Attack Detection and Mitigation using Intelligent Data Planes in SDNs
Aparna Ganesan, Kamil Saraç · GLOBECOM 2022 - 2022 IEEE Global Communications Conference · 2022
Despite its significant advantages over distributed control in traditional networks, the centralized control used in software defined networks (SDN) introduces potential security vulnerabilities. The controller-switch bandwidth, flow tables in data plane switches, and the controller itself could become overwhelmed by potential denial of service attacks in SDN. In this work, we present a machine learning (ML) based approach to defend SDNs from such attacks. We use decision tree and logistic regression based ML models to identify decision boundaries at the controller site. We then translate these decision boundaries into range compressed match-action table rules. Next, we dynamically communicate these rules to the data plane switches using P4 language primitives enabling switches to filter out attack traffic without needing to consult with the SDN controller for each new packet. Our solution allows us to dynamically update the match-action rules based on the changing behavior of the attack traffic without causing any downtime for the data plane switches.