Title :
Denial-of-service attacks in OpenFlow SDN networks
Author :
Kandoi, Rajat ; Antikainen, Markku
Author_Institution :
Ericsson, Jorvas, Finland
Abstract :
Software-Defined Networking (SDN) has recently gained significant momentum. However, before any large scale deployments, it is important to understand security issues arising from this new technology. This paper discusses two types of Denial-of-Service (DoS) attacks specific to OpenFlow SDN networks. We emulate them on Mininet and provide an analysis on the effect of these attacks. We find that the timeout value of a flow rule, and the control plane bandwidth have a significant impact on the switch´s capability. If not configured appropriately, they may allow successful DoS attacks. Finally, we highlight possible mitigation strategies to address such attacks.
Keywords :
computer network security; software defined networking; DoS attacks; OpenFlow SDN networks; control plane bandwidth; denial-of-service attacks; flow rule; mitigation strategies; security issues; software-defined networking; switch capability; Bandwidth; Computer crime; Conferences; Protocols; Switches; DoS; OpenFlow; SDN; control plane; flow rule; security;
Conference_Titel :
Integrated Network Management (IM), 2015 IFIP/IEEE International Symposium on
Conference_Location :
Ottawa, ON
DOI :
10.1109/INM.2015.7140489