Software-defined networking facilitates better network management by decoupling the data and control planes of legacy routers and switches and is widely adopted in the data center and production networks. The decoupling of control and data planes facilitates more optimal network management and deployment of elaborate security mechanisms but also introduces new vulnerabilities that could be exploited using distributed denial of service (DDoS) attacks. This talk presents several protocol vulnerabilities and resource limitations that are exploited by DDoS attacks. Often, techniques mitigate these attacks change the attack surface, which can lead to new vulnerabilities exploitable by new DDoS attacks. Several examples of new vulnerabilities introduced by DDoS mitigation schemes are presented with potential attacks to exploit them. The talk concludes with some guidelines on designing DDoS attack mitigation schemes that minimize the introduction of new vulnerabilities.