Title: Research on flow table overflow attacks in software defined networks based on machine learning

Authors: Dawei Li; Chuntao Li; Yingze Ye; Mingxuan Guo

Addresses: Informatisation Office, Wuhan Textile University, Wuhan, Hubei, China ' Basic Science Department, Wuchang Shouyi University, Wuhan, Hubei, China ' Network Security and Informatisation, Huazhong Agricultural University, Wuhan, Hubei Province, China ' Equipment Management Department Automation Section, Wuhan Iron and Steel Co., Ltd., Wuhan, Hubei, China

Abstract: SDN switches have limited flow table capacity and are vulnerable to flow table overflow attacks. This paper proposes a method named FTsec to protect SDN switches, which analyses flow table entries based on machine learning to enhance the detection and mitigation capability of attacks. The source address validation method is adopted to locate and block the source of spoofed source address attacks, and correlation between flow table feature and network topology is used to trace the root cause of attack. Experimental results show that FTsec can effectively detect and suppress the flow table overflow attack, significantly reduce the risk of flow table overflow. Especially when dealing with spoofed source address attack, it can limit the average proportion of attack flow table entries to less than 7%. At the same time, the average CPU load is only increased by 1.4%, which shows the feasibility of deploying FTsec in SDN.

Keywords: software defined network; flow table overflow attacks; source address validation; flow table feature.

DOI: 10.1504/IJWMC.2026.155335

International Journal of Wireless and Mobile Computing, 2026 Vol.31 No.1, pp.53 - 64

Received: 14 Oct 2025
Accepted: 16 Dec 2025

Published online: 30 Jul 2026 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article