Toward Mitigation of Flow Table Modification Attacks in P4‐Based SDN Data Plane
Buchammagari Avinash Reddy, Kshira Sagar Sahoo, Monowar H. Bhuyan · Security and Privacy · 2025
ABSTRACT Software‐defined network (SDN) is an emerging programmable network paradigm that enables numerous advantages to meet massive‐scale and automated network management demands. Despite that, security risks are inherent in SDN architecture for many reasons. Control and data plane limitations are examples that open up security challenges such as updating flow tables, resource exhaustion, and topology spoofing. This article presents a new flow table modification threat model that modifies matching flow rules periodically in the P4‐programmable SDN data plane, where an attacker manipulates the flow rules from a compromised switch in a stochastic manner. The centralized management and programmable capability of SDN data plane have been used to identify and address the modified flow rules effectively. The proposed detection framework identifies the malicious switch within the network using thrift ports. Moreover, a fuzzy‐rule‐based mitigation strategy has been developed to identify the severity of attacks. Two key strategies are explored: mild and complete mitigation to thwart attacks, where each action was carried out according to the modified flow rules. The efficacy of the proposed model is evaluated using a developed testbed setup that uses Facebook datacenter fabric topology using a Mininet emulator and Behavioral Model version 2 (BMv2) switch. This finding demonstrates a remarkable enhancement in the packet delivery ratio by and reduced the controller overhead by .