TY - JOUR
T1 - Lightweight yet Accurate
T2 - Detecting SDN Topology Poisoning via Traffic Pattern Correlation and Sequential Hypothesis Probing
AU - Huang, Xuanbo
AU - Li, Ruiqing
AU - Xue, Kaiping
AU - Chen, Lutong
AU - Yin, Hang
AU - Huang, Zixu
AU - Su, Zhou
AU - Shin, Hyundong
N1 - Publisher Copyright:
© 2013 IEEE.
PY - 2026
Y1 - 2026
N2 - Topology poisoning in Software-Defined Networking (SDN) enables attackers to inject non-existent links into the controller's topology view, allowing traffic hijacking, blackholing, or surveillance. Existing defenses either rely on verifying controller behavior or utilize attack-specific packet inspections. Consequently, such methods have high overhead and provide limited detection efficacy against diverse topology poisoning attacks (TPAs). In this paper, we introduce a traffic-pattern-based detection scheme against in-band TPAs. The key insight is that in-band TPAs must reuse existing physical links, so fake links inevitably shadow the traffic characteristics of one or more underlying physical paths. To capture these shadowed characteristics, we develop two techniques. First, we identify candidate physical paths for each newly reported link and select observation points with minimal overhead by formulating a hitting-set problem and reducing it to a minimum-cut problem that can be solved efficiently. Second, we apply a sequential probability ratio test (SPRT) to traffic characteristics derived from link-load time series, i.e., Pearson correlation coefficients of suspicious links and potential physical paths that support them. The SPRT provides targeted detection confidence while enabling early termination to reduce detection overhead. Experiments demonstrate that the proposed scheme achieves more than 98.8% accuracy, recall, precision, and F1 score in high-noise environments while maintaining low overhead.
AB - Topology poisoning in Software-Defined Networking (SDN) enables attackers to inject non-existent links into the controller's topology view, allowing traffic hijacking, blackholing, or surveillance. Existing defenses either rely on verifying controller behavior or utilize attack-specific packet inspections. Consequently, such methods have high overhead and provide limited detection efficacy against diverse topology poisoning attacks (TPAs). In this paper, we introduce a traffic-pattern-based detection scheme against in-band TPAs. The key insight is that in-band TPAs must reuse existing physical links, so fake links inevitably shadow the traffic characteristics of one or more underlying physical paths. To capture these shadowed characteristics, we develop two techniques. First, we identify candidate physical paths for each newly reported link and select observation points with minimal overhead by formulating a hitting-set problem and reducing it to a minimum-cut problem that can be solved efficiently. Second, we apply a sequential probability ratio test (SPRT) to traffic characteristics derived from link-load time series, i.e., Pearson correlation coefficients of suspicious links and potential physical paths that support them. The SPRT provides targeted detection confidence while enabling early termination to reduce detection overhead. Experiments demonstrate that the proposed scheme achieves more than 98.8% accuracy, recall, precision, and F1 score in high-noise environments while maintaining low overhead.
KW - correlation analysis
KW - Software-defined networking
KW - topology poisoning attacks
UR - https://www.scopus.com/pages/publications/105041020878
U2 - 10.1109/TNSE.2026.3699574
DO - 10.1109/TNSE.2026.3699574
M3 - 文章
AN - SCOPUS:105041020878
SN - 2327-4697
JO - IEEE Transactions on Network Science and Engineering
JF - IEEE Transactions on Network Science and Engineering
ER -