Detección de ataques de denegación de servicio en redes definidas por software
Fecha
Autores
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
Software-Defined Networking (SDN) has emerged as an innovative alternative to traditional network architectures, offering flexibility, programmability, and a global view of topology through the separation of the control and data planes. However, this centralization also introduces new security challenges, as the controller becomes a critical point of vulnerability. Among the most significant threats are Denial-of-Service (DoS/DDoS) attacks, which can exhaust control-plane resources through malicious traffic flows and degrade overall network performance. This article presents a review of vulnerabilities in SDN environments, the main detection techniques proposed in literature and the key current challenges. Based on this analysis, a two-layer hybrid detection architecture is proposed, combining lightweight detection techniques for early anomaly identification with on-demand ML/DL based classifiers for suspicious traffic, highlighting the need for specialized mechanisms that preserve controller performance while optimizing computational cost.
