ProvGuard: Detecting SDN Control Policy Manipulation via Contextual Semantics of Provenance Graphs

Ziwen Liu

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Network Security 2

Overview

This article delves into "ProvGuard," a novel system designed to detect subtle control policy manipulations (CPM) within Software-Defined Networks (SDN). Presented by Ziwen Liu at the NDSS Symposium, this work introduces a system-centric approach that leverages provenance graphs and contextual semantics to monitor SDN controllers. The talk highlights a critical gap in existing SDN security mechanisms: while SDN's flexibility offers significant advantages, it also creates new avenues for attackers to manipulate network behavior in ways that traditional policy verification or anomaly detection systems often miss.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to SDN vulnerabilities and problem
  2. 2:15 Limitations of existing SDN attack detection methods
  3. 3:05 Introducing provenance graphs for SDN control plane analysis
  4. 3:55 Key challenges: long-running attacks and huge graphs
  5. 4:55 ProvGuard's overall approach: provenance, semantics, detection
  6. 5:55 Constructing provenance graphs using execution units
  7. 7:25 Using contextual semantics in paths for attack detection

ProvGuard: Detecting SDN Control Policy Manipulation via Contextual Semantics of Provenance Graphs

Speakers: Ziwen Liu

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=4-2QiQIXUck

Overview

This article delves into "ProvGuard," a novel system designed to detect subtle control policy manipulations (CPM) within Software-Defined Networks (SDN). Presented by Ziwen Liu at the NDSS Symposium, this work introduces a system-centric approach that leverages provenance graphs and contextual semantics to monitor SDN controllers. The talk highlights a critical gap in existing SDN security mechanisms: while SDN's flexibility offers significant advantages, it also creates new avenues for attackers to manipulate network behavior in ways that traditional policy verification or anomaly detection systems often miss.

The talk underscores the importance of viewing an SDN controller as a complex software system, where malicious intent might not manifest as direct policy changes but rather as a series of legitimate-looking operations that collectively achieve a harmful outcome. ProvGuard addresses this by tracing the causal dependencies of operations within the controller, providing a deeper understanding of how data plane messages influence control plane state. This innovative perspective is crucial for bolstering the security posture of modern, flexible network architectures, offering a robust defense against sophisticated, stealthy attacks.

Background

▶ Watch: Introduction to SDN vulnerabilities and problem (0:00)

Software-Defined Networking (SDN) revolutionized network management by decoupling the control plane from the data plane. This separation grants network operators unprecedented flexibility in configuring and managing network resources programmatically. However, as the speaker notes, "flexibility is also attackers' flexibility." This inherent adaptability opens new attack surfaces, allowing malicious actors to manipulate the control plane through various means, such as faking IP addresses to inject incorrect network information, modifying or deactivating network forwarding rules, or subtly altering security policies.

Existing defensive approaches to detect Control Policy Manipulation (CPM) typically fall into a few categories, each with limitations. Anomaly detection methods often establish rules for what constitutes regular OpenFlow rules. While effective against direct rule changes, these methods falter when attacks don't involve explicit OpenFlow rule modifications. Many sophisticated attacks instead affect the control plane's internal state through other packets or exploit software bugs and vulnerabilities, which remain undetected by rule-based systems. Another line of defense, policy verification, validates whether policies on the control plane are in a "good shape." However, this approach is insufficient for attacks that leverage regular network functionalities, such as link fabrication, where legitimate operations are used for malicious purposes without violating predefined policies.

The fundamental challenge identified by the researchers is that CPM often occurs not through direct policy alterations but through a sequence of "contextual operations" within the controller's software. Recognizing that an SDN controller is essentially "just another software system," the team drew upon their experience in system and software security. They realized that the controller's operations provide critical insights into network state changes and policy evolution. This led to the hypothesis that provenance graphs — which describe the causal dependencies between functions within a software system — could be effectively applied to SDN controllers to reveal hidden malicious behaviors. The main challenge then became how to extract meaningful features from potentially long-running CPM attacks, which generate vast amounts of operational data, without creating unmanageably large and blurred provenance graphs.

Key Findings

▶ Watch: Introducing provenance graphs for SDN control plane analysis (3:05)

ProvGuard's development and evaluation yielded several significant findings that underscore its efficacy and the validity of its core principles:

  • Effective Detection of Subtle Attacks: ProvGuard successfully captures the nuanced features of control plane operations, outperforming existing solutions in detecting four distinct types of typical CPM attacks. This validates the core idea that operational context, as revealed through provenance graphs, provides the necessary semantics to identify malicious behaviors that evade traditional detection methods.
  • Resilience to Noise and Scalability: The system demonstrated strong resilience to injected noise and proved stable across different network scales. The algorithm effectively selects core signals from a high volume of events, ensuring that crucial attack indicators are not obscured by irrelevant data, even in complex or large-scale SDN environments.
  • Contribution of Contextual Semantics: The research confirmed that the depth of contextual information significantly impacts detection accuracy. As the "window of operations" (i.e., the amount of context considered) increases, ProvGuard's accuracy improves, highlighting the critical role of understanding the broader operational sequence rather than isolated events.
  • Reduced Investigator Workload: ProvGuard substantially reduces the manual review workload for security investigators. The system identifies a small, critical portion of edges within the provenance graph that require human analysis, allowing automated processes to handle the majority of events and significantly streamlining the incident response process.
  • Performance Metrics: While demonstrating high detection capabilities, the system's performance metrics indicate practical overheads. The average runtime overhead for an instrumented controller ranged between 18% and 24% compared to an uninstrumented one. Storage overhead for logs was approximately 1.3 GB per hour. The speaker acknowledged that while the storage overhead is "a bit high," there is significant scope for further optimization.

These findings collectively establish ProvGuard as a promising new direction for enhancing SDN security, offering a robust method to detect sophisticated, stealthy attacks that manipulate the control plane through indirect means.

Technical Deep Dive

▶ Watch: Key challenges: long-running attacks and huge graphs (3:55)

ProvGuard's technical foundation lies in its innovative use of provenance graphs to model the internal operations of SDN controllers and detect deviations from normal behavior. The entire process can be broken down into three main phases: provenance collection, graph construction, and semantic deviation evaluation.

1. Provenance Collection:

The initial step involves instrumenting the SDN controller's source code to gather detailed logs of its internal operations. For the prototype, the researchers targeted the Floodlight SDN controller, which is Java-based. This required analyzing the Java source code to identify specific instrumentation points. These points are strategically chosen to capture events related to data plane message operations and their subsequent impact on the control plane. The goal is to collect enough granular information to describe the controller's behavior comprehensively, including method calls, data accesses, and inter-thread communications.

2. Provenance Graph Construction:

Building a meaningful provenance graph from raw logs presents significant challenges, primarily due to the sheer volume and complexity of events in a long-running software system like an SDN controller.

  • Challenge 1: Event Volume and Noise: Logs contain "many, many events," but only a "few events" are directly related to key operations that can affect the control plane. A naive graph construction would be overwhelmingly large and noisy.
  • Challenge 2: State Blow-up and Mixed Data Flows: SDN controllers are often multi-threaded. If all operations from different threads are simply merged into a single graph, data flows can become mixed, leading to a state explosion and obscuring causal dependencies.

ProvGuard addresses these challenges with several key techniques:

  • Execution Units: To manage complexity and prevent data flow mixing, the system identifies execution units. In a multi-threaded Java application like Floodlight, each thread is treated as an execution unit. This partitioning prevents the "state blown up" scenario by isolating data flows within their respective threads.
  • Execution Unit Graph Construction: For each execution unit, a sub-graph is constructed, detailing its internal operations and data dependencies.
  • Inter-Unit Connection: Dependencies and connections between different execution units are then identified. This includes instances where threads share attributes or exchange data, forming crucial links across the system.
  • Edge Reduction: To combat noise and focus on critical information, unnecessary edges are systematically reduced. The focus is on retaining only those edges directly related to data flow operations that have a potential impact on the control plane, ensuring that "our key message is not hidden among a lot of noises."
  • Path Extraction and Representation: The final step in graph construction involves extracting meaningful paths. These are not just arbitrary sub-graphs but rather connected paths that associate attributes and data from different execution units. These paths represent a "long chain or long path of operations" that specifically capture data operations with an impact on the control plane. This representation is crucial for capturing the contextual semantics of controller behavior.

