The paper discusses security threats in Software Defined Networks (SDN) focused on OpenFlow and proposes detection and defense strategies against ARP spoofing and dynamic flow tunneling attacks. It introduces a prototype called FlowEye that utilizes simulation tests to explore these vulnerabilities and suggests methods for monitoring and defending against malicious behaviors. The research aims to enhance SDN security by leveraging centralized control while addressing the unique challenges posed by its architecture.