Moving Target Defense in SDN-enabled EV Charging Network

arXiv:2610.11996 · cs.CR, cs.GT, cs.NI · Submitted 2026-10-08 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: I'm Nadia, and with me are Elias and Priya, guest researcher.

Elias: Today's paper: "Moving Target Defense in SDN-enabled EV Charging Network".

Nadia: The gist: CS-SHIELD, a Moving Target Defense mechanism for SDN-enabled EVCI communication,

Elias: First, who's behind it and why it matters.

Title and authors: Nadia: The paper is called "Moving Target Defense in SDN-enabled EV Charging Network," and the authors are Roland Plaka, Mikael Asplund, and Simin Nadjm-Tehrani from Linköping University in Sweden. They’re looking at how to keep charging sites available when they get hit by these subtle DoS attacks that exploit the flow table limits of SDN switches.

Elias: Yes, and what’s important is that the title itself points to the solution: Moving Target Defense, which is a technique where you constantly change things around—like addresses or configurations—to make an attacker's map outdated very quickly. That’s a key concept here.

Priya: So, for someone listening who isn't in networking, it means we are talking about building defenses that actively move and shake the network configuration while the charging sessions are running so that an attacker can’t just wait around and exploit a known path.

Nadia: Exactly. The authors of this paper point out a gap in research because MTD hasn't really been studied for EV charging infrastructure specifically when trying to keep services available against low-rate DoS attacks, which is what they call CS-SHIELD.

Elias: They are setting up the problem by noting that classical DoS detection based on volume just doesn't work here because the traffic is periodic and low-bandwidth, but the resource exhaustion still happens. That’s why this research is necessary to look at a different kind of attack vector entirely.

Priya: It makes sense that they are focusing on availability as the property under attack, because if the defense itself causes too much disruption, then it’s not working for anyone.

The paper's summary: Nadia: CS-SHIELD is their proposed mechanism and it has two main phases. First is detection where the system polls the switch to see what flows are active, and then they compare that list against a verified list from the Charging Station Management System, or CSMS. If they find an address in the switch but not in the authenticated CSMS list, it flags it as malicious.

Elias: That detection phase is crucial because it uses cross-layer identity verification to distinguish between a legitimate charger and something that's trying to inject fake rules into the switch flow table, which is a clever way to spot the attack without having to inspect the actual data payload of every flow.

Priya: So, once they find that discrepancy, what happens next? The summary says in Phase Two is Shuffling where they reassign virtual IP addresses for all active chargers by drawing a new one randomly from a large address pool. That’s the mechanism for invalidating the attacker's knowledge.

Nadia: Right, and then they install those new forwarding rules and update the internal address map to reflect those changes, which is what makes earlier reconnaissance by an attacker completely worthless because their discovered addresses are now wrong.

Elias: They also mention that this shuffling happens fast enough to counteract the attack, specifically saying that CS-SHIELD detects and mitigates the attack at saturation, restoring normal forwarding within one heartbeat interval under certain conditions.

The paper's improvements: Nadia: The main improvement they are presenting is CS-SHIELD itself, which is a specific SDN mechanism designed to handle low-rate DoS attacks against EVCI communication by using that cross-layer identity verification detection and the subsequent IP address shuffling.

Elias: They are showing how this MTD directly counters the problem of an attacker learning address bindings during reconnaissance by constantly shifting the system configurations, which is what makes their defense effective.

Priya: What’s really compelling from their experimental validation is that they showed full site availability maintained under attack, and they even showed that in Scenario three CS-SHIELD evicted all the attacker-injected rules and restored normal forwarding within just one heartbeat interval after the purge <ref:2610.11996#pg1>.

Nadia: That rapid response time is what sets it apart; it means service continuity isn't lost during the defense, which is a huge win for critical infrastructure like charging networks.

Elias: They also measured the overhead of this whole process, noting that for a full CS-SHIELD response, it’s about seventeen point nine milliseconds total for detection and shuffling, which seems pretty low when you compare it to the time needed to detect a saturation point in some of their test scenarios.

Conclusion: Nadia: To wrap up, the paper on "Moving Target Defense in SDN-enabled EV Charging Network" shows that CS-SHIELD effectively protects availability under low-rate DoS attacks by using cross-layer identity verification to spot malicious flows and then rapidly shuffling virtual IP addresses for all active chargers.

Elias: The implication is that an attacker’s hour of reconnaissance can be invalidated in milliseconds, which means they can’t build up a reliable map against this kind of defense because the system keeps changing what the address bindings are.

