以综合考虑网络协议类型、操作类型及优先级等因素,制定防火墙规则,由SDN控制器转换成不同的流表项,下发给对应交换机,从而实现可定制的智能防火墙功能。此外,针对单级流表和多级流表的不同场景,分别设计了对应的防火墙规则下发流程,并详细描述了防火墙应用的具体实施方式。本设计适用于所有种类SDN交换机的防火墙,通用性强。 The problems of traditional network firewalls in software defined network(SDN)are introduced in this paper.A firewall for SDN is proposed based on OpenFlow who is started by the controller of SDN.Users can decide rules of firewall according to the network protocol,operation type,priority and other factors.These rules will be translated to flow tables by the controller who sends flow tables to the switch.It can be achieved intelligent and customized firewall by this method.In view of the difference between the single level flow table and the multilevel flow table,the processes of firewall rules are designed respectively.And the implementations of this firewall are described thoroughly.This design has good versatility and can be applied to the firewalls for all types of SDN switches.
作者 雷明涛 柯昌骏 朱昊 李晓禹 Lei Mingtao;Ke Changjun;Zhu Hao;Li Xiaoyu(The 28th Research Institute of China Electronics Technology Group Corporation, Nanjing 210007, China)
出处 《信息化研究》 2018年第2期29-34,共6页 INFORMATIZATION RESEARCH
关键词 OpenFlow交换机 软件定义网络 防火墙 控制器 流表 OpenFlow switch software defined network firewall controller flow table
  • 相关文献

参考文献10

二级参考文献36

  • 1杜晓丽,蒋昌俊,徐国荣,丁志军.一种基于模糊聚类的网格DAG任务图调度算法[J].软件学报,2006,17(11):2277-2288. 被引量:48
  • 2张昭理,洪帆,肖海军.一种防火墙规则冲突检测算法[J].计算机工程与应用,2007,43(15):111-113. 被引量:9
  • 3Rosen E,Rekhter Y.RFC2547 BGP/MPLS VPNs[S].March 1999
  • 4Ivan Pepelnjak,Jim Guichard.MPLS and VPN architectures[M].北京:人民邮电出版社,2001
  • 5港湾网络有限公司.BigHammer6800系列智能多层交换机软件配置手册[M].2005
  • 6Rosen E,Vishwanathan A,Callon R.RFC3031 Multiprotocol Label Switching Architecture[S].January 2001
  • 7McKeown N.Software-defined networking[J].INFOCOM Keynote Talk,2009,17(2):30-32.
  • 8McKeown N,Anderson T,Balakrishnan H,et al.OpenFlow:enabling innovation in campus networks[J].ACM SIGCOMM Computer Communication Review,2008,38(2):69-74.
  • 9Zhang S,Malik S,McGeer R.Verification of computer switching networks:an overview[M]//Automated Technology for Verification and Analysis.Berlin:Springer,2012:1-16.
  • 10Canini M,Venzano D,Peresíni P,et al.A NICE way to test OpenFlow applications[C]// Proc of the 9th USENIX Conference on Networked Systems Design and Implementation.Berkeley:USENIX Association,2012:10.

共引文献63

同被引文献2

引证文献1

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部