Securing Southbound Interface in SDNs: Utilizing Support Vector Machines for OpenFlow Packet Classification

Ali Gökhan Avran, Elif Ak, Kübra Duran, Gökhan Yurdakul, Gökhan Seçinti · 2023

The southbound interface enables communication and interaction between the Software-Defined Networking (SDN) controller and the underlying network infrastructure, including switches, routers, and other network devices, requesting network resources and manipulating the network’s behavior. Nevertheless, it introduces certain risks that must be addressed to ensure the effective deployment and operation of SDN systems. This paper introduces an OpenFlow Packet Classification Framework for southbound communication in SDN using a Support Vector Machine (SVM) that addresses possible security risks associated with OpenFlow communication in SDN environments. The proposed framework empowers the SVM model to capture complex patterns and boundaries within Southbound communication data using our novel adjusted-weight level approach. Our empirical analysis demonstrates that this framework yields superior results in classifying Southbound SDN packets by incorporating level adjustments to OpenFlow parameters. The introduced solution demonstrated its effectiveness with remarkable accuracy, achieving a detection rate of 0.985 as measured by the classification model’s score, coupled with a notably low occurrence of false alarms. The examined OpenFlow Packet Classification Framework also offers a promising platform for future studies implementing advanced security mechanisms, thereby mitigating security risks prevalent in SDN environments.

Read the paper · More papers on PaperTik