SDNGuard: An Extension in Software Defined Network to Defend DoS Attack
Jeevan Surya Maddu, Somanath Tripathy, Sanjeet Kumar Nayak · 2019 IEEE Region 10 Symposium (TENSYMP) · 2019
Nowadays, Software Defined Networking (SDN) is an emerging paradigm which facilitates easy management with enhanced reliability. OpenFlow enables the network controller to direct the packets across the switches in the network, so has many advantages. But, OpenFlow SDN networks are exposed to Denial-of-Service (DoS) attacks in which attacker consume the bandwidth of the the control plane and overload the butter memory of OpenFlow switch by sending bogus packets with non existence destination (random) IP. In this work, we propose a mitigation technique called SDNGuard to address this issue. SDNGuard extends the existing OpenFlow by adding a dataplane cache and a simple packet migration module. We evaluate SDNGuard and the results show that this model is effective in reducing the saturation attack.