HSDT: Table-Overflow Attack Defender with Historical Statistics Based Dynamic Timeout in Software Defined Networks

Citations

WEB OF SCIENCE

2

초록

A Software Defined Network (SDN) provides efficient network management by decoupling two planes: the control plane and the data plane. However, although SDN provides efficient network management, it also causes several critical vulnerabilities. In particular, the lack of memory for a flow table in the data plane can be exploited to conduct a flow table overflow attack. This paper proposes a history-based dynamic timeout scheme to mitigate the flow table overflow attack. The proposed scheme dynamically sets up both hard timeout and idle timeout based on statistical history for each flow, which can quickly remove attack flows from a flow table. Consequently, it can keep the occupancy of the flow table low and secure the robustness against the flow table overflow attack. The experiment results show that the proposed HSDT can mitigate the overflow attack with reasonable overhead by effectively evicting attack flow rules from the flow table while it has a minimal impact on the other normal flow rules and bandwidth.

키워드

Software Defined Networkflow table overflowdynamic timeout
제목
HSDT: Table-Overflow Attack Defender with Historical Statistics Based Dynamic Timeout in Software Defined Networks
저자
Noh, Sichul KevinPark, Minho
DOI
10.3390/app132212232
발행일
2023-11
유형
Article
저널명
APPLIED SCIENCES-BASEL
13
22