Modelirovanie i Analiz Informatsionnykh Sistem
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive
Impact factor

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Model. Anal. Inform. Sist.:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Modelirovanie i Analiz Informatsionnykh Sistem, 2018, Volume 25, Number 3, Pages 251–256
DOI: https://doi.org/10.18255/1818-1015-2018-3-251-256
(Mi mais625)
 

This article is cited in 1 scientific paper (total in 1 paper)

Software Defined Networks

A new approach for detecting and resolving anomalies in security policy of the external firewall module of the floodlight SDN controller

S. V. Morzhova, M. A. Nikitinskiyb

a P.G. Demidov Yaroslavl State University, 14 Sovetskaya str., Yaroslavl 150003, Russia
b A-Real Group, Energiya-Info Inc., 144 Soyuznaya str., Yaroslavl, 150008, Russia
Full-text PDF (549 kB) Citations (1)
References:
Abstract: In this paper, the authors analyze the developed PreFirewall network application for the Floodlight software defined network (SDN) controller. This application filters rules, which are added into the firewall module of the Floodlight SDN controller in order to prevent the occurrence of anomalies among them. The rule filtering method is based on determining whether the addition of a new rule will not cause any anomalies with already added ones. If an anomaly was detected while adding the new rule, PreFirewall application should be able to resolve it and must report the detection of the anomaly.
The developed network application PreFirewall passed a number of tests. As a result of the stress testing, it was found that the time of adding a new rule, when using PreFirewall, substantially increases with increase in the number of previously processed rules. Analysis of the network application PreFirewall showed that while adding a rule (the most frequent operation), in the worst case it is necessary to compare it with all existing rules, which are stored as a two-dimensional array. Thus, the operation of adding a new rule is the most time-consuming and has the greatest impact on the performance of the network application, which leads to an increase in response time.
A possible way to of solving this problem is to select a data structure used to store the rules, in which the operation of adding a new rule would be simple. After analyzing the structure of the policy rules for the Floodlight SDN controller, the authors noted that a tree is the most adequate data structure for its storage. It provides optimization of memory used for storing the rules and, more important, it allows to achieve the constant complexity of the operation of adding a new rule and, consequently, solving the performance problem of the network application PreFirewall.
The article is published in the authors’ wording.
Keywords: firewall, Floodlight, hash table, network controller, policy tree, PreFirewall, rules anomalies resolving, SDN, software-defined network.
Funding agency Grant number
Russian Foundation for Basic Research 16-07-01103_а
The work was supported by RFBR, the research project № 16-07-01103_а.
Received: 26.12.2017
Bibliographic databases:
Document Type: Article
UDC: 004.415.25
Language: English
Citation: S. V. Morzhov, M. A. Nikitinskiy, “A new approach for detecting and resolving anomalies in security policy of the external firewall module of the floodlight SDN controller”, Model. Anal. Inform. Sist., 25:3 (2018), 251–256
Citation in format AMSBIB
\Bibitem{MorNik18}
\by S.~V.~Morzhov, M.~A.~Nikitinskiy
\paper A new approach for detecting and resolving anomalies in security policy of the external firewall module of the floodlight SDN controller
\jour Model. Anal. Inform. Sist.
\yr 2018
\vol 25
\issue 3
\pages 251--256
\mathnet{http://mi.mathnet.ru/mais625}
\crossref{https://doi.org/10.18255/1818-1015-2018-3-251-256}
\elib{https://elibrary.ru/item.asp?id=35144407}
Linking options:
  • https://www.mathnet.ru/eng/mais625
  • https://www.mathnet.ru/eng/mais/v25/i3/p251
  • This publication is cited in the following 1 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Моделирование и анализ информационных систем
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2025