SDN_Guard: An Advanced Machine Learning based Defense System against Packet Injection Attacks in SDN
Mitali Sinha, Padmalochan Bera, Manoranjan Satpathy · Procedia Computer Science · 2025
The centralized architecture of a Software Defined Network (SDN) makes it prone to many security vulnerabilities like packet injection attacks. In this type of attack, malicious applications from compromised hosts inject a large number of fake packets with spoofed MAC or IP addresses into the controller leading to malfunctions in the network. Existing solutions address this problem by indiscriminately blocking both malicious and benign traffic resulting in a notable False Positive Rate (FPR). To address this challenge, we have proposed SDN Guard, which is introduced to the control layer of the SDN architecture; SDN Guard consists of three modules: Detection, Mapping, and Prevention modules. In the first module, we apply Random Forest based Machine Learning approach to the network traffic to accurately determine the actual MAC and IP addresses of hosts connected to switch host ports. This information is recorded in a mapping table by the Mapping module. The Prevention module integrates the mapping table into the switches to drop the spoofed packets at their source points without interrupting the legitimate packets. SDN Guard is implemented in Floodlight controller and its performance is evaluated under varying attack scenarios. The experimental results show that SDN Guard reduces FPR to 0.51% and improves the response time of the legitimate traffic, with a reduction in CPU utilization by 6-7% compared to existing solutions.