Methodology to Improve Control Plane Security in SDN Environments

Methodology to Improve Control Plane Security in SDN Environments

River Publishers Series in River Rapids

Methodology to Improve Control Plane Security in SDN Environments Forthcoming

Authors:
Wendwossen Desalegn, Adama Science and Technology University, Ethiopia
Javed Shaikh, Adama Science and Technology University, Ethiopia
Bayisa Taye, Adama Science and Technology University, Ethiopia

ISBN: 9788770041959 e-ISBN: 9788770041942

Available: August 2024


This book unveils a blueprint for safeguarding the very backbone of modern communication networks. It offers a roadmap towards fortifying SDN infrastructures against the relentless onslaught of cyber threats, ensuring resilience and reliability in an ever-evolving digital landscape.

This is an exhaustive study of crafting a robust security solution tailored for the SDN environment, specifically targeting the detection and mitigation of distributed denial of service (DDoS) attacks on the control plane. The methodology hinges on an early detection strategy, meticulously aligned with industry standards, serving as a beacon for professionals navigating the intricate realm of implementing security solutions. This reference elucidates an innovative approach devised to identify and mitigate the inherent risks associated with the OpenFlow protocol and its POX controller. Validated through rigorous simulations conducted within controlled environments utilizing the Mininet tool and SDN controller, the methodology unfolds, showcasing the intricate dance between theory and practice.

Through meticulous observation of detection algorithm results in simulated environments, followed by real-world implementation within network testbeds, the proposed solution emerges triumphant. Leveraging network entropy calculation, coupled with swift port blocking mechanisms, the methodology stands as a formidable barrier against a DDoS attack such as TCP, UDP, and ICMP floods.
Software defined networks, network security, deniel of service, distributed deniel of service, attack detection and mitigation, entropy, internet control message protocol, openflow, pox controller, Scapy library