Skip to content
Review Open access

Software-Defined Networking Security: Architecture, Attack Surface, and Resilient Mechanisms

Aug 2026 · International journal of computer information systems and industrial management applications · Vol 18, pp. 731-743 · 0 citations

TL;DR

A comprehensive survey of the SDN security by covering its architecture, key benefits and potential vulnerabilities, and explores potential attacks on the data plane, attacks on the communication channels outside the control plane, security challenges in the control plane, and existing approaches and proposed countermeasures from the literature.

Abstract

Software-Defined Networking (SDN) is a new way of thinking about networking in which the networking function is split into two planes: control plane and data plane. The aim of SDN is to give network managers greater control over network configuration, increased programmability, flexibility, and efficient use of network resources. These features have driven the rapid-fire uptake of SDN in today's communications networks, cloud and data center. However, all these appealing features can create additional security problems, increasing the attack surface and putting critical elements at risk of breaches. With the rapid emergence of SDN, network security and resilience are emerging top topics of researchers' interests. This paper provides a comprehensive survey of the SDN security by covering its architecture, key benefits and potential vulnerabilities. It explores potential attacks on the data plane, attacks on the communication channels outside the control plane, security challenges in the control plane, and existing approaches and proposed countermeasures from the literature. Moreover, the paper presents a survey of existing work, lists open challenges, research gaps and future research directions and implements some new trends related to secure, scalable and resilient SDN environments.

Read PDF

Similar papers

Open access Aug 2026

A MITRE ATT&CK based Threat Modeling and QuantitativeRisk Assessment Framework for Software-Defined Networking

Software-Defined Networking (SDN) has emerged as a programmable networking paradigm that separates the control and data planes, enabling flexible and centralized network management while introducing new security challenges due to its software-based control architecture. However, this centralization of control, while ad...

Mariyam Ouaissa, Mariya Ouaissa, Zineb Nadifi et al. · 0 citations
Review Open access Sep 2026

Securing Industrial Control Systems: A Systematic Review of Software-Defined Networking (SDN) for Mitigating Attacks on Modbus/TCP and HTTP Protocols

Many communication protocols used in Industrial Control Systems, such as Modbus/TCP and web-based services, were developed many years ago and were not originally designed with strong security features. As a result, Industrial Control Systems became vulnerable to cyberattacks. This paper reviews existing studies that ex...

Mupatiwa Zulu, Lukumba Phiri · 0 citations
Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...

Kamal Singh, Brijesh Kumar · 0 citations
Conference Open access 2026

Mitigating Security Challenges in 5G Wireless Networks

An AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP), and empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees is pr...

F. Philip-Kpae, A. Imoize, K. .. Okafor et al. · 0 citations
Review Open access 2026

O-RAN Security: From Standardization and Threat Modeling to Practical Security Testing

The Open Radio Access Network (O-RAN) introduces openness and disaggregation to cellular networks, enabling innovation and multi-vendor interoperability. This article provides a comprehensive examination of O-RAN security with emphasis on two distinct contributions. First, we classify the O-RAN threat surface into thre...

Joshua Moore, A. S. Abdalla, Felix Klement et al. · 0 citations
Open access Aug 2026

DDoS Attacks in 5G Networks: Characteristics and Analysis of Defense Strategies

5G networks introduce transformative technologies like SDN, NFV, Network Slicing, and MEC that enable ultra-low latency and massive IoT connectivity, but simultaneously create new security vulnerabilities. The software-defined control plane, shared infrastructure, and proliferation of insecure IoT devices make DDoS att...

Ahmad Ahmadov · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.