{"title":"Multi-probability sampling-based detection of malicious switching nodes in SDN","authors":"Jingxu Xiao , Chaowen Chang , Ping Wu , Lu Yuan","doi":"10.1016/j.cose.2025.104324","DOIUrl":null,"url":null,"abstract":"<div><div>Addressing the potential risk of malicious exploitation of switching devices in software-defined networks (SDN), this paper proposes a multi-probability sampling-based detection of malicious switching nodes in SDN, called MPSDMN. MPSDMN selects switching nodes in the link as sampling nodes and assigns sampling probabilities to them. The sampling nodes sample and count data packets based on rewritten headers, and the controller detects and locates the malicious switching nodes based on the bisection method, effectively reducing the computational cost of switching devices. The experimental results show that the MPSDMN can effectively detect and locate the attacks of various malicious nodes such as tampering attacks, path anomaly attacks, and drop attacks, introducing less than 9% forwarding delay and less than 9% throughput loss, with lightweight performance overhead.</div></div>","PeriodicalId":51004,"journal":{"name":"Computers & Security","volume":"151 ","pages":"Article 104324"},"PeriodicalIF":4.8000,"publicationDate":"2025-01-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computers & Security","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0167404825000136","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
Addressing the potential risk of malicious exploitation of switching devices in software-defined networks (SDN), this paper proposes a multi-probability sampling-based detection of malicious switching nodes in SDN, called MPSDMN. MPSDMN selects switching nodes in the link as sampling nodes and assigns sampling probabilities to them. The sampling nodes sample and count data packets based on rewritten headers, and the controller detects and locates the malicious switching nodes based on the bisection method, effectively reducing the computational cost of switching devices. The experimental results show that the MPSDMN can effectively detect and locate the attacks of various malicious nodes such as tampering attacks, path anomaly attacks, and drop attacks, introducing less than 9% forwarding delay and less than 9% throughput loss, with lightweight performance overhead.
期刊介绍:
Computers & Security is the most respected technical journal in the IT security field. With its high-profile editorial board and informative regular features and columns, the journal is essential reading for IT security professionals around the world.
Computers & Security provides you with a unique blend of leading edge research and sound practical management advice. It is aimed at the professional involved with computer security, audit, control and data integrity in all sectors - industry, commerce and academia. Recognized worldwide as THE primary source of reference for applied research and technical expertise it is your first step to fully secure systems.