A MITRE ATT&CK based Threat Modeling and QuantitativeRisk Assessment Framework for Software-Defined Networking
Software-Defined Networking (SDN) has emerged as a programmable networking paradigm that separates the control and data planes, enabling flexible and centralized network management while introducing new security challenges due to its software-based control architecture. However, this centralization of control, while advantageous, also introduces new vulnerabilities. The SDN controller, the heart of the architecture, can become a prime target for attacks, particularly Distributed Denial-of-Service (DDoS) attacks. These attacks aim to overload the controller with a massive flood of malicious requests, causing performance degradation, loss of connectivity, or even complete network paralysis. This paper proposes a threat modeling framework for SDN based on the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework, developed by the MITRE Corporation, a non-profit organization that operates federally funded research and development centers (FFRDCs). The framework models adversarial tactics and techniques to identify, analyze, and prioritize security threats targeting SDN environments. A Data Flow Diagram (DFD) is used to identify attack surfaces and trust boundaries, and identified threats are mapped to MITRE ATT&CK to reflect realistic attacker behavior. A quantitative risk assessment based on the Annualized Loss Expectancy (ALE) model is then applied to prioritize threats according to their potential impact. Finally, appropriate mitigation strategies are proposed to enhance the security and resilience of SDN environments. The results indicate that controller impersonation (ALE = €7,500), data exposure targeting the SDN controller (ALE = €10,000), and network flow disruption (ALE = €9,000) represent the highest-risk threats. Furthermore, MITRE ATT&CK mapping reveals that Initial Access, Defense Evasion, and Impact are the most prevalent adversarial tactic categories, demonstrating the effectiveness of the proposed framework in identifying, prioritizing, and mitigating critical SDN security risks.