首页> 外文会议>IEEE Conference on Local Computer Networks >FireFlow - High Performance Hybrid SDN-Firewalls with OpenFlow
【24h】

FireFlow - High Performance Hybrid SDN-Firewalls with OpenFlow

机译:FireFlow-具有OpenFlow的高性能混合SDN-防火墙

获取原文

摘要

Today, the most widely distributed type of firewalls are software firewalls, running as applications on standard systems. Dedicated networking hardware like SDN switches has also been used to implement firewall functionality, although their native classification capabilities are restricted to relatively simple checks, such as subnet tests. However, native SDN hardware can satisfy high performance requirements that would be challenging for standard software firewalls. This motivates to build a hybrid combination of fast SDN hardware with a standard software firewall. Our approach directly offloads simple rule policies instead of flows to the SDN switch, in order to exploit the limited storage capacity more efficiently. An effective packet diversion algorithm based on header space analysis avoids expensive communication with the back-end. This way, it can achieve the throughput of a native SDN switch while still being able to resort decisions to the full extent of a software firewall. Our evaluation demonstrates a 23-fold classification performance increase over a standard software firewall.
机译:如今,分布最广泛的防火墙类型是软件防火墙,它们在标准系统上作为应用程序运行。尽管专用网络硬件(如SDN交换机)的本机分类功能仅限于相对简单的检查(如子网测试),但也已用于实现防火墙功能。但是,本地SDN硬件可以满足高性能要求,这对于标准软件防火墙而言将是一个挑战。这促使建立快速SDN硬件与标准软件防火墙的混合组合。我们的方法直接将简单的规则策略卸载,而不是流到SDN交换机,以便更有效地利用有限的存储容量。基于报头空间分析的有效数据包转移算法避免了与后端的昂贵通信。这样,它可以实现本机SDN交换机的吞吐量,同时仍然可以在软件防火墙的全部范围内采用决策。我们的评估表明,与标准软件防火墙相比,分类性能提高了23倍。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号