Title: Research on flow table overflow attacks in software defined networks based on machine learning
Authors: Dawei Li; Chuntao Li; Yingze Ye; Mingxuan Guo
Addresses: Informatisation Office, Wuhan Textile University, Wuhan, Hubei, China ' Basic Science Department, Wuchang Shouyi University, Wuhan, Hubei, China ' Network Security and Informatisation, Huazhong Agricultural University, Wuhan, Hubei Province, China ' Equipment Management Department Automation Section, Wuhan Iron and Steel Co., Ltd., Wuhan, Hubei, China
Abstract: SDN switches have limited flow table capacity and are vulnerable to flow table overflow attacks. This paper proposes a method named FTsec to protect SDN switches, which analyses flow table entries based on machine learning to enhance the detection and mitigation capability of attacks. The source address validation method is adopted to locate and block the source of spoofed source address attacks, and correlation between flow table feature and network topology is used to trace the root cause of attack. Experimental results show that FTsec can effectively detect and suppress the flow table overflow attack, significantly reduce the risk of flow table overflow. Especially when dealing with spoofed source address attack, it can limit the average proportion of attack flow table entries to less than 7%. At the same time, the average CPU load is only increased by 1.4%, which shows the feasibility of deploying FTsec in SDN.
Keywords: software defined network; flow table overflow attacks; source address validation; flow table feature.
DOI: 10.1504/IJWMC.2026.155335
International Journal of Wireless and Mobile Computing, 2026 Vol.31 No.1, pp.53 - 64
Received: 14 Oct 2025
Accepted: 16 Dec 2025
Published online: 30 Jul 2026 *