Preventing DDoS Attacks in SDN Networks: A Model of Defense Against Packet-in Flooding
Wendnéso Aïda Ouedraogo Rakissaga, Pegdwindé Justin Kouraogo, Tounwendyam Frédéric Ouédraogo · 2025
The Software-Defined Networking (SDN) paradigm is increasingly attracting market players due to the centralization of control functions and the physical distinction between the control and data planes. However, it is not immune to disruptions caused by misconfigurations, cyberattacks, or natural disasters. Moreover, the primary benefit of SDN, centralized network control, also makes it highly susceptible to DDoS (Distributed Denial of Service) attacks. As a result, DDoS attacks pose a considerable threat to the security of SDN networks. To address this issue, we focus on a specific type of message known as the 'packet-in.' In SDN network operations, when a switch receives a new packet and does not find a match in its flow table, it requests a forwarding rule from the controller via a packet-in message. We leverage this type of message to propose a solution for preventing DDoS attacks in SDN environments. Several approaches have been explored to counter DDoS attacks in SDN networks, but most involve the controller. This presents two limitations: first, it increases the controller’s workload, which is already heavily utilized in the SDN architecture; second, it is preferable to eliminate the attack at the network’s edge. The proposed solution involves monitoring the number of distinct destinations contacted by a given source within a specific time window, based on the quantity of packet-in messages triggered by that source. If the number of unique destinations exceeds a predefined threshold, the source node is deemed suspicious and placed in quarantine. Through our solution, which enables the identification and blocking of DDoS attacks directly at the data plane, we contribute to reducing the controller’s workload and facilitating rapid decision-making (no need to send a Packet-In to the controller for every suspicious packet).