A Signalling Game-Based Security Enforcement Mechanism for SDN Controllers
Madhukrishna Priyadarsini, Padmalochan Bera, Mohammad Ashiqur Rahman · 2019
The major advantages of software-defined networking (SDN) lie on effective traffic management, dynamic configuration of policy and flow rules, better scalability with heterogeneous traffic requirements. However, the centralized network control and use of OpenFlow protocols introduce security challenges over the underlying network. The attacks on the SDN controller are more critical as it hosts all network control functions to effectively manage the network. This paper presents a solution to proactively prevent various potential attacks in the SDN controller. Our work is motivated by a systematic analysis of different attack scenarios in SDN using STRIDE attack model. We design a trust-based controller attack detection(TCAD) model using the signaling game approach. It calculates the trust value of each incoming packet request to the controller that drives the generation of secure flow rules. We have evaluated our proposed solution in different scenarios with varying traffic requirements and injecting attacks based on the STRIDE model. The experimentation results show 99% accuracy in attack detection against potential attacks.