Enhancing SDN Controller Resilience against DDoS Attacks through Fraud Message Detection using Principal Component Analysis

G Florance, R J Anandhi, C. Mahiba · IETE Journal of Research · 2025

Software-defined networking (SDN) is a virtual network technology that operates on the OpenFlow protocol and is increasingly vulnerable to distributed denial of service (DDoS) attacks. To address this, various detection techniques analyze data from the flow table of OpenFlow switches to identify DDoS attacks within an SDN environment. However, these methods often overload the centralized OpenFlow controller, impacting network performance. This study proposes a fraud message detection (FMD) technique using principal component analysis (PCA) to identify anomalies in PACKET_IN messages without relying on flow table data, thereby reducing the controller's processing load. The FMD technique triggers dynamic detection when PACKET_IN messages exceed 75% of the flow table capacity, enabling lightweight and real-time mitigation of DDoS attacks. The approach is evaluated using Mininet, POX, and OpenDayLight (ODL) controllers under simulated DDoS attack scenarios. Results demonstrate a 20-30% reduction in controller processing time compared to flow table-based methods, with detection achieved in 13 min during attack conditions on the ODL controller, as opposed to 17 min with existing techniques. This highlights the effectiveness of the proposed approach in enhancing SDN resilience against DDoS attacks.

Read the paper · More papers on PaperTik