Computer and Modernization ›› 2022, Vol. 0 ›› Issue (09): 93-98.

Previous Articles     Next Articles

POF Protocol Parser

  

  1. (1. National Network New Media Engineering Research Center, Institute of Acoustics, Chinese Academy of Sciences,
    Beijing 100190, China; 2. University of Chinese Academy of Sciences, Beijing 100049, China)
  • Online:2022-09-22 Published:2022-09-22

Abstract: For the security issues of SDN, the traditional firewalls and antivirus softwares can only prevent unauthorized external intrusions, but have little effect on preventing internal threats such as important information leakage caused by unauthorized modification of switch or controller configurations and flow rules. As the southbound interface of SDN, POF enables the controller to configure and control network behavior. By parsing POF messages, the communication content of SDN can be monitored and internal security problems can be discovered. In this paper, the POF is carefully studied and analyzed, and a protocol parser is designed based on network security audit system, through which the POF message types and key fields can be parsed and identified online, and session logs and operation logs can be generated for storage and display. This helps discover illegal behaviors in time and trace the source of evidence after a cyber security incident occurs. Through experimental tests, the system can achieve at least 30000 connections per second, 460 Mbps throughput, and 530000 packets per second processing performance under the premise of zero packet loss.

Key words: network security audit system, SDN, POF, protocol parsing