{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T06:27:05Z","timestamp":1757312825178},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,1,21]],"date-time":"2023-01-21T00:00:00Z","timestamp":1674259200000},"content-version":"vor","delay-in-days":20,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2023,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Programmable networking is evolving from programmable control plane solutions such as OpenFlow-based software-defined networking (SDN) to programmable data planes such as P4-based SDN. To support the functionality of the SDN, the correct view of the network topology is required. However, multiple attacks aimed at topology poisoning have been demonstrated in SDNs. While several controller-centralised security solutions have been proposed to defeat topology poisoning attacks, some attacks e.g., the Data Plane ARP Cache Poisoning Attack and the relay-type Link Fabrication Attack are difficult to detect using a fully centralised security solution. In this paper, we present the Security-Aware Programmable (SECAP) Switch\u2014a lightweight, in-network, P4-based security solution that is designed to prevent attacks that might otherwise evade control plane solutions. The SECAP switch verifies source address details contained within the headers of protocols commonly used to perform topology poisoning attacks. This function is supported by a novel variance-based anomaly detection solution to provide a layered defence. We demonstrate the ability of the SECAP switch to defeat topology poisoning attacks with minimal memory and processing overhead.<\/jats:p>","DOI":"10.1007\/s10922-022-09714-z","type":"journal-article","created":{"date-parts":[[2023,1,21]],"date-time":"2023-01-21T04:43:19Z","timestamp":1674276199000},"update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["SECAP Switch\u2014Defeating Topology Poisoning Attacks Using P4 Data Planes"],"prefix":"10.1007","volume":"31","author":[{"given":"Dylan","family":"Smyth","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sandra","family":"Scott-Hayward","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Victor","family":"Cionca","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sean","family":"McSweeney","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Donna","family":"O\u2019Shea","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,1,21]]},"reference":[{"key":"9714_CR1","first-page":"8","volume":"15","author":"S Hong","year":"2015","unstructured":"Hong, S., Xu, L., Wang, H., Gu, G.: Poisoning network visibility in software-defined networks: new attacks and countermeasures. Ndss 15, 8\u201311 (2015)","journal-title":"Ndss"},{"key":"9714_CR2","first-page":"8","volume":"15","author":"M Dhawan","year":"2015","unstructured":"Dhawan, M., Poddar, R., Mahajan, K., Mann, V.: Sphinx: detecting security attacks in software-defined networks. Ndss 15, 8\u201311 (2015)","journal-title":"Ndss"},{"key":"9714_CR3","first-page":"1","volume-title":"2016 International conference on cyber security and protection of digital services (cyber security)","author":"D Smyth","year":"2016","unstructured":"Smyth, D., Cionca, V., McSweeney, S., O\u2019Shea, D.: Exploiting pitfalls in software-defined networking implementation. In: 2016 International conference on cyber security and protection of digital services (cyber security), pp. 1\u20138. IEEE (2016)"},{"issue":"3","key":"9714_CR4","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1145\/2656877.2656890","volume":"44","author":"P Bosshart","year":"2014","unstructured":"Bosshart, P., Daly, D., Gibb, G., Izzard, M., McKeown, N., Rexford, J., Schlesinger, C., Talayco, D., Vahdat, A., Varghese, G., et al.: P4: programming protocol-independent packet processors. ACM SIGCOMM Comput Commun Rev 44(3), 87\u201395 (2014)","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"9714_CR5","first-page":"277","volume-title":"International conference on human aspects of information security, privacy, and trust","author":"P