Software Security in Software-Defined Networking: A Systematic Literature Review

📅 2025-02-18
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the lack of a systematic, rigorous survey on security vulnerabilities in the software layer of Software-Defined Networking (SDN)—encompassing controllers, northbound/southbound APIs, and applications. We conduct the first dedicated systematic literature review (SLR), analyzing 58 high-quality publications. Using thematic coding, vulnerability taxonomy modeling, and trend-based statistical analysis, we construct a comprehensive SDN software security risk classification framework that characterizes prevailing attack surfaces and detection methodologies. Key contributions include: (1) identifying three fundamental root causes of software-layer vulnerabilities; (2) exposing critical research gaps in five areas—dynamic policy verification, cross-layer coordinated defense, runtime anomaly containment, API-level trust enforcement, and controller-resilient application design; and (3) delivering the most complete, up-to-date landscape of SDN software security research to date, thereby establishing a foundational theoretical and technical basis for next-generation defense mechanism design.

Technology Category

Application Domains: Software EngineeringNatural Language Processing: Safety and RobustnessPlanning, Routing, and Scheduling: Other Foundations of Planning, Routing & Scheduling

Application Category

Security and Privacy: Large-scale security measurementsSystems and Infrastructure for Web, Mobile and WoT: Virtualization and resource management in Web systems and infrastructuresSocial Networks and Social Media: Applications and emergent phenomena
📝 Abstract
Software-defined networking (SDN) has shifted network management by decoupling the data and control planes. This enables programmatic control via software applications using open APIs. SDN's programmability has fueled its popularity but may have opened issues extending the attack surface by introducing vulnerable software. Therefore, the research community needs to have a deep and broad understanding of the risks posed by SDN to propose mitigating measures. The literature, however, lacks a comprehensive review of the current state of research in this direction. This paper addresses this gap by providing a comprehensive overview of the state-of-the-art research in SDN security focusing on the software (i.e., the controller, APIs, applications) part. We systematically reviewed 58 relevant publications to analyze trends, identify key testing and analysis methodologies, and categorize studied vulnerabilities. We further explore areas where the research community can make significant contributions. This work offers the most extensive and in-depth analysis of SDN software security to date.
Problem

Research questions and friction points this paper is trying to address.

Analyzes SDN software security risks
Reviews 58 publications for vulnerabilities
Identifies future research opportunities
Innovation

Methods, ideas, or system contributions that make the work stand out.

Systematic review of SDN security
Focus on software vulnerabilities
Extensive analysis of 58 publications
🔎 Similar Papers
No similar papers found.
M
M. Diouf
SnT Centre, University of Luxembourg, Esch-sur-Alzette, Luxembourg
S
Samuel Ouya
Cheikh Anta Diop University, Dakar, Senegal
Jacques Klein
Jacques Klein
University of Luxembourg / SnT
Computer ScienceSoftware EngineeringAndroid SecuritySoftware SecurityModel-Driven Engineering
T
Tegawend'e F. Bissyand'e
SnT Centre, University of Luxembourg, Esch-sur-Alzette, Luxembourg