An Approach for Protecting the OpenFlow Switch from the Saturation Attack
Mingxin Wang, Huachun Zhou, Jia Chen, Bo Tong · 2016
Security is always a serious issue influencing the development of Software-Defined Network (SDN).The central control mechanism makes the SDN controller a bottleneck of the network which is vulnerable to network saturation attack.In this paper, we propose an approach to defense this kind attack.Firstly, we add a miss matched packet cache module in the OpenFlow switch which can temporarily cache the packets that don't match in the flow table.Besides, we apply the mechanism of separating the header and payload of packets in the cache queue once the switch detects the volume of cache queue exceeding the threshold of the cache size.In addition, the switch can classify the packets headers and send it in an alert message to the SDN controller for further processing.At last in the paper, we evaluate the effort of our proposed approach in Mininet.With our approach, the SDN network can effectively defend the network saturation attack.