Mitigating Rogue Switch Attacks in Software-Defined Networking: Techniques and Countermeasures
Shantanu Sudhir Gujar, Prithvi Aiyattira Kishor Kumar · 2024
Software-defined networking (SDN) introduces innovative network management and flexibility but also exposes new vulnerabilities. This paper investigates the impact of rogue switches on SDN controllers, detailing various attack methodologies, including Denial-of-Service (DoS), traffic diversion, rule modification, and false reporting. Through experimentation with both basic and optimized Distributed Denial-of-Service (DDoS) attacks on Pox and Ryu controllers, I demonstrate significant degradation in network performance. The study also explores advanced rogue switch behaviors, such as cloning and diverting traffic, selective rule manipulation, and information extraction about the controller’s state. I propose several countermeasures, emphasizing the necessity of SSL/TLS implementation and additional verification mechanisms to protect controllers. Our findings underline the critical need to integrate security as a fundamental priority in future SDN specifications to safeguard against these threats.