Toward Delegating the Detection of DDOS Attacks to the SDN Data Plane: A Security Perspective
Mohamed Ali Setitra, Sid Ali Madoune, Zine El Abidine Bensalem, Mingyu Fan · 2023
With the widespread adoption of Software-Defined Networking (SDN) infrastructures that give a flexible architecture and make this network more reliable, network security has become a critical concern. Expressly, the Control Plane assumes a crucial role within this architecture and is often regarded as the brain of SDN. However, due to this centralization, the Control Plane is often the target of Distributed Denial of Service (DDoS) attack attacks, which are increasingly sophisticated. In the same context, most DDoS solutions are concentrated in the Control Plane, which has many other tasks and responsibilities. This study investigates the potential advantages and obstacles associated with relocating DDoS attack detection to the data plane, aligning with the growing prevalence of Programmable Data Planes utilizing the Programming Protocol-Independent Packet Processors (P4) language. To optimize resource utilization in combatting DDoS attacks.