VLDB 2026 Research / reviewers in the wild / expert
Shuhua Deng
dblp:211/8515
· DBLP profile ↗
10ranked-venue papers
7as first author
7since 2021 · last 2025
0000-0002-8985-1295ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 first-author · 2 since 2021Security and privacy · 4 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Investigating Vulnerabilities in OpenFlow Discovery Protocol: Novel Attacks and Their DefenseabstractSoftware-defined networking (SDN) enables network visibility and intelligence by providing a global topology view. The controller maintains and updates the real-time topology using the OpenFlow Discovery Protocol (OFDP). However, without robust security mechanisms, OFDP introduces new security threats to the network. This paper investigates the security threats of OFDP packets, focusing specifically on their header fields and data units. We propose novel methods to implement existing attacks and bypass current defenses. In addition, we identify two new vulnerabilities that allow for the manipulation of link information and the exhaustion of network resources. Through a series of experiments, we demonstrate the feasibility of these attacks. Our findings have been responsibly disclosed to Floodlight, and two CVEs ( CVE-2024-57672 and CVE-2024-57673) were assigned. To defend against such attacks, we designLOFDPto enhance the security of OFDP by thoroughly inspecting the header fields and encrypting the data units. As a lightweight extension of existing controllers,LOFDPcan filter malformed packets to prevent attacks, balancing scalability and security. We implement a prototype ofLOFDPand evaluate its effectiveness and performance in a simulated environment. The results show thatLOFDPcan effectively prevent attacks with negligible latency. Shuhua Deng, Zhangping Yin, Xieping Gao 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Vulnerabilities in SDN Topology Discovery Mechanism: Novel Attacks and CountermeasuresabstractSoftware-defined networking (SDN) has significantly enriched network functions by separating the control plane from the data plane. Meanwhile, the unique architecture of SDN brings new security challenges. Recent studies show that attackers can fabricate inter-switch links to hijack the traffic or interfere with network services. In this paper, we uncover two new vulnerabilities that can tamper with the topology view of the SDN controller. Then, we present two novel attacks named Cluster Splitting and Cluster Amnesia according to such flaws. We split or forget partial network topology by establishing a broadcast domain port or external link. As a result, it affects the module responsible for computing topology instances and disrupts the routing calculations. To defend against such attacks, we design a two-stage algorithm to verify the switch port and link in real-time. With the principle of saving the limited control channel resources and not extending the LLDP protocol, we propose LldpChecker. As a lightweight extension for SDN controllers, it can filter malicious broadcast domain ports and external links. We conduct a series of experiments to evaluate the effectiveness and efficiency of LldpChecker. The results show that LldpChecker can effectively mitigate these two novel attacks with negligible overhead. Shuhua Deng, Wenjie Dai, Xian Qing, Xieping Gao 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Poisoning Topology View in Software-Defined Vehicular Network: An Empirical StudyabstractThe development of the vehicular ad-hoc network (VANET) provides a promising solution to promoting road safety and driving experiences, but it also generates massive data, leading to network configuration and management issues. Fortunately, by integrating software-defined network (SDN) and VANET, a new network paradigm called software-defined vehicular network (SDVN) is proposed to tackle these problems via furnishing centralized control and programmability. With the help of SDN, the centralized controller provides global visibility about network devices and improves the efficiency of various applications. However, the building procedure of global topology also brings new security concerns to the SDVN. In this paper, we comprehensively investigate the security of topology management under a standard SDVN scenario. By exploiting the high mobility of VANET and vulnerabilities in topology management inherited from SDN, we unveil five threats of topology poison in SDVN with lower attack bars. Based on such threats, we propose several attacks to poison the global topology of four mainstream controllers in emulated and real-world environments. Additionally, we present empirical studies to illustrate the impact of these attacks on network communication and topology-based applications. Finally, we discuss the feasibility of these attacks under existing state-of-the-art defense systems. Shuhua Deng, Xieping Gao 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | Manipulating Sensitive Match Fields to Poison Applications in SDNabstractSoftware-Defined Networking (SDN) significantly simplifies the management of networks by deploying various applications. However, the performance gap between the application and the forwarding device brings new security concerns for the network. In this paper, we systematically study the match field defined in the OpenFlow protocol and reveal the vulnerability in the match process of data streams. Then, we propose sensitive field manipulation attacks to saturate the network bottleneck. Furthermore, we investigate the threats to SDN architecture by exploiting such attacks. We demonstrate the feasibility of the attack and evaluate it in a physical environment. To defend against such attacks, we design SFieldDefender to detect malicious probing by training machine learning models. Moreover, we design a multi-policy coordination mechanism to deal with different types of abnormal traffic. Implementations and evaluations demonstrate that SFieldDefender can effectively detect the sensitive field manipulation attack and protect the network core services. Shuhua Deng, Xieping Gao 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyabstractSoftware-Defined Networking (SDN) enables the deployment of diversified networking applications by providing global visibility and open programmability on a centralized controller. As SDN enters its second decade, several well-developed open source controllers have been widely adopted in industry, and various commercial SDN applications are built to meet the surging demand of network innovation. This complex ecosystem inevitably introduces new security threats, as malicious applications can significantly disrupt network operations. In this paper, we introduce a new vulnerability in existing SDN controllers that enable adversaries to create a backdoor and further deploy malicious applications to disrupt network service via a series of topology poisoning attacks. The root cause of this vulnerability is that SDN systems simply process received Packet-In messages without checking the integrity, and thus can be misguided by manipulated messages. We discover that five popular SDN controllers (i.e., Floodlight, ONOS, OpenDaylight, POX and Ryu) are potentially vulnerable to the disclosed attack, and further propose six new attacks exploiting this vulnerability to disrupt SDN services from different layers. We evaluate the effectiveness of these attacks with experiments in real SDN testbeds, and discuss feasible countermeasures. Shuhua Deng, Xian Qing, Xiaofan Li 0009, Xing Gao 0001, Xieping Gao 0001 |
INFOCOM | 1 |
| 2023 | A soft actor-critic reinforcement learning algorithm for network intrusion detection
Zhengfa Li, Chuanhe Huang, Shuhua Deng, Wanyu Qiu, Xieping Gao 0001 |
Comput. Secur. | 3 |
| 2021 | Joint optimization of energy saving and load balancing for data center networks based on software defined networksabstractSummary To meet the surging demand for artificial intelligence and cloud service, data centers have been expanding rapidly on recent years. Therefore, data center networks have received great attention recently and more challenges gradually emerged. The exiting technology of data center networks (DCNs) has presented two problems: high energy consumption and network load imbalance. Traditionally, the middle‐box hardware is dedicated and complexly merged, such as network load balancer and network energy optimizer. As an emerging architecture, software defined networks (SDNs) brings an opportunity to accomplish load balancing and energy optimization simultaneously with its characteristics. In this article, we propose a traffic flow management strategy which jointly considers energy optimization and load balancing. The strategy forwards traffic flows with maximum available bandwidth multipath routing to balance network load. We minimize activated links and switches to save energy by scheduling traffic flows. We jointly formulate these as an integer linear programming (ILP) problem. We propose a heuristic algorithm to handle the problem. The full simulation results reveal the high efficiency of our algorithm and the coexistence of network energy optimization and load balancing. Yihao He, Zebin Lu, Junru Lei, Shuhua Deng, Xieping Gao 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2019 | DoS vulnerabilities and mitigation strategies in software-defined networks
Shuhua Deng, Xing Gao 0001, Zebin Lu, Zhengfa Li, Xieping Gao 0001 |
J. Netw. Comput. Appl. | 1 |
| 2019 | A Self-Adaptive Virtual Network Embedding Algorithm Based on Software-Defined NetworksabstractNetwork virtualization provides a promising tool to allow multiple virtual networks (VNs) to run on a shared substrate network (SN) simultaneously. VN embedding (VNE) is one of the key technologies of network virtualization. The main goal of VNE is to effectively map VN requests to the SN, which is efficiently utilizes the network resources. The emergence of software defined networks provides a platform for network virtualization to be used and promoted. In a real environment, the resource requirements of tenants are generally different. A single VN mapping algorithm can not effectively handle the multi-demand problem of tenants. We propose a self-adaptive VNE algorithm. VN requests are divided into different types by an adaptive algorithm, we use an integer linear programming formulation to solve VNE problem. This paper considers three different types of VN requests. Type 1 VN requests for high bandwidth requirements, type 2 VN requests for low latency requirements, and type 3 VN requests for high bandwidth requirements and latency requirements. The simulation results show that the virtual network embedding algorithm proposed in this paper can make full use of the SN resources and improve the overall revenue, while effectively dealing with the multi-demand problem of tenants. Zhengfa Li, Zebin Lu, Shuhua Deng, Xieping Gao 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2018 | Packet Injection Attack and Its Defense in Software-Defined NetworksabstractSoftware-defined networks (SDNs) are novel networking architectures that decouple the network control and forwarding functions from the data plane. Unlike traditional networking, the control logic of SDNs is implemented in a logically centralized controller which provides a global network view and open programming interface to the applications. While SDNs have become a hot topic among both academia and industry in recent years, little attention has been paid on the security aspect. In this paper, we introduce a novel attack, namely, packet injection attack, in SDNs. By maliciously injecting manipulated packets into SDNs, attackers can affect the services and networking applications in the control plane, and largely consume the resources in the data plane. The consequences could be the disruption of applications built on the top of the topology manager service and rest API, as well as a huge consumption of network resources, such as the bandwidth of the OpenFlow channel. To defend against the packet injection attack, we present PacketChecker, a lightweight extension module on SDN controllers to effectively detect and mitigate the flooding of falsified packets. We implement a prototype of PacketChecker in floodlight controller and conduct experiments to evaluate the efficiency of the defense mechanism. The evaluation shows that the PacketChecker module can effectively mitigate the attack with a minor overhead to the SDN controller. Shuhua Deng, Xing Gao 0001, Zebin Lu, Xieping Gao 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |