TY - JOUR A2 - Tsai, Sang-Bing AU - Gao, Ya AU - Wang, Zhenling PY - 2021 DA - 2021/11/23 TI - A Review of P4 Programmable Data Planes for Network Security SP - 1257046 VL - 2021 AB - Network attacks show a trend of increased attack intensity, enhanced diversity, and more concealed attack methods, which put forward higher requirements for the performance of network security equipment. Unlike the SDN (software defined network) switch with a fixed-function data plane, switches with programmable data planes can help users realize more network protocols. Programming Protocol-independent Packet Processors (P4) is proposed to define the operations of the data plane and to implement user’s applications, e.g., data center networks, security, or 5G. This paper provides a review of research papers on solving network security problems with P4-based programmable data plane. The work can be organized into two parts. In the first part, the programming language P4, P4 program, architectures, P4 compilers, P4 Runtime, and P4 target are introduced according to the workflow model. The advantages of P4-based programmable switching in solving network security are analyzed. In the second part, the existing network security research papers are divided into four parts according to the perspectives of passive defense, active defense, and combination of multiple technologies. The schemes in each category are compared, and the core ideas and limitations are clarified. In addition, a detailed comparison is made for the research on the performance of P4 targets. Finally, trends and challenges related to the P4-based programmable data plane are discussed. SN - 1574-017X UR - https://doi.org/10.1155/2021/1257046 DO - 10.1155/2021/1257046 JF - Mobile Information Systems PB - Hindawi KW - ER -