When SDN Meets Low-rate Threats: A Survey of Attacks and Countermeasures in Programmable Networks

D Tang, R Dai, Y Yan, K Li, W Liang, Z Qin - ACM Computing Surveys, 2024 - dl.acm.org
Low-rate threats are a class of attack vectors that are disruptive and stealthy, typically crafted
for security vulnerabilities. They have been the significant concern for cyber security …

LtRFT: Mitigate the low-rate data plane DDoS attack with learning-to-rank enabled flow tables

D Tang, Y Yan, C Gao, W Liang… - IEEE Transactions on …, 2023 - ieeexplore.ieee.org
Software-Defined Networking (SDN) switches typically have limited ternary content
addressable memory (TCAM) that caches the flow entries on the data plane. The scarcity …

RDefender: A lightweight and robust defense against flow table overflow attacks in SDN

D Kong, X Chen, C Wu, Y Shen, Z Zhou… - IEEE Transactions …, 2024 - ieeexplore.ieee.org
The flow table is a critical component of Software-Defined Networking (SDN). However, flow
tables' limited capacity makes them highly vulnerable to flow table overflow attacks (FTOAs) …

FTODefender: An efficient flow table overflow attacks defending system in SDN

D Tang, Z Zheng, C Yin, B **ong, Z Qin… - Expert Systems with …, 2024 - Elsevier
Abstract Software-Defined Networking (SDN) is a promising architecture that disentangles
the control plane from the data plane. A mainstream southbound protocol for controller-to …

Ftop: An efficient flow table overflow preventing system for switches in sdn

D Tang, Z Zheng, K Li, C Yin, W Liang… - IEEE Transactions on …, 2023 - ieeexplore.ieee.org
The Software-Defined Networking (SDN) is a new network framework widely adopted in
data center networks that decouples the control plane from data plane to make network …

POAGuard: A Defense Mechanism Against Preemptive Table Overflow Attack in Software-Defined Networks

Y Liu, Y Wang, H Feng - IEEE Access, 2023 - ieeexplore.ieee.org
In Software-Defined Networks (SDN), the limited flow table capacity of switches makes them
susceptible to flow table overflow attacks, which can lead to performance degradation or …

FTSheild: An intelligent framework for LOFT attack detection and mitigation with programmable data plane

L Jain, U Venkanna, S Vollala - Expert Systems with Applications, 2025 - Elsevier
Programmable data plane switches typically have limited flow table capacity, making them
easily vulnerable to overflow attacks. Due to this, it faces challenges in efficiently forwarding …

In-band Network Telemetry Manipulation Attacks and Countermeasures in Programmable Networks

D Kong, Z Zhou, Y Shen, X Chen… - 2023 IEEE/ACM 31st …, 2023 - ieeexplore.ieee.org
In-band Network Telemetry (INT) is a widely used monitoring framework in modern large-
scale networks that provides fine-grained visibility into network conditions by inserting …

Securing P4-SDN data plane against flow table modification attack

BA Reddy, KS Sahoo, M Bhuyan - NOMS 2024-2024 IEEE …, 2024 - ieeexplore.ieee.org
Security in Software Defined Network (SDN) architecture is becoming the most substantial
challenge. This paper introduces a novel threat model focused on flow table modification in …

Synchronizing real-time and high-precision LDoS defense of learning model-based in AIoT with programmable data plane, SDN

J Ma, W Su, Y Li, Y Yuan, Z Zhang - Journal of Network and Computer …, 2024 - Elsevier
The availability of SD-AIoT is currently under complicated and serious cyber threats,
especially Low-rate Denial-of-Service attacks. However, traditional defense schemes for …