Impact Analysis of New-Flow Based DDoS Attacks in SDN-Enabled Autonomous Systems
摘要
Software-defined networking (SDN) enhances network programmability. Still, it introduces vulnerabilities, particularly to new-flow DDoS attacks, where attackers flood the network with unique, short-lived flows, forcing switches to generate excessive packet-in messages to the controller. Existing research primarily addresses traditional DDoS attacks but lacks a detailed impact analysis of new-flow DDoS attacks on SDN-enabled autonomous systems (AS). This study evaluates the POX controller’s performance under such attacks using a Mininet-based simulation, where a custom SDN topology was subjected to both legitimate and attack traffic. The Key performance metrics, including packet-in message rate, flow table utilization, and packet loss, were analyzed, revealing that as the attack intensity increases, the POX controller becomes overwhelmed, leading to processing delays, resource exhaustion, and severe network degradation. The insights from this study provide a deeper understanding of the vulnerabilities of the SDN controller, helping researchers and network administrators develop more robust security strategies, traffic management policies, and adaptive control mechanisms to improve SDN resilience against sophisticated DDoS attacks.