Score
Designs and evaluates architectures for Software-Defined Networking (SDN) controllers, including control-plane components, module organization, northbound and southbound APIs, placement and distribution strategies, scalability, fault tolerance, and state management. Builds prototypes or analytical models to analyze controller performance, consistency, reliability, failure recovery, and interactions with forwarding devices and management applications.
Existing performance evaluations of SDN controllers lack comprehensive coverage of realistic scenarios—such as asymmetric topologies, dynamic topology reconfigurations, and high-concurrency flow bursts—limiting insights into practical bottlenecks. Method: We design a programmable emulation platform based on Mininet and OpenFlow 1.3, introducing a standardized experimental framework and automated performance measurement scripts to enable reproducible, multi-controller comparative analysis. Contribution/Results: Our systematic evaluation reveals that Ryu exhibits up to a 37% throughput degradation in tree- and ring-shaped topologies; control-path latency scales quadratically (O(n²)) with network size. Crucially, we quantitatively identify previously unreported deficiencies: drastic flow-table update latency spikes under dynamic topology changes and imbalanced handling of asymmetric links. These findings provide empirically grounded guidance for SDN controller selection, architectural refinement, and protocol enhancement, along with a publicly replicable benchmarking methodology.
This study systematically evaluates the Quality-of-Service (QoS) performance differences between two prominent open-source SDN controllers—POX and Ryu—in scalable network environments. Using Mininet, we construct multi-scale topologies and implement OpenFlow-based flow programming and Python-based controller logic to quantitatively measure key QoS metrics: throughput, end-to-end latency, and jitter. Our work presents the first cross-topology empirical quantification of their scalability boundaries. Results show that Ryu achieves 42% higher throughput and 31% lower average latency than POX at the thousand-node scale, demonstrating superior production-readiness for large deployments. Conversely, POX exhibits advantages in small-scale scenarios—including faster startup time and greater debugging flexibility—due to its lightweight architecture. These findings provide data-driven, practical guidance for SDN controller selection and optimization in real-world network deployments.
This study addresses the lack of a systematic, rigorous survey on security vulnerabilities in the software layer of Software-Defined Networking (SDN)—encompassing controllers, northbound/southbound APIs, and applications. We conduct the first dedicated systematic literature review (SLR), analyzing 58 high-quality publications. Using thematic coding, vulnerability taxonomy modeling, and trend-based statistical analysis, we construct a comprehensive SDN software security risk classification framework that characterizes prevailing attack surfaces and detection methodologies. Key contributions include: (1) identifying three fundamental root causes of software-layer vulnerabilities; (2) exposing critical research gaps in five areas—dynamic policy verification, cross-layer coordinated defense, runtime anomaly containment, API-level trust enforcement, and controller-resilient application design; and (3) delivering the most complete, up-to-date landscape of SDN software security research to date, thereby establishing a foundational theoretical and technical basis for next-generation defense mechanism design.
This work addresses the challenges of low routing efficiency, poor scalability, and security vulnerabilities in mobile ad hoc networks (MANETs) and Internet of Things (IoT) systems, which stem from their decentralized nature and resource constraints. To overcome these limitations, the study proposes a novel, centralized, and programmable intelligent networking framework by systematically integrating software-defined networking (SDN) architecture for the first time. An optimization model balancing both capital expenditure (CAPEX) and operational expenditure (OPEX) is formulated to enable efficient resource allocation and enhanced security under dynamic topologies. Experimental results demonstrate that the proposed approach significantly improves network scalability, reduces end-to-end latency and packet loss, and increases throughput, with particularly pronounced performance gains in large-scale, highly dynamic scenarios.
This paper addresses the challenge of detecting state-dependent performance issues (SPIs) in Software-Defined Networking (SDN) controllers—i.e., input sequences that drive the controller into anomalous states, causing severe performance degradation in subsequent operations. We propose the first dependency-aware, modular performance fuzzing methodology, integrating event-driven architecture modeling, static service dependency analysis, and state-sensitive coverage-guided grey-box fuzzing to systematically uncover SPIs across 157 network services in ONOS. Our approach identifies 10 previously unknown SPI vulnerabilities in ONOS, two of which have been confirmed to induce critical latency spikes or response blocking. Compared to existing performance fuzzing techniques, our method achieves significantly higher detection efficiency and uncovers deeper, more complex SPIs rooted in intricate service dependencies and state transitions.
This study addresses the coordination challenges in in-band SDN control plane deployments with multiple controllers, where controller discovery, state synchronization, and failure recovery must be achieved without expanding switch forwarding state. The authors propose a boundary-switch-based local forwarding graph mechanism that confines inter-domain routing information to boundary devices, preventing state propagation into intermediate domains. In-band control communication is realized using Open vSwitch’s Nicira extensions with NSH encapsulation, and neighbor discovery is accomplished via Controller Advertisement messages. The approach requires no switch firmware modifications and incurs flow table overhead independent of the number of controllers, maintaining constant space complexity. Experiments in a Mininet environment with 96 switches and 5 controllers demonstrate that internal switches exhibit fixed flow table occupancy, enabling network scalability to hundreds of nodes with controller discovery convergence times on the order of seconds.
This work addresses the challenges of in-band SDN control planes in resource-constrained wide-area telecommunication networks, including autonomous bootstrap, source routing, sub-50ms failure recovery, and multi-controller coordination. The authors propose Periplus, a system that embeds a forwarding graph—encoding both primary and per-hop backup paths—into L2/L3 packet headers. This design enables controller-independent local failover within 50 milliseconds and facilitates switch bootstrap with minimal flow table overhead. Notably, only two switches require initial configuration, eliminating network-wide flooding during provisioning. Flow table occupancy is decoupled from network size, scaling only at nodes that encode multipath information. Experimental evaluation using Ryu and Open vSwitch (augmented with Nicira extensions for NSH encapsulation) demonstrates Periplus’s capabilities in rapid recovery, scalable bootstrapping, and efficient resource utilization.
In highly dynamic multimodal transportation environments, conventional centralized control architectures struggle to meet the stringent requirements of low latency, high reliability, and scalability in communication. This work proposes a hierarchical distributed architecture that integrates Software-Defined Networking (SDN) with Multi-access Edge Computing (MEC), combining regional coordination with edge autonomy to enable local failover and adaptive interface management, thereby eliminating dependence on a central node. Experimental results demonstrate that the control-plane communication and flow establishment latency between the designed edge SDN controllers and Pods are significantly lower than those of existing approaches, confirming the proposed architecture’s superior efficiency and practicality.
该研究使用软件定义网络(SDN)技术设计校园网的核心层,通过RouteFlow平台和OSPF协议提高网络的可用性和路由效率。
This study addresses the frequently overlooked role of SDN controller runtimes in Moving Target Defense (MTD), which significantly constrains the performance trade-off between address shuffling and flow table installation. We port CPAM logic to Ryu, OpenDaylight, and ONOS, quantitatively evaluating their resource overhead and responsiveness in a 500-node network based on RFC 8456 benchmarks. Our findings reveal that controller selection constitutes a first-order design decision for MTD: ONOS achieves low latency with minimal CPU utilization, whereas Ryu exhibits a small memory footprint but incurs a hundredfold increase in round-trip time, while all three maintain near-zero packet loss. This work provides the first systematic quantification of runtime-specific performance trade-offs, offering critical empirical evidence to guide controller deployment in MTD architectures.