Security of SDN in an Adversarial Setting: The DDoS Case
Ranwa Al Mallah, Brian Lachine, Godwin Badu-Marfo · 2023
In Software Defined Networking (SDN) centralization of network control creates a single point of failure and a valuable target for threat actors that wish to produce an impact on the network. Notably, network controllers can be targeted by effects such as Denial of Service (DoS) attacks that would cripple the performance of the network as a whole by making critical services unavailable if they are not detected and prevented. In Artificial Intelligence (AI), Machine Learning (ML) techniques are used to identify the presence of malicious distributed DoS activity within a sample of data collected from network activity over an interval of time. However, machine learning techniques are themselves vulnerable to attacks. We perform a detailed security analysis of a highly realistic threat model and experimentally demonstrate the effectiveness of poisoning and evasion attacks on the SDN. After this adversarial AI experiment, we propose a defense mechanism adapted to the machine learning algorithm and able to protect against those attacks on the system. This research highlights the implications of the poor management of the use of AI as a new technology in this field.