Game-Theoretic Approach to Malicious Controller Detection in Software Defined Networks

Vignesh Sridharan, Mohan Gurusamy · 2018

Software Defined Networking (SDN) enables programmability and flexibility in networks through the separation of control and data plane. SDN architecture poses new security threats to the network, especially in the control plane. A compromised controller can exhibit malicious behavior such as fraudulent rule installation while avoiding detection. Existing approaches deal with this issue by broadcasting every flow setup request to multiple controllers to check for forwarding rule consistency. This imposes heavy load on the control plane, leading to longer response time and increased cost. We propose a novel approach that can effectively detect a malicious controller without overloading the control plane. The proposed game-theoretic approach randomly selects switches to check for consistency of forwarding rules. We model the problem as a Stackelberg game and solve the corresponding optimization problem to obtain an effective randomization strategy. We also develop a heuristic algorithm to determine a set of actions for the defender to make the problem tractable. We consider load management at the controller and relative importance of switches while finding an optimal strategy for randomized checking. In comparison with three other heuristic approaches, our approach achieves up to 88% improvement in probability of detecting the malicious controller.

Read the paper · More papers on PaperTik