Jadwal Sholat

Memuat jadwal sholat…

Ilmu Komputer & AI editorial

Open AccessOA2026

Rethinking Software-Defined Networking Link Discovery with Dynamic Randomization

ChameleonDisc: A Moving-Target Defense Against Topology-Poisoning Attacks in SDN
Mingming Chen; Teryl Taylor; Frederico Araujo; Benjamin E. Ujcich; Thomas La Porta; Trent Jaeger· 2026· DOI 10.48550/arXiv.2609.14805

The core problem

Software-defined networking (SDN) separates the control and data planes, enabling programmable, centralized network management. A core SDN service is topology discovery — a periodic process that identifies network links. The authors analyze five open-source SDN controllers and ten discovery protocols, finding that all remain vulnerable to at least one form of link-fabrication attack. The common root cause is their reliance on traditional Link Layer Discovery Protocol (LLDP) packets, whose static identifiers expose their discovery purpose and attract adversaries to exploit them. This work proposes ChameleonDisc, a dynamic link-discovery protocol that simultaneously prevents and detects topology-poisoning attacks by eliminating this root cause. The key insight is that an SDN controller can infer topology without embedding meaningful information in discovery packets. ChameleonDisc removes targetable static LLDP signatures and employs a moving-target defense that combines decoy, obfuscation, and camouflage techniques instantiated dynamically at runtime to prevent topology poisoning and detect manipulation.

Innovation

On a 252-link topology, ChameleonDisc achieves median convergence of 1.37–4.53 s for legitimate link changes and 4.06 s for malicious relay detection. The additional mean CPU overhead is 13.0 percentage points, with negligible retained-heap difference. Across topologies up to 816 links, the protocol provides a tunable security–performance trade-off; expanding discovery intervals reduces CPU and mapping state at the cost of increased attack-detection latency. The implementation demonstrates effectiveness against all identifier-based topology-poisoning attacks. The following Mermaid diagram illustrates the high-level architecture of ChameleonDisc within an SDN controller:
Software-defined networking (SDN) separates the control and data planes, enabling programmable, centralized network management. A core SDN service is topology discovery — a periodic process that identifies network links. The authors analyze five open-source SDN controllers and ten discovery protocols, finding that all remain vulnerable to at least one form of link-fabrication attack. The common root cause is their reliance on traditional Link Layer Discovery Protocol (LLDP) packets, whose static identifiers expose their discovery purpose and attract adversaries to exploit them. This work proposes ChameleonDisc, a dynamic link-discovery protocol that simultaneously prevents and detects topology-poisoning attacks by eliminating this root cause. The key insight is that an SDN controller can infer topology without embedding meaningful information in discovery packets. ChameleonDisc removes targetable static LLDP signatures and employs a moving-target defense that combines decoy, obfuscation, and camouflage techniques instantiated dynamically at runtime to prevent topology poisoning and detect manipulation.

ChameleonDisc is implemented on the OpenDaylight controller. The protocol replaces static LLDP identifiers with dynamically generated, randomized fields that carry no semantic meaning to an adversary. At runtime, the controller instantiates a moving-target defense composed of three techniques: decoy, obfuscation, and camouflage. These are combined to prevent topology poisoning and to detect manipulation attempts. The design is evaluated on a 252-link topology, measuring median convergence time for legitimate link changes and for malicious relay detection, along with CPU overhead and retained-heap difference. The evaluation is extended across topologies up to 816 links to characterize a tunable security–performance trade-off. The core mechanism can be abstracted as follows: for each discovery interval, the controller generates a random mapping

that transforms packet fields, such that an adversary observing a packet cannot infer its discovery role. The mapping is refreshed at runtime, ensuring that static signatures are never exposed.

Why it matters

The results indicate that eliminating static LLDP signatures is an effective strategy against topology-poisoning attacks. The moving-target defense, instantiated dynamically at runtime, prevents adversaries from identifying discovery packets and thus from crafting targeted link-fabrication attacks. The tunable trade-off between security and performance allows network operators to balance detection latency against resource consumption. The 13.0 percentage point CPU overhead is modest given the security benefits, and the negligible heap difference suggests that the approach is memory-efficient. The protocol's ability to detect malicious relays within 4.06 s on a 252-link topology demonstrates practical viability. Future work may explore extending the approach to other SDN protocols and larger-scale deployments. The core insight — that topology can be inferred without embedding meaningful information in discovery packets — challenges traditional assumptions in SDN link discovery and opens avenues for further research in moving-target defenses for network control planes.

Who should read this

CS practitioners and researchers

Opening member content…