首页> 外文OA文献 >Using Software Defined Networking To Solve Missed Firewall Architecture In Legacy Networks
【2h】

Using Software Defined Networking To Solve Missed Firewall Architecture In Legacy Networks

机译:使用软件定义的网络解决遗留网络中缺少的防火墙体系结构

摘要

This study is concerned with migrating traditional networks and their inherent firewall architecture to Software Defined Networking (SDN) architecture to provide an initial attempt at preventing application downtime due to hidden firewall domain rules. In legacy organization environments the networking engineers, firewall teams, and application analysts are often silo groups, but Software Defined Networking (SDN) can blur the lines between these group silos.This thesis first outlines the interworking of SDN, traditional firewall architecture and how it interacts with SDN, an experiment of implementation, and the resulting conclusions.Testing with SDN shows we are approaching new environments where the edges of network are no longer dominated by firmware on switches and routers. The technologies behind SDN allow for the programmability of the entire network, which creates a logical flow of both network traffic and firewall policies that allow us to bypass traditional errors that may arise from physically segmented networks.The physical and logical level network programming inherent in SDN allows organizations to merge and adapt skill sets of networking engineer and application developers to reduce the risk and reliance on firewall expertise.Utilizing OpenFlow protocols and flow table concepts presented in SDN we can propagate firewall rules centrally and logically, which provides end-to-end traffic with firewall rules in our network. Using these concepts reduces the traditional firewall complexity for organizations. In this study we present a paper prototype that demonstrates that we may add in firewall rules to a centralized instance allowing our SDN controllers to provide firewall protection throughout the entire network instead of isolated risk domains or tiers. In the prototype application developers are prevented from calling incorrect ports and possibly missing hidden local firewalls not previously known. The approach described in this paper is based on a case study of several large American firms.
机译:这项研究涉及将传统网络及其固有的防火墙体系结构迁移到软件定义网络(SDN)体系结构,从而为防止由于隐藏的防火墙域规则而导致的应用程序停机提供了初步的尝试。在旧的组织环境中,网络工程师,防火墙团队和应用程序分析人员通常是孤岛小组,但是软件定义网络(SDN)可能会模糊这些孤岛之间的界线。本文首先概述了SDN,传统防火墙体系结构及其相互作用方式与SDN的交互,实现的实验以及由此得出的结论。对SDN的测试表明,我们正在接近一种新的环境,在该环境中,网络边缘不再由交换机和路由器上的固件控制。 SDN背后的技术实现了整个网络的可编程性,从而创建了网络流量和防火墙策略的逻辑流,使我们能够绕过物理分段网络可能产生的传统错误.SDN固有的物理和逻辑级别的网络编程允许组织合并和调整网络工程师和应用程序开发人员的技能集,以降低风险和对防火墙专业知识的依赖。利用SDN中提供的OpenFlow协议和流表概念,我们可以集中和逻辑地传播防火墙规则,从而提供端到端网络中防火墙规则的流量。使用这些概念可以降低组织的传统防火墙复杂性。在本研究中,我们提供了一个纸制原型,该原型证明了我们可以将防火墙规则添加到集中式实例中,从而使我们的SDN控制器能够在整个网络中提供防火墙保护,而不是孤立的风险域或层。在原型应用程序中,可以防止开发人员调用不正确的端口,并可能丢失以前未知的隐藏本地防火墙。本文描述的方法基于对几家大型美国公司的案例研究。

著录项

  • 作者

    Vogel Jared Dean;

  • 作者单位
  • 年度 2015
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号