V\u00f6r\u00f6s","year":"2016","unstructured":"V\u00f6r\u00f6s, P., Kiss, A.: Security middleware programming using p4. In: International conference on human aspects of information security, privacy, and trust, pp. 277\u2013287. Springer (2016)"},{"key":"9714_CR6","doi-asserted-by":"publisher","first-page":"58845","DOI":"10.1109\/ACCESS.2020.2982859","volume":"8","author":"F Hauser","year":"2020","unstructured":"Hauser, F., Schmidt, M., H\u00e4berle, M., Menth, M.: P4-macsec: dynamic topology monitoring and data layer protection with macsec in p4-based sdn. IEEE Access 8, 58845\u201358858 (2020)","journal-title":"IEEE Access"},{"key":"9714_CR7","first-page":"415","volume-title":"26th USENIX security symposium","author":"S Jero","year":"2017","unstructured":"Jero, S., Koch, W., Skowyra, R., Okhravi, H., Nita-Rotaru, C., Bigelow, D.: (2017) Identifier binding attacks and defenses in software-defined networks. In: 26th USENIX security symposium, pp. 415\u2013432. USENIX Security (2017)"},{"issue":"8","key":"9714_CR8","doi-asserted-by":"publisher","first-page":"5971","DOI":"10.1109\/JIOT.2021.3062886","volume":"9","author":"J Wang","year":"2021","unstructured":"Wang, J., Liu, J.: Location hijacking attack in software-defined space-air-ground-integrated vehicular network. IEEE Internet Things J 9(8), 5971\u20135981 (2021)","journal-title":"IEEE Internet Things J"},{"key":"9714_CR9","doi-asserted-by":"crossref","unstructured":"Smyth, D., McSweeney, S., O\u2019Shea, D., Cionca, V.: Detecting link fabrication attacks in software-defined networks. http:\/\/www.smythtech.net\/slides\/Detecting_LFA_in_SDN_Softfire_2018.pdf","DOI":"10.1109\/ICCCN.2017.8038435"},{"key":"9714_CR10","unstructured":"Floodlight, P.: Floodlight. https:\/\/github.com\/floodlight\/floodlight"},{"key":"9714_CR11","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1145\/2491185.2491220","volume-title":"Proc of the second ACM SIGCOMM workshop on hot topics in software defined networking","author":"S Shin","year":"2013","unstructured":"Shin, S., Gu, G.: Attacking software-defined networks: a first feasibility study. In: Proc of the second ACM SIGCOMM workshop on hot topics in software defined networking, pp. 165\u2013166. ACM (2013)"},{"key":"9714_CR12","first-page":"1","volume-title":"2017 26th International conference on computer communication and networks (ICCCN)","author":"D Smyth","year":"2017","unstructured":"Smyth, D., McSweeney, S., O\u2019Shea, D., Cionca, V.: Detecting link fabrication attacks in software-defined networks. In: 2017 26th International conference on computer communication and networks (ICCCN), pp. 1\u20138. IEEE (2017)"},{"key":"9714_CR13","volume-title":"Proc of the 40th conference on local computer networks (LCN)","author":"T Alharbi","year":"2015","unstructured":"Alharbi, T., Portmann, M., Pakzad, F.: The (in) security of topology discovery in software defined networks. In: Proc of the 40th conference on local computer networks (LCN). IEEE (2015)"},{"key":"9714_CR14","first-page":"1","volume-title":"2019 IEEE conference on network function virtualization and software defined networks (NFV-SDN)","author":"B Lewis","year":"2019","unstructured":"Lewis, B., Broadbent, M., Race, N.: P4id: P4 enhanced intrusion detection. In: 2019 IEEE conference on network function virtualization and software defined networks (NFV-SDN), pp. 1\u20134. IEEE (2019)"},{"key":"9714_CR15","unstructured":"Open Networking lab: ONOS. https:\/\/github.com\/opennetworkinglab\/onos"},{"key":"9714_CR16","first-page":"1","volume-title":"2019 ACM\/IEEE symposium on architectures for networking and communications systems (ANCS)","author":"B O\u2019Connor","year":"2019","unstructured":"O\u2019Connor, B., Tseng, Y., Pudelko, M., Cascone, C., Endurthi, A., Wang, Y., Ghaffarkhah, A., Gopalpur, D., Everman, T., Madejski, T., et al.: Using p4 on fixed-pipeline and programmable stratum switches. In: 2019 ACM\/IEEE symposium on architectures for networking and communications systems (ANCS), pp. 1\u20132. IEEE (2019)"},{"key":"9714_CR17","unstructured":"P4 Language Consortium: P4 