Priya: From a measurement standpoint, it confirms that even though the traffic is low-bandwidth and periodic over long sessions, this proactive approach keeps availability at one point zero throughout their experiments, proving that you can defend against resource exhaustion without sacrificing service continuity <ref:2610.11996#pg1>.

Nadia: So essentially, if you're building EV infrastructure on SDN, you need a defense that reacts to flow table saturation by shuffling addresses before the attacker can lock down the site with low-rate traffic.

Elias: It’s about making the system constantly unpredictable so that an attacker’s pre-attack knowledge becomes useless almost instantly, which is a core principle of MTD applied to this specific environment.

Priya: That's what it suggests for the future—that proactive detectors focusing on flow arrival rates could shorten the window where an attacker can successfully prepare their low-rate attack against critical services like EV charging.

Roland Plaka, Mikael Asplund, Simin Nadjm-Tehrani

Department of Computer and Information Science, Linköping University

cs.CR, cs.GT, cs.NI

Submitted: 2026-10-08

Updated: 2026-10-08

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

The gist: The gist: CS-SHIELD, a Moving Target Defense mechanism for SDN-enabled EVCI communication, detects malicious flow table rules via cross-layer identity verification and responds by reassigning virtual

Key concepts

SDN
Software-Defined Networking allows for flexible control over network infrastructure, such as EV charging systems. It separates the control plane from the data plane, enabling centralized management where a controller dictates how traffic flows through switches. This flexibility is key to implementing dynamic defenses like CS-SHIELD.
OCPP
The Open Charge Point Protocol (OCPP) is the standard communication protocol used for managing EV charging sessions. It governs the low-bandwidth, periodic traffic between vehicles and charging stations, which makes these systems vulnerable to low-rate DoS attacks that conventional volume-based defenses miss.
Moving Target Defense (MTD)
MTD is a security technique where system properties, like IP addresses, are frequently changed or moved. CS-SHIELD uses this by reassigning virtual IPs to chargers randomly. This makes reconnaissance efforts by an attacker useless because the addresses they discover quickly become invalid.
Flow Table Exhaustion DoS
This attack targets the limited capacity of SDN switch flow tables, not high traffic volume. An attacker sends a low rate of specially crafted flows that fill up the table, effectively denying service to legitimate chargers without triggering traditional monitors based on bandwidth or packet rates.

Terminology

Summary

The gist: CS-SHIELD, a Moving Target Defense mechanism for SDN-enabled EVCI communication, detects malicious flow table rules via cross-layer identity verification and responds by reassigning virtual IP addresses to all active chargers.

Problem and Motivation

Software-Defined Networking (SDN) offers flexible control for Electric Vehicle Charging Infrastructure (EVCI), but it faces low-rate Denial-of-Service (DoS) attacks that exhaust SDN switch flow tables, potentially disabling entire charging sites without triggering volume-based defenses Classical denial-of-service attacks exhaust resources with high-volume traffic and are detected by throughput and packet-rate monitors EVCI runs low-bandwidth, periodic traffic over long-lived TLS/WebSocket sessions governed by the Open Charge Point Protocol (OCPP) Because availability depends on the continuity of these sessions rather than on raw bandwidth, an attacker may deny service at a low rate without producing volume that conventional defences would flag SDN switches forward traffic using a flow table of fixed capacity which can be exhausted by a low-rate stream of crafted flows rather than by high-volume traffic

CS-SHIELD Mechanism

CS-SHIELD is an MTD mechanism structured into two phases: detection and shuffling Phase 1, Detection identifies attacker-injected flows by polling the switch for active flows at a fixed interval Tpoll and comparing this list against the authenticated charger list from the CSMS The controller flags any address present in the switch's flow table but absent from the CSMS-verified charger list as malicious Once a discrepancy is found, the controller drops all non-verified flows to free up the flow table Phase 2, Shuffling reassigns virtual addresses for all active chargers by drawing a new virtual IP address at random from a large address pool The controller then installs the new forwarding rules and updates the internal address map to reflect these changes This shuffling makes earlier reconnaissance knowledge by the attacker worthless because an attacker who has discovered a charger’s address during reconnaissance can no longer use it

