Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

SIPAV-SDN: Source Internet Protocol Address Validation for Software Defined Network

View through CrossRef
SDN technology is becoming every day more popular and big data centers and organizational networks have started deploying for its advantages. Current development of SDN network relies on target host IP address of packet and OFSwitches ignores checking of source host IP. SDN has separated control planes and data planes and OpenFlow protocol enabled switches are used as packet forwarding devices. The SDN controller controls flow of data packet through forwarding devices and when these are turned on, do not have any control and defense. The devices are not able to handle packet arriving from connected host. In this case, data packets of hosts are sent to the controller forwarding device for inspection and control packet creation for data packet and setting up required matching entries in flow table of forwarding device for such type of data packets generated by the hosts. The attackers can generate packets with Spoofed source IP address and perform various types of attacks. In this research paper, we offer a scheme as Source IP Address Validation for Software Defined Network (SIPAV-SDN) to check packet’s source host IP address by binding source host IP Address and MAC address with switch port. It maintains a HostTable at Controller for verification of source host IP and MAC with switch port and only forwards the packets which have valid sources host IP address. We also simulated SIPAV-SDN with hybrid SDN network and experiment results have shown that it achieved 100% packet filtering accuracy for IP spoofed TCP, UDP and ICMP packet attacks. We used python programming language for RYU controller in Mininet network emulator.
Blue Eyes Intelligence Engineering and Sciences Engineering and Sciences Publication - BEIESP
Title: SIPAV-SDN: Source Internet Protocol Address Validation for Software Defined Network
Description:
SDN technology is becoming every day more popular and big data centers and organizational networks have started deploying for its advantages.
Current development of SDN network relies on target host IP address of packet and OFSwitches ignores checking of source host IP.
SDN has separated control planes and data planes and OpenFlow protocol enabled switches are used as packet forwarding devices.
The SDN controller controls flow of data packet through forwarding devices and when these are turned on, do not have any control and defense.
The devices are not able to handle packet arriving from connected host.
In this case, data packets of hosts are sent to the controller forwarding device for inspection and control packet creation for data packet and setting up required matching entries in flow table of forwarding device for such type of data packets generated by the hosts.
The attackers can generate packets with Spoofed source IP address and perform various types of attacks.
In this research paper, we offer a scheme as Source IP Address Validation for Software Defined Network (SIPAV-SDN) to check packet’s source host IP address by binding source host IP Address and MAC address with switch port.
It maintains a HostTable at Controller for verification of source host IP and MAC with switch port and only forwards the packets which have valid sources host IP address.
We also simulated SIPAV-SDN with hybrid SDN network and experiment results have shown that it achieved 100% packet filtering accuracy for IP spoofed TCP, UDP and ICMP packet attacks.
We used python programming language for RYU controller in Mininet network emulator.

Related Results

Macroeconomic and Social Precursors of Suicide Rates in the Philippines: A Quantitative Analysis (Preprint)
Macroeconomic and Social Precursors of Suicide Rates in the Philippines: A Quantitative Analysis (Preprint)
BACKGROUND Suicide is a complex, serious and multifaceted public health issue that poses significant challenges to societies worldwide. In fact, it represen...
The Geography of Cyberspace
The Geography of Cyberspace
The Virtual and the Physical The structure of virtual space is a product of the Internet’s geography and technology. Debates around the nature of the virtual — culture, s...
Contribution to the system architecture design for electromagnetic nano-network communications
Contribution to the system architecture design for electromagnetic nano-network communications
(English) A nano-network is a communication network at the nano-scale between nano-devices. Nanodevices face certain challenges in functionalities, because of limitations in their ...
Le riviste scientifiche e la fondazione della SIPaV
Le riviste scientifiche e la fondazione della SIPaV
Nel 1892 fu fondata la «Rivista di Patologia vegetale» (RPV) dai fratelli Berlese: Augusto Napoleone, patologo vegetale nella Regia Scuola Enologica di Avellino e Antonio, entomolo...
Patent Litigation and the Internet
Patent Litigation and the Internet
Patent infringement litigation has not only increased dramatically in frequency over the past few decades, but also has also seen striking growth in both stakes and cost. Although ...
Breast Carcinoma within Fibroadenoma: A Systematic Review
Breast Carcinoma within Fibroadenoma: A Systematic Review
Abstract Introduction Fibroadenoma is the most common benign breast lesion; however, it carries a potential risk of malignant transformation. This systematic review provides an ove...
Novel architectures and strategies for security offloading
Novel architectures and strategies for security offloading
Internet has become an indispensable and powerful tool in our modern society. Its ubiquitousness, pervasiveness and applicability have fostered paradigm changes around many aspects...
Novel Approach for Ddos Attack Mitigation in Software Defined Network
Novel Approach for Ddos Attack Mitigation in Software Defined Network
Introduction: This research article intends to depict the usage of machine learning (ML) techniques in software defined network (SDN) to address the Distributed Denial of Service (...

Back to Top