An Efficient Flow Rule Conflict Comprehensive Detection Scheme for SDN Networks
Bo Han, Yuan Liu, Yongbin Zhou, Yiwen Gao · 2024
Software-Defined Networking (SDN) has introduced flexibility and efficiency to network management but also faces challenges from flow rule conflicts, including static, dynamic, and dependency conflicts. Existing detection algorithms often focus on a single conflict type, resulting in inefficiencies and high false positive rates. To address these issues, we propose a comprehensive flow rule conflict detection scheme that improves real-time detection of explicit conflicts (both static and dynamic) and reduces false positives in implicit (dependency) conflict detection. Specifically, we present a real-time explicit conflict detection algorithm based on the Protocol-Divided Trie (PDT), which categorizes flow rules by protocol type and uses a prefix tree for rapid matching. Experimental results show that this approach significantly reduces detection times by at least 39.2% and achieves 100% detection accuracy. Additionally, we propose a two-stage detection (TSD) algorithm that combines the precision of path-based detection (PBD) with the efficiency of alias set-based detection (ASD). Our experiments reveal a 51% reduction in false positives compared to ASD and a 48% reduction in detection time compared to PBD, while maintaining equivalent false positive rates. This approach provides a robust solution for conflict detection in SDN, improving network security and resource utilization efficiency.