An Efficient Approach for Detection of Compromised SDN Switches and Restoration of Network Flow

PDF (627KB), PP.46-56

Tinku Adhikari 1,2,* Ajoy Kumar Khan 1 Malay Kule 3 Subhajit Das 4

1. Mizoram University/Computer Engineering, Aizawl, 796009, India

2. Techno International Newtown/Information Technology, Kolkata, 700156, India

3. IIEST/CST, Shibpur, 711103, India

4. Hiroshima University/HiSIM Research Center, Hiroshima, 739-8530, Japan

* Corresponding author.


Received: 10 Apr. 2023 / Revised: 19 Oct. 2023 / Accepted: 27 Dec. 2023 / Published: 8 Oct. 2024

Index Terms

Compromised SDN Switch, Data Plane, Flow Reconstruction, CPU Overhead


In Software Defined Networking (SDN) the data plane is separated from the controller plane to achieve better functionality than the traditional networking. Although this approach poses a lot of security vulnerabilities due to its centralized approach. One significant issue is compromised SDN switches because the switches are dumb in SDN architecture and in absence of any intelligence it can be a easy target to the attackers. If one or more switches are attacked and compromised by the attackers, then the whole network might be down or defunct. Therefore, in this work we have devised a strategy to successfully detect the compromised SDN switches, isolate them and then reconstruct the whole network flow again by bypassing the compromised switches. In our proposed approach of detection, we have used two controllers, one as primary and another as secondary which is used to run and validate our algorithm in the detection process. Flow reconstruction is the next job of the secondary controller which after execution is conveyed to the primary controller. A two-controller strategy has been used to balance the additional load of detection and reconstruction activity from the master controller and thus achieved a balanced outcome in terms of running time and CPU utilization. All the propositions are validated by experimental analysis of the results and compared with existing state of the art to satisfy our claim.

Cite This Paper

Tinku Adhikari, Ajoy Kumar Khan, Malay Kule, Subhajit Das, "An Efficient Approach for Detection of Compromised SDN Switches and Restoration of Network Flow", International Journal of Computer Network and Information Security(IJCNIS), Vol.16, No.5, pp.46-56, 2024. DOI:10.5815/ijcnis.2024.05.05