Experimental Validation and Results

Experiments on an emulated SDN testbed with a real charging protocol implementation demonstrate that CS-SHIELD maintains full site availability under attack while responding quickly, adding only a negligible delay under normal conditions Scenario 2 showed that the attacker drives the rule count linearly to full capacity at t ≈ 3,350 s (Figure 4b), after which the network can no longer accommodate new legitimate flows The full three-phase attack takes ≈ 64 min total: Phase 1 nmap scan (≈ 13 min), Phase 2 binary-search timeout inference (≈ 1 min), and Phase 3 Slowloris fill with 245 connections (≈ 50 min) Scenario 4 evaluated CS-SHIELD with MTD enabled and no attacker present, showing that all ten WiFi chargers maintain A(t) = 1.0 throughout the experiment The IP shuffle event is visible at packet 28, where RTT reaches its maximum observed value of 0.236 ms — a 3.1× momentary increase over the mean In Scenario 3, CS-SHIELD evicts all attacker-injected rules and restores normal forwarding within one heartbeat interval

Conclusion on Effectiveness

CS-SHIELD provides complete availability protection under the evaluated low-rate attack because the CSMS re-registers chargers under their new VIP mappings within one heartbeat interval, before the 90 s session timeout The mechanism is operationally transparent to legitimate traffic as it adds only sub-millisecond RTT overhead and maintains A(t) = 1.0 under normal operation The defender–attacker asymmetry is the central outcome because over an hour of reconnaissance is invalidated in milliseconds, and rebuilding it takes far longer This demonstrates that a proactive flow-arrival-rate detector could shorten the pre-saturation window The paper concludes that CS-SHIELD detects and mitigates the attack at saturation, restoring normal forwarding within one heartbeat interval

Overhead Analysis

The overhead cost of each phase is measured in three variants: detect-only, purge-only (DROP plus table clearing), and the full CSSHIELD process DETECT costs 0.265 ms mean PURGE costs 2.37 ms in the purge-only variant and 1.48 ms in the full variant SHUFFLE adds 16.4 ms beyond PURGE for a total response of 17.9 ms For polling overhead, Scenario 3 and Scenario 4 have mean poll-cycle costs of 18.8 ± 12.9 ms and 20.4 ± 13.7 respectively The overlapping variance indicates no measurable additional polling burden during active defense This experiment was repeated 7 times

Limitations

Real hardware differs in three respects: TCAM rules incur different hardware costs depending on how many packet header fields they match hardware eviction policies may differ from OVS idle-timeout expiry OpenFlow latency on hardware is typically lower than in Mininet CS-SHIELD shuffles only when the flow table is exhausted, at which point the attack has already put the affected sessions at risk A time-periodic shuffle would instead tear down active sessions at fixed intervals and force reconnection, indistinguishable from the attack’s own effect The paper suggests that a proactive flow-arrival-rate detector could shorten the pre-saturation window

Future Work

Validation on hardware SDN switches and formal quantification of shuffle entropy are left for future study The paper suggests that a proactive flow-arrival-rate detector could shorten the pre-saturation window The attacker’s entire ≈ 64 min of reconnaissance is invalidated in 17.9 ms: every IP binding learned during Phases 1-2 becomes worthless once each charger gets a new address drawn randomly from a pool of over 65,000 candidates Re-discovering all addresses at the same low rate takes far longer than the interval between purges, so the attack cannot succeed again without fundamentally changing its approach The paper suggests that a proactive flow-arrival-rate detector could shorten the pre-saturation window The attacker’s entire ≈ 64 min of reconnaissance is invalidated in 17.9 ms: every IP binding learned during Phases 1-2 becomes worthless once each charger gets a new address drawn randomly from a pool of over 65,000 candidates Re-discovering all addresses at the same low rate takes far longer than the interval between purges, so the attack cannot succeed again without fundamentally changing its approach<ref:2610.

Improvements for AI systems

  1. Bold Header: Cross-layer Identity Verification Detection

The AI system can detect malicious flow table rules by cross-checking the switch’s flow table against the chargers that CSMS has authenticated by comparing flows present in Fsw with those in Fcsms, effectively distinguishing an attacker-injected flow from a legitimate charger flow without payload inspection.

  1. Bold Header: Reactive IP Address Shuffling

The system can respond to detected saturation by executing the shuffling phase, which involves randomizing addresses and stating, A new virtual IP address is drawn at random from a large address pool, ensuring that an attacker who has discovered a charger’s address during reconnaissance can no longer use it.

  1. Bold Header: Session Continuity Preservation

The system ensures that service availability is maintained despite the defense by confirming, no charger is counted as unavailable because the CSMS path is restored before the session timeout is reached, and the controller reinstalls the table-miss rule immediately after the purge, allowing the reactive SDN path to resume forwarding before the new VIP rules propagate.

Related papers