On Denial of Service Attacks in Software Defined Networks

Peng Zhang,Huanzhao Wang,Chengchen Hu,Chuang Lin
DOI: https://doi.org/10.1109/mnet.2016.1600109nm
IF: 10.294
2016-01-01
IEEE Network
Abstract:Software defined networking greatly simplifies network management by decoupling control functions from the network data plane. However, such a decoupling also opens SDN to various denial of service attacks: an adversary can easily exhaust network resources by flooding short-lived spoofed flows. Toward this issue, we present a comprehensive study of DoS attacks in SDN, and propose multi-layer fair queueing (MLFQ), a simple but effective DoS mitigation method. MLFQ enforces fair sharing of an SDN controller's resources with multiple layers of queues, which can dynamically expand and aggregate according to controller load. Both testbed-based and emulation-based experiments demonstrate the effectiveness of MLFQ in mitigating DoS attacks targeted at SDN controllers.
What problem does this paper attempt to address?