3. Semantic Deviation Evaluation:

With the provenance paths constructed, ProvGuard proceeds to evaluate semantic deviations to detect suspicious behaviors. The core idea here is borrowed from research in graph processing: "the neighbor nodes provides the context to review its semantics." In ProvGuard, this translates to using the context within the extracted paths to define the semantics of specific operations.

  • Contextual Semantics: Instead of just looking at individual operations or fixed-hop graph features (which are "not good enough to reflect the similarity"), ProvGuard leverages the sequence and context of operations within a path. This contextual information provides a rich semantic understanding of what the controller is doing.
  • Anomaly Detection: By comparing the semantics of current operational paths against established baselines of normal behavior, ProvGuard identifies deviations. These deviations, particularly when they form specific patterns within the contextual paths, are indicative of malicious control policy manipulation. The system can thus detect "hidden semantics" that would be invisible to simpler rule-based or policy-validation approaches.

This multi-faceted approach, from granular instrumentation to intelligent graph construction and contextual semantic analysis, allows ProvGuard to build a sophisticated understanding of an SDN controller's behavior, enabling the detection of even the most subtle and indirect forms of attack.

Demo / Proof of Concept

▶ Watch: Constructing provenance graphs using execution units (5:55)

The practical implementation and evaluation of ProvGuard were crucial to validating its theoretical underpinnings. The researchers prototyped the system on the Floodlight SDN controller, a popular open-source Java-based controller. This involved performing the necessary instrumentation of Floodlight's source code to enable the collection of detailed operational logs, as described in the technical deep dive.

For network simulation and data generation, the team utilized Mininet, a widely used network emulator for SDN research. Mininet allowed them to create virtual network topologies and generate both normal network traffic and specific attack scenarios. During the data collection phase, logs were gathered under two conditions:

  1. Normal Operations: Data representing legitimate, benign network activity and controller behavior.
  2. Attack Scenarios: Data reflecting the execution of four typical types of Control Policy Manipulation (CPM) attacks. While the specific nature of these four attacks isn't detailed in the transcript, their inclusion demonstrates the system's ability to tackle various attack vectors.

The evaluation focused on several key aspects:

  • Detection Effectiveness: How accurately ProvGuard could identify the four types of CPM attacks. The results showed that ProvGuard effectively captured malicious features and performed better than other existing solutions.
  • Noise Reduction Effectiveness: The impact of ProvGuard's noise reduction techniques was assessed, demonstrating that the algorithm's selection of core signals remained stable even when significant noise was injected into the system.
  • Contribution of Contextual Semantics: The researchers investigated how varying the "windows of operations" (i.e., the amount of context considered) affected detection accuracy. They found that more context led to greater accuracy, confirming the importance of their semantic approach.
  • Workload Reduction: The evaluation quantified how much ProvGuard reduced the manual review workload for security investigators, showing that only a small portion of identified events required human intervention.
  • Performance Overhead: Crucially, the system's performance impact was measured, reporting an average runtime overhead of 18-24% and a log storage overhead of 1.3 GB per hour. While acknowledging the storage overhead as "a bit high," the speaker expressed confidence in future optimization possibilities.

This comprehensive evaluation, leveraging a real-world controller (Floodlight) and a standard simulation environment (Mininet), provided concrete evidence of ProvGuard's capabilities in detecting subtle SDN attacks.

Defensive Implications

▶ Watch: Using contextual semantics in paths for attack detection (7:25)

ProvGuard offers several critical insights and actionable strategies for enhancing the defensive posture of Software-Defined Networks:

  1. Beyond Policy and Rules: Defenders must recognize that relying solely on static policy verification or anomaly detection based on OpenFlow rule changes is insufficient. Sophisticated attackers can manipulate the control plane through indirect means, exploiting internal software logic or vulnerabilities without directly altering network policies. ProvGuard highlights the necessity of monitoring the internal state and operational semantics of the SDN controller itself.
  2. Provenance-Based Monitoring: The research strongly advocates for the adoption of provenance-based monitoring systems. By tracing the causal dependencies of operations within the controller, organizations can gain an unprecedented level of visibility into how data plane messages influence control plane logic and network state. This allows for the detection of "hidden semantics" of attacks that would otherwise go unnoticed.
  3. Focus on Internal Data Flows: Security efforts should extend beyond network traffic analysis to include the detailed analysis of internal data flows and execution paths within the SDN controller. Understanding how different "execution units" (e.g., threads) interact and share data is crucial for identifying subtle manipulations.
  4. Generalizable Approach: While ProvGuard was prototyped on the Floodlight controller, the underlying methodology of instrumenting source code, constructing provenance graphs, and analyzing contextual semantics is broadly applicable. Defenders should explore how similar techniques can be adapted to other popular SDN controllers, such as OpenDaylight. Although manual analysis of controller source code for instrumentation points is currently required, the speaker alluded to potential future automation inspired by work on Linux kernel analysis.
  5. Enhancing Existing Systems: ProvGuard's ability to uncover "hidden semantics" can complement and enhance existing security tools. By making these subtle manipulations visible, the information can be fed back into traditional policy-based or rule-based detection systems, making them more robust and comprehensive.
  6. Resource Allocation for Security: While the system introduces performance overhead (18-24% runtime, 1.3 GB/hour storage for logs), this must be weighed against the significant security benefits of detecting advanced, persistent threats. Organizations need to consider allocating sufficient computational and storage resources to implement such deep monitoring capabilities, potentially prioritizing critical segments of their SDN infrastructure for this level of scrutiny.
  7. Proactive Vulnerability Identification: The process of instrumenting and analyzing controller source code for provenance collection can also serve as a proactive measure to identify potential vulnerabilities or obscure interaction points that attackers might exploit.

In essence, ProvGuard pushes the envelope for SDN security by advocating for a deeper, system-level understanding of controller behavior, enabling a more resilient defense against the evolving landscape of network attacks.

Key Takeaways

  • SDN's inherent flexibility, while beneficial for management, also creates new attack surfaces for subtle Control Policy Manipulation (CPM) that can bypass traditional security measures.
  • Existing SDN security solutions, such as simple anomaly detection on OpenFlow rules or policy verification, often fail to detect sophisticated CPM attacks that manipulate internal controller state without direct policy changes.
  • ProvGuard introduces a novel, system-centric approach that leverages provenance graphs and contextual semantics to trace and understand the causal dependencies of operations within SDN controllers.
  • By instrumenting controller source code (e.g., Floodlight) and analyzing "execution units" (threads), ProvGuard constructs detailed operational paths that reveal how data plane messages impact control plane logic.
  • The system's ability to derive contextual semantics from these paths is critical for accurately distinguishing malicious behavior from normal operations, leading to effective detection of four types of CPM attacks.
  • ProvGuard, prototyped with Mininet, significantly reduces the manual workload for security investigators and demonstrates manageable performance overhead (18-24% runtime, 1.3 GB/hour storage), with potential for further optimization.

About the Speaker(s)

Ziwen Liu is the speaker who presented the work on ProvGuard. While specific institutional affiliations are not detailed in the provided transcript, the presentation indicates a strong background and expertise in applying system-level approaches to network security. Ziwen Liu's research focuses on detecting control policy violations through sophisticated software methods, drawing on extensive experience in software systems and system security domains. The work presented is a collaboration, suggesting a team effort in bringing this advanced security solution to fruition. The speaker's insights highlight a deep understanding of both SDN architecture and the intricacies of software-based attack vectors, bridging the gap between traditional software security and modern network security challenges.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Legitimate academic systems-security work applied to an underserved problem — SDN controller-internal attack detection via provenance graphs. The core idea is sound and the contribution is real, but the scope is narrow (single controller, simulated environment), the overhead numbers are uncomfortable, and the threat model leans heavily on a world where attackers already have meaningful controller-adjacent access.

Heather Calloway (CISO) — WEAK

Technically credible research on SDN controller integrity that belongs in a systems security venue — which is exactly where it was presented. The work is real and the threat class is legitimate, but this talk has no governance angle, no institutional accountability frame, and no path for operators who don't run Floodlight in a lab.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025