节点文献

基于SDN的数据库型防火墙研究与实现

Building Database-based Firewall Over the Software-Defined Network

【作者】 刘颖

【导师】 刘长军; 丁国忠;

【作者基本信息】 华东理工大学 , 安全工程, 2015, 硕士

【摘要】 随着计算机技术和网络技术的发展,互联网已经成为人们生活中不可或缺的一部分,与此同时也给人们带来了新的威胁:网络安全。防火墙是最常用的防病毒和网络攻击的措施。目前,大多数的转发规则都是由路由器和交换机等硬件设施根据包头的结构来完成,然而对于不同的设备可能会有不同的转发规则。传统的防火墙具有维护成本高且不灵活的特点,一旦网络设备被推向市场,就很难对其进行替换或修改。本文通过对国内外防火墙技术的学习研究,提出了一种基于SDN(软件定义网络)架构的数据库型防火墙的设计。该防火墙设计可以通过软件编程的方式自定义任何想实现的网络路由和传输规则策略,对防火墙进行集中式管理,从而更加灵活和智能。同时,借助数据库的优点,使得该防火墙的设计应用更加可靠和高效。为了验证该防火墙设计的有效性,使用Mininet在虚拟机中创建网络拓扑,模拟现实网络环境,使用搭建的策略管理系统对策略进行添加和删除。通过iperf命令、ping命令以及ssh命令对功能的可靠性进行验证,最后使用wireshark抓包软件对拓扑内各虚拟主机间的流量数据包抓包并进行直观分析。

【Abstract】 With the development of computer and network technology, internet has been become an integral part in people’s lives. Likewise, it brings people a new threat:network security.Firewall is the most common measure to prevent virus and network attack. At present, most of the forwarding rules are executed by routers and switches or other hardware devices base on the structure of packet headers. But different devices may have different forwarding rules. Traditional firewalls have the defects of high cost and inconvenience for maintenance. The network devices, once they have been brought to the market, can hardly be replaced or modified.By studies over both foreign and domestic firewall technology, this article put forward a new firewall design base on SDN (software-defined network) and database technology. The new firewall design is allowed to define your desired network routing and forwarding rules through programming. It centralized management of firewalls and become much more flexible and intelligent. Meanwhile, it makes the new firewall design more reliable and efficient by leveraging the database merits.In order to verify effectiveness of the firewall design, the Mininet was applied to build network topology in the Virtual Machine to simulate a real network environment. It added or deleted rules through the simulant rule management system, verified reliability through iperf, ping and ssh command, then captured and analyzed data flow between virtual hosts through wireshark.

  • 【分类号】TP311.13;TP393.08
  • 【被引频次】5
  • 【下载频次】262
节点文献中: