Maximizing SDN Resilience to Node‐Targeted Attacks—A Game‐Theoretic Approach
Michał Pióro, Mariusz Mycek, Artur Tomaszewski, Konstanty Junosza‐Szaniawski, Dariusz NogalskiABSTRACT
This paper studies a strategic conflict between two players—a telecommunications network operator seeking to maximize network availability after an attack and an attacker seeking to minimize it—using a game‐theoretic framework. The analysis focuses on software‐defined networking (SDN), where the separation of the transport and control planes introduces a critical vulnerability: transport switches must maintain connectivity to controllers located at selected nodes in order to operate. Following an attack, switches (and any co‐located controllers) at targeted nodes are disabled together with their transport links. As a consequence, not only directly attacked switches fail, but also those that lose connectivity to operational controllers, further reducing network availability. This setting gives rise to a zero‐sum matrix game in which the operator selects controller placements while the attacker chooses attack targets, with each player unaware of the other's decision. The payoff of the game is the number of surviving switches (for the operator) and the number of disabled switches (for the attacker), and both players adopt mixed strategies, represented by optimized decision probability distributions. To compute these strategies, we develop a column‐generation optimization framework based on a primal–dual pair of non‐compact linear programming formulations. Controller placements and attack sets are generated via integer programming pricing problems. The resulting method remains computationally efficient even for large‐scale networks with a vast number of possible placement and attack combinations. The proposed approach has been implemented and tested on two representative network instances. The results demonstrate both the effectiveness of the game model and the computational efficiency and scalability of the solution method.