🤖 AI Summary
This study addresses the vulnerability of Software-Defined Networking (SDN)-based electric vehicle charging systems to low-rate denial-of-service attacks, which can cause flow table exhaustion and station paralysis. To overcome the limitations of conventional passive, traffic-threshold-based defenses, this work proposes CS-SHIELD, a Moving Target Defense mechanism that integrates cross-layer authentication with dynamic virtual IP reassignment. This approach accurately detects and filters malicious flow rules while continuously shuffling IP addresses to invalidate attacker reconnaissance, thereby achieving proactive defense. Simulation results demonstrate that CS-SHIELD maintains full availability and rapid responsiveness of charging stations under attack scenarios, while introducing negligible latency during normal operation.
📝 Abstract
Software-Defined Networking (SDN) is emerging as a promis- ing technology for EV Charging infrastructure (EVCI) since it enables flexible, programmable control of EVCI networks, yet its security gain to EVCI remains underexplored. SDN-enabled EVCI faces an increas- ing number of cyber threats arising from the convergence of IT and OT components; in particular, low-rate Denial-of-Service (DoS) attacks. Ear- lier works identify a trend toward low-rate attacks in OT networks that may exhaust SDN switch flow tables and which can result in disabling the entire charging sites without triggering volume-based defenses. In this paper, we propose CS-SHIELD, a Moving Target Defense mecha- nism for SDN-enabled EVCI communication. We showcase the imple- mentation of the proposed mechanism that detects malicious flow table rules via cross-layer identity verification and responds by reassigning virtual IP addresses to all active chargers. Experiments on an emulated SDN testbed with a real charging protocol implementation demonstrate that CS-SHIELD maintains full site availability under attack, responds quickly, adds only a negligible delay under normal conditions. The reas- signing (shuffle) approach at each reaction makes the earlier reconnais- sance knowledge by the attacker rendered worthless.