P4M3: Preventing SYN Flood Attacks on IPv6 Networks in SDN Using P4
Hongfei Zhang, Jie Li, Zeyu Yang, Shu Li, Huiping Zhu, Qingyun Liu · 2025
Software-Defined Networking (SDN) centralizes control through a controller, making it a target for DDoS attacks, especially with IPv6's expansive address space, which increases vulnerability to SYN Flood attacks. P4M3(Three-layer Module architecture based on P4), a preventive solution for IPv6 SDN environments, is designed to detect and prevent SYN Flood attacks through P4 switches and the ONOS controller. The solution includes three modules: the Quick Detection and Threshold Detection modules on the data plane, and the Machine Learning Detection module on the controller. The data plane uses a danger address matching table and a Count-Min Sketch threshold method to filter suspicious SYN Flood traffic and relay packet characteristics to the controller's Machine Learning Detection module. The controller classifies packets using an ensemble learning model and issues blocking rules to the switch as needed. Results show that P4M3 reduces CPU usage by 81.92%, while maintaining low latency and enhancing SYN Flood detection accuracy, thus demonstrating its effectiveness in protecting IPv6 SDN networks from DDoS attacks.