RUS  ENG
Full version
JOURNALS // Journal of the Belarusian State University. Mathematics and Informatics // Archive

Journal of the Belarusian State University. Mathematics and Informatics, 2024 Volume 3, Pages 90–102 (Mi bgumi698)

Theoretical foundations of computer science

Methodology for assessing the reliability of software-defined networks under computer attacks

I. V. Kotenkoa, I. B. Saenkoa, O. S. Lautab, S. Y. Skorobogatova, V. P. Kochync

a Saint Petersburg Federal Research Center of the Russian Academy of Sciences, 39, 14th Line V. O., Saint Petersburg 199178, Russia
b Admiral Makarov State University of Maritime and Inland Shipping, 5/7 Dvinskaja Street, Saint Petersburg 198035, Russia
c Belarusian State University, 4 Niezaliezhnasci Avenue, Minsk 220030, Belarus

Abstract: Introduction. An important feature of SDN technology is centralised network management using a controller realised using the OpenFlow control protocol and allowing not only to manage network devices, but also to collect network statistics, which permits to solve emerging network problems more effectively by configuring all network devices simultaneously. The controller is the most vulnerable element, an attack on which can affect the stability of its the entire infrastructure. $\\$ Problem statement. The development of mathematical foundations for assessing SDN stability will allow us to calculate SDN stability indicators using analytical expressions. As the main indicator, it is proposed to use the coefficient of serviceable action for SDN stability. $\\$ Methods. The estimation of SDN stability indicators is carried out using methods of the theory of Markov processes. In order to ensure the stability of the SDN operation, this paper substantiates an algorithm for monitoring the state of controllers and their automatic adjustment. $\\$ Results. A verbal and mathematical formulation of the scientific problem for the study is carried out, and the general problem is decomposed into specific problems, namely, conceptual modelling of the subsystem of intelligent monitoring of the state of the public information and telecommunications network, development of a method for synthesising its subsystem of intelligent monitoring of the state, as well as the formation of scientific and technical proposals for the implementation of this method. $\\$ Practical significance. The proposed methodology makes it possible to estimate the stability of a software-defined network in the conditions of computer attacks characteristic for it, as well as to form general requirements for the protection system using the obtained stability indicators.

Keywords: computer attacks; stability; software-defined networks; Markov chains

UDC: 002.6, 004.7, 004.722

Received: 08.08.2024
Revised: 23.10.2024
Accepted: 23.10.2024



© Steklov Math. Inst. of RAS, 2026