Software-Defined Networking Security: Architecture, Attack Surface, and Resilient Mechanisms
DOI:
https://doi.org/10.70917/ijcisim-2026-5340Keywords:
Software-Defined Networking (SDN), Network Security, SDN Architecture, Control Plane Security, Intrusion Detection Systems, OpenFlow Security, DDoS Attacks and Network VirtualizationAbstract
Software-Defined Networking (SDN) is a new way of thinking about networking in which the networking function is split into two planes: control plane and data plane. The aim of SDN is to give network managers greater control over network configuration, increased programmability, flexibility, and efficient use of network resources. These features have driven the rapid-fire uptake of SDN in today's communications networks, cloud and data center. However, all these appealing features can create additional security problems, increasing the attack surface and putting critical elements at risk of breaches. With the rapid emergence of SDN, network security and resilience are emerging top topics of researchers' interests. This paper provides a comprehensive survey of the SDN security by covering its architecture, key benefits and potential vulnerabilities. It explores potential attacks on the data plane, attacks on the communication channels outside the control plane, security challenges in the control plane, and existing approaches and proposed countermeasures from the literature. Moreover, the paper presents a survey of existing work, lists open challenges, research gaps and future research directions and implements some new trends related to secure, scalable and resilient SDN environments.