P4Filter: A two level defensive mechanism against attacks in SDN using P4
Ananya Saxena, Ritvik Muttreja, Shivam Upadhyay, K. Shiv Kumar,, Venkanna U

TL;DR
This paper introduces P4Filter, a two-level security mechanism in SDN using P4, combining a dynamic firewall and port knocking to enhance network security against unauthorized access and attacks.
Contribution
The work presents a novel two-level defense mechanism in SDN using P4, integrating dynamic firewall logic and port knocking for improved security.
Findings
Outperforms previous P4-based firewall approaches.
Successfully mitigates specific security attacks.
Effective in blocking unauthorized network access.
Abstract
The advancements in networking technologies have led to a new paradigm of controlling networks, with data plane programmability as a basis. This facility opens up many advantages, such as flexibility in packet processing and better network management, which leads to better security in the network. However, the current literature lacks network security solutions concerning authentication and preventing unauthorized access. In this work, our goal is to avoid attacks in a two level defense mechanism (P4Filter). The first level is a dynamic firewall logic, which blocks packets generated from an unauthorized source. The second level is an authentication mechanism based on dynamic port knocking. The two security levels were tested in a virtual environment with P4 based switches. The packets arriving at the switch from unknown hosts are sent to the controller. The controller maintains an ACL…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Network Packet Processing and Optimization · Software-Defined Networks and 5G
