MARATTO

article · Journal of Applied Science and Technology Trends

A MITRE ATT&CK based Threat Modeling and QuantitativeRisk Assessment Framework for Software-Defined Networking

2026Open accessCadi Ayyad University

In plain language

Software-Defined Networking separates network control from data traffic, but its centralised software controller creates critical security vulnerabilities, particularly to denial-of-service disruptions. To address these vulnerabilities, a threat modelling framework has been developed using the MITRE ATT&CK knowledge base. The methodology applies Data Flow Diagrams to map attack surfaces and trust boundaries, linking identified risks directly to realistic adversary tactics. Threats are then prioritised using an Annualized Loss Expectancy model to quantify potential financial impacts, alongside proposed mitigation strategies. Evaluation of the framework shows that data exposure targeting the controller, network flow disruption, and controller impersonation represent the most severe risks. In addition, the analysis highlights Initial Access, Defense Evasion, and Impact as the most frequent categories of adversary tactics, providing a structured mechanism to target and remediate software-defined network vulnerabilities.

Key takeaways

  • A threat modelling framework integrates the MITRE ATT&CK database with Data Flow Diagrams to identify vulnerabilities in Software-Defined Networking.
  • Quantitative assessment using Annualized Loss Expectancy identifies data exposure, network flow disruption, and controller impersonation as the highest-risk threats.
  • Mapping threats to adversary tactics demonstrates that Initial Access, Defense Evasion, and Impact are the most prevalent threat categories targeting SDN environments.

Why it matters

Centralised network control architectures are increasingly vital for modern digital infrastructure, yet their central controllers present enticing single points of failure for cyber attacks. By quantifying potential financial losses and categorising specific attacker behaviours, this approach enables network managers to direct defensive resources and mitigations toward the most damaging and probable threats before outages or data breaches occur.

Commercialisation angle

The framework provides an applied risk assessment tool for network operators, enterprise security teams, and telecommunication providers managing software-defined network infrastructure. It enables organisations to evaluate financial exposure and select targeted mitigation strategies based on real attacker tactics. The abstract presents a tested analytical model evaluated with specific cost figures, placing the work at an applied research stage that could inform future network auditing software or automated security management products.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

Software-Defined Networking (SDN) has emerged as a programmable networking paradigm that separates the control and data planes, enabling flexible and centralized network management while introducing new security challenges due to its software-based control architecture. However, this centralization of control, while advantageous, also introduces new vulnerabilities. The SDN controller, the heart of the architecture, can become a prime target for attacks, particularly Distributed Denial-of-Service (DDoS) attacks. These attacks aim to overload the controller with a massive flood of malicious requests, causing performance degradation, loss of connectivity, or even complete network paralysis. This paper proposes a threat modeling framework for SDN based on the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework, developed by the MITRE Corporation, a non-profit organization that operates federally funded research and development centers (FFRDCs). The framework models adversarial tactics and techniques to identify, analyze, and prioritize security threats targeting SDN environments. A Data Flow Diagram (DFD) is used to identify attack surfaces and trust boundaries, and identified threats are mapped to MITRE ATT&CK to reflect realistic attacker behavior. A quantitative risk assessment based on the Annualized Loss Expectancy (ALE) model is then applied to prioritize threats according to their potential impact. Finally, appropriate mitigation strategies are proposed to enhance the security and resilience of SDN environments. The results indicate that controller impersonation (ALE = €7,500), data exposure targeting the SDN controller (ALE = €10,000), and network flow disruption (ALE = €9,000) represent the highest-risk threats. Furthermore, MITRE ATT&CK mapping reveals that Initial Access, Defense Evasion, and Impact are the most prevalent adversarial tactic categories, demonstrating the effectiveness of the proposed framework in identifying, prioritizing, and mitigating critical SDN security risks.

Research topics

  • Software-Defined Networks and 5G
  • Network Security and Intrusion Detection
  • Information and Cyber Security

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.38094/jastt71896

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.