About

Log in?

DTU users get better search results including licensed content and discounts on order fees.

Anyone can log in and get personalized features such as favorites, tags and feeds.

Log in as DTU user Log in as non-DTU user No thanks

DTU Findit

Conference paper

P4Knocking: Offloading host-based firewall functionalities to the network

From

Department of Photonics Engineering, Technical University of Denmark1

Networks Technology and Service Platforms, Department of Photonics Engineering, Technical University of Denmark2

University of the Basque Country3

The introduction of Software-Defined Networks (SDN) and the evolution towards programmable data planes bring the opportunity to offload several functions to the data plane. In this context, the P4 programming language opens the door to the customization of data planes. It can provide packet processing functionalities that can be applied to improve network security among other areas.

This paper presents P4Knocking, a P4-based port knocking implementation that can externally open ports that appear to be closed. The goal of bringing port knocking capabilities to the network is to seamlessly deploy firewall functions in the data plane, reliving hosts from dealing with unintended traffic.

Our work presents a total of four implementations that involve data and control planes in different degrees. In this case, P4Knocking can provide a more transparent and efficient way to deploy the port knocking service compared to a host-based port knocking implementation. In fact, it requires no specific purpose externs apart from registers, hence its higher portability and flexibility with local or remote control planes.

Language: English
Publisher: IEEE
Year: 2020
Pages: 7-12
Proceedings: 23rd Conference on Innovation in Clouds, Internet and Networks and Workshops
ISBN: 1728151279 , 1728151287 , 9781728151274 and 9781728151281
ISSN: 24728144
Types: Conference paper
DOI: 10.1109/icin48450.2020.9059298
ORCIDs: Ollora Zaballa, Eder and Berger, Michael Stübert

DTU users get better search results including licensed content and discounts on order fees.

Log in as DTU user

Access

Analysis