International Journal of Computer Science and Technology

ISSN 2996-8223

International Journal of Computer Science and Technology | Vol. 1, No. 6, June 2020 | pp. 41–48

Research Article

Title: Performance Evaluation of Software-Defined Networking Controllers Under Distributed Denial-of-Service Attacks

Names of Authors: Lucas Silva¹, Gabriel Santos², and Mariana Costa³

Authors’ Affiliations:
¹Department of Computer Science, University of São Paulo, São Paulo, Brazil
²Department of Computer Engineering, Federal University of Rio de Janeiro, Rio de Janeiro, Brazil
³Department of Telecommunications, State University of Campinas, Campinas, Brazil

Abstract: Software-Defined Networking (SDN) decouples the control plane from the data plane, centralizing network intelligence and flow management within a programmable controller. While this architecture provides unprecedented flexibility and administrative control, the centralized controller represents a high-value target for distributed denial-of-service (DDoS) attacks, particularly packet-in flooding that saturates control channel bandwidth and processing queues. Evaluating the resilience and operational thresholds of different SDN controllers under high-intensity attack scenarios is essential for enterprise deployment safety. This research provides a comparative performance evaluation of three prominent open-source SDN controllers: ONOS, Ryu, and Floodlight, subjected to simulated TCP SYN flood and UDP flooding attacks. Testbed experiments measure performance degradation across multiple indicators, including maximum throughput measured in megabits per second (Mbps), control plane packet-in processing latency measured in milliseconds (ms), CPU utilization percentage, and packet drop ratio. Experimental findings reveal that ONOS exhibits superior clustering resilience, maintaining stable control packet handling under flood rates up to 50,000 requests/sec before experiencing severe queue congestion. Ryu demonstrates high agility in low-to-medium traffic profiles but encounters rapid resource exhaustion during sustained multi-vector saturation. Furthermore, the study analyzes the mitigation efficiency of an integrated sFlow-based anomaly detection module capable of dynamically installing drop rules on OpenFlow switches. The insights offer practical benchmarks for network architects designing robust, attack-resilient programmable network fabrics.

Keywords: Software-defined networking, SDN controllers, DDoS attacks, Network security, Performance evaluation, OpenFlow

Manuscript Timeline: Received: March 18, 2020; Revised: April 25, 2020; Accepted: May 18, 2020; Published: June 1, 2020

Citation: Silva, L., Santos, G., & Costa, M. (2020). Performance evaluation of software-defined networking controllers under distributed denial-of-service attacks. International Journal of Computer Science and Technology, 1(6), 41–48. DOI: 10.46882/2020/IJCST/000006