作者: Wonkyu Han , Hongxin Hu , Ziming Zhao , Adam Doupé , Gail-Joon Ahn
关键词: OpenFlow 、 Networking hardware 、 Access network 、 Network Access Control 、 Computer network 、 Forwarding plane 、 Stateful firewall 、 Computer science 、 Network management station 、 Distributed computing 、 Software-defined networking
摘要: OpenFlow, as the prevailing technique for Software-Defined Networks (SDNs), introduces significant programmability, granularity, and flexibility many network applications to effectively manage process flows. However, because OpenFlow attempts keep SDN data plane simple efficient, it focuses solely on L2/L3 transport consequently lacks fundamental ability of stateful forwarding plane. Also, provides a very limited access connection-level information in controller. In particular, any management SDNs that require comprehensive state information, these inherent limitations pose challenges supporting services. To address challenges, we propose an innovative connection tracking framework called STATEMON global state-awareness provide better control SDNs. is based lightweight extension programming plane, while keeping underlying devices possible. demonstrate practicality feasibility STATEMON, implement evaluate firewall port knocking SDNs, using APIs provided by STATEMON. Our evaluations show minimal message exchanges monitoring active connections with manageable overhead (3.27% throughput degradation).