A Lightweight Path Validation Scheme in Software-Defined Networks
Bing Hu, Yuanguo Bi, Kui Wu, Rao Fu, Zixuan Huang
Abstract
Software-Defined Networks (SDN) revolutionize traditional networks by separating control and data planes for enhanced agility and programmability. This separation, however, also opens up vulnerabilities, allowing adversaries to manipulate data plane forwarding and breach security policies. To counter this, we propose a Lightweight Path Validation Scheme (L-PVS) specifically designed for SDN environments. Our approach uses a simple validation scheme for packet forwarding paths that verifies the paths traversed by packets. Then, we further amplify the scheme with a network flow path validation to boost the validation efficiency. To reduce storage demands on switches during flow path validation, we develop a storage optimization method that aligns switch storage overhead with network flows rather than individual packets. Furthermore, we formulate a path partition scheme and present a Greedy-based KeySwitch Node Selection Algorithm (GKSS) to pinpoint optimal switches for path partition, significantly reducing overall data plane storage usage. Lastly, we design a technique using temporary KeySwitch nodes to identify anomaly switches when the controller encounters path validation failure. Evaluation results verify that L-PVS facilitates path validation with a reduced validation header size while minimizing the impact on processing delay and switch storage overhead.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Achieving Efficient Multipath Validation in Software-Defined NetworksBing Hu, Yuanguo Bi, Kui Wu, Zixuan Huang et al.INFOCOM 2025 · 1 citation
- The CrossPath Attack: Disrupting the SDN Control Channel via Shared LinksJiahao Cao, Qi Li, Renjie Xie, Kun Sun et al.USENIX Security 2019 · 68 citations
- 1BIT: Persistent Path Validation with Customized Noise Signal CharacteristicsKeji Miao, Jie Yuan, Xinghai Wei, Xingwu Wang et al.CCS 2025
- ProvGuard: Detecting SDN Control Policy Manipulation via Contextual Semantics of Provenance GraphsZiwen Liu, Jian Mao, Jun Zeng, Jiawei Li et al.NDSS 2025
- Towards Fine-grained Network Security Forensics and Diagnosis in the SDN EraHaopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu et al.CCS 2018 · 44 citations
