Summary

Asia-Pacific Network Operations and Management Symposium

2014

Session Number:S2

Session:

Number:S2-20

A Scalable Flow Rule Translation Implementation For Software Defined Security

Hao Tu,  Weiming Li,  Dong Li,  Junqing Yu,  

pp.-

Publication Date:2014/09/17

Online ISSN:2188-5079

DOI:10.34385/proc.21.S2-20

PDF download (451KB)

Summary:
Software defined networking brings many possibilities to network security, one of the most important security challenge it can help with is the possibility to make network traffic pass through specific security devices, in other words, determine where to deploy these devices logically. However, most researches focus on high level policy and interaction framework but ignored how to translate them to low-level OpenFlow rules with scalability. We analyze different actions used in common security scenarios and resource constraints of physical switch. Based on them, we propose a rule translation implementation which can optimize the resource consumption according to different actions by selecting forward path dynamically.