Side-Channel Attacks in SDNs
Comprehensive survey of side-channel attack vectors in Software-Defined Networks, submitted to ACM Computing Surveys.
A systematic literature survey co-authored with Prof. Zhiyong Shan, currently under review at ACM Computing Surveys.
SDN Architecture
Attack Surface Summary
| Attack Class | Vector | Target | Mitigation Gap |
|---|---|---|---|
| Control-plane timing leak | First-packet round-trip time | Flow-rule existence | Partial (randomized delays) |
| Flow-table covert channel | TCAM capacity exhaustion | Cross-tenant traffic inference | Open problem |
| Controller load oracle | High-rate packet-in flooding | Concurrent flow state | Partial (rate limiting) |
| Topology fingerprinting | Probe packet timing | Network topology | Limited coverage |
Key Findings
Software-defined networking creates three novel side-channel surfaces absent from traditional networks:
- Control-plane timing leaks — the round-trip time of a first-packet lookup reveals whether a flow rule exists, enabling topology fingerprinting without breaking encryption.
- Flow-table covert channels — TCAM capacity exhaustion allows a malicious tenant to infer other tenants’ traffic across isolation boundaries.
- Controller load oracles — saturating the packet-in queue enables inference about concurrent flow state.
Status. Under review at ACM Computing Surveys (2025).