DOI QR코드

DOI QR Code

Resource Attack Based On Flow Table Limitation in SDN

SDN 플로우 테이블 제한에 따른 리소스 어택

  • Tri, Hiep T. Nguyen (Department of Electronics and Computer Engineering Chonnam National University) ;
  • Kim, Kyungbaek (Department of Electronics and Computer Engineering Chonnam National University)
  • Published : 2014.11.05

Abstract

In Software Defined Network (SDN), data plane and control plane are decoupled. Dummy switches on the data plane simply forward packet based on the flow entries that are stored in its flow table. The flow entries are generated by a centralized controller that acts as a brain of the network. However, the size of flow table is limited and it can conduct a security issue related to Distributed Denial of Service (DDoS). Especially, it related to resource attack that consumes all flow table resource and consumes controller resources. In this paper, we will analyze the impact of flow table limitation to the controller. Then we propose an approach that is called Flow Table Management to handle flow table limitation.

Keywords