Dan Tang, Pei Tan, Yudong Yan, Keqin Li, Wei Liang, Zheng Qin, Jiliang Zhang
Software-defined Networking (SDN) is an emerging network architecture. The decoupled data and control plane provide flexible manageability and programmability to the network. One of the core components in SDN switches to direct traffic forwarding is the flow table, which is usually stored in the ternary content addressable memory (TCAM) with limited space and high power consumption, making the flow table a potential target for attacks. This paper examines the Low-Rate Flow Table Overflow (LRFTO) attacks, which fill the flow table and render it unavailable by continuously sending attack rules to occupy the space. We propose a quantitative model of LRFTO attacks to describe the attack behavior, analyze its difference from legitimate traffic, and summarize some key aspects and features to distinguish attack rules from legitimate rules. We also propose LRFTO-ADMS, a system that utilizes machine learning-based classification as its core to evict suspicious rules, thereby ensuring flow table availability. Experimental results show that the threat model can adapt correctly to the network environment. The proposed LRFTO-ADMS can evict attack rules with an accuracy of more than 95% and low overhead while protecting the flow table and the legitimate rules from being unavailable.