behaviour model reference switch. P4 Language Consortium. https:\/\/github.com\/p4lang\/behavioral-model Accessed Aug 2022"},{"key":"9714_CR18","unstructured":"Inc., D.: What is docker? https:\/\/www.docker.com\/what-docker"},{"key":"9714_CR19","unstructured":"Foundation, O.N.: ONOS overview. https:\/\/opennetworking.org\/onos\/"},{"key":"9714_CR20","unstructured":"Project, S.: Scapy. https:\/\/scapy.net\/"},{"key":"9714_CR21","doi-asserted-by":"crossref","unstructured":"Gao, S., Handley, M., Vissicchio, S.: Stats 101 in p4: towards in-switch anomaly detection. In: Proceedings of the twentieth ACM workshop on hot topics in networks, pp. 84\u201390. (2021)","DOI":"10.1145\/3484266.3487370"},{"key":"9714_CR22","doi-asserted-by":"crossref","unstructured":"Datta, R., Choi, S., Chowdhary, A., Park, Y.: P4guard: designing p4 based firewall. In: MILCOM 2018-2018 IEEE military communications conference (MILCOM), pp. 1\u20136. IEEE (2018)","DOI":"10.1109\/MILCOM.2018.8599726"},{"key":"9714_CR23","doi-asserted-by":"crossref","unstructured":"Ndonda, G.K., Sadre, R.: A two-level intrusion detection system for industrial control system networks using p4. In: 5th International symposium for ICS & SCADA cyber security research 2018, pp. 31\u201340 (2018)","DOI":"10.14236\/ewic\/ICS2018.4"},{"issue":"1","key":"9714_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10922-021-09633-5","volume":"30","author":"F Musumeci","year":"2022","unstructured":"Musumeci, F., Fidanci, A.C., Paolucci, F., Cugini, F., Tornatore, M.: Machine-learning-enabled ddos attacks detection in p4 programmable networks. J Netw Syst Manag 30(1), 1\u201327 (2022)","journal-title":"J Netw Syst Manag"},{"key":"9714_CR25","doi-asserted-by":"crossref","unstructured":"Sanghi, A., Kadiyala, K.P., Tammana, P., Joshi, S.: Anomaly detection in data plane systems using packet execution paths. In: Proceedings of the ACM SIGCOMM 2021 workshop on secure programmable network infrastructure. pp. 9\u201315 (2021)","DOI":"10.1145\/3472873.3472880"},{"issue":"1","key":"9714_CR26","doi-asserted-by":"publisher","first-page":"510","DOI":"10.1109\/TNSM.2021.3109099","volume":"19","author":"P Shrivastava","year":"2021","unstructured":"Shrivastava, P., Kataoka, K.: Topology poisoning attacks and prevention in hybrid software-defined networks. IEEE Trans Netw Service Manag 19(1), 510\u2013523 (2021)","journal-title":"IEEE Trans Netw Service Manag"},{"issue":"1","key":"9714_CR27","doi-asserted-by":"publisher","first-page":"39","DOI":"10.26599\/TST.2021.9010077","volume":"28","author":"Y Gao","year":"2022","unstructured":"Gao, Y., Xu, M.: Defense against software-defined network topology poisoning attacks. Tsinghua Sci Technol 28(1), 39\u201346 (2022)","journal-title":"Tsinghua Sci Technol"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-022-09714-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-022-09714-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-022-09714-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,2]],"date-time":"2023-02-02T02:16:21Z","timestamp":1675304181000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-022-09714-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1]]},"references-count":27,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,1]]}},"alternative-id":["9714"],"URL":"https:\/\/doi.org\/10.1007\/s10922-022-09714-z","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1]]},"assertion":[{"value":"30 August 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 November 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 December 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 January 2023","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The direction of the work carried out in the paper was not influenced by any third party, nor do the authors of this paper have any conflict of interest in relation to the technologies used.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interest"}},{"value":"Not Applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical Approval"}}],"article-number":"28"}}