The search functionality is under construction.
The search functionality is under construction.

A Verification Method of SDN Firewall Applications

Miyoung KANG, Jin-Young CHOI, Inhye KANG, Hee Hwan KWAK, So Jin AHN, Myung-Ki SHIN

  • Full Text Views

    0

  • Cite this

Summary :

SDN (Software-Defined Networking) enables software applications to program individual network devices dynamically and therefore control the behavior of the network as a whole. Incomplete programming and/or inconsistency with the network policy of SDN software applications may lead to verification issues. The objective of this paper is to describe the formal modeling that uses the process algebra called pACSR and then suggest a method to verify the firewall application running on top of the SDN controller. The firewall rules are translated into a pACSR process which acts as the specification, and packet's behaviors in SDN are also translated to a pACSR process which is a role as the implementation. Then we prove the correctness by checking whether the parallel composition of two pACSR processes is deadlock-free. Moreover, in the case of network topology changes, our verification can be directly applied to check whether any mismatches or inconsistencies will occur.

Publication
IEICE TRANSACTIONS on Communications Vol.E99-B No.7 pp.1408-1415
Publication Date
2016/07/01
Publicized
Online ISSN
1745-1345
DOI
10.1587/transcom.2015EBP3329
Type of Manuscript
PAPER
Category
Fundamental Theories for Communications

Authors

Miyoung KANG
  Korea University
Jin-Young CHOI
  Korea University
Inhye KANG
  the University of Seoul
Hee Hwan KWAK
  SOLiD
So Jin AHN
  Korea University
Myung-Ki SHIN
  ETRI

Keyword