Home / Current Issue / Paper 1710969
Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach
Subject area: Science,Engineering and Technology · Area of research: Machine Learning
Abstract
(DDoS) Attacks remain a significant concern for network security, utilizing flood-like traffic at the volume, protocol, and application levels to exploit vulnerabilities in today's infrastructure. To lessen these risks, Software-Defined Networking (SDN) offers programmability and centralized control. However, current machine learning (ML)-based detection techniques have a high false positive rate, are not very flexible against zero-day attacks, and are ineffective when handling high-dimensional flow data. To enhance the detection of DDoS attacks in software-defined networks, this paper proposes a hybrid machine-learning approach. Tapping into SDNs broad view of all network flows, the system studies traffic in real time by merging supervised deep learning- in this case, Long Short-Term Memory- with unsupervised anomaly detection called Isolation Forest. The LSTM sorts incoming packets and learns new normal behavior, while the Isolation Forest flags any stray patterns that don?t fit.
Keywords
DDoS attacks, network security, Long Short-Term Memory (LSTM), CNN
References
[1] Kreutz, Diego & Ramos, Fernando & Veríssimo, Paulo & Esteve Rothenberg, Christian & Azodolmolky, Siamak & Uhlig, Stev. Software-Defined Networking: A Comprehensive Survey. ArXiv e-prints.2014, 103. 10.1109/JPROC.2014.2371999.
[2] Ha, Asmaa & Gunawan, Teddy & Habaebi, Mohamed & Halbouni, Murad & Kartiwi, Mira & Ahmad, Robiah. CNN-LSTM: Hybrid Deep Neural Network for Network Intrusion Detection System. IEEE Access.2022, PP. 1-1. 10.1109/ACCESS.2022.3206425.
[3] I. Sharafaldin, A. H. Lashkari, S. Hakak and A. A. Ghorbani, "Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy," 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India, 2019, pp. 1-8, doi: 10.1109/CCST.2019.8888419.
[4] D. Kreutz, F. M. V. Ramos, and P. Veríssimo, “Towards secure and dependable softwaredefined networks,” in Proc. ACM SIGCOMM Workshop Hot Topics Softw. Defined Netw., 2013, pp. 55–60.
[5] S. M. Mousavi and M. St-Hilaire, “Early detection of DDoS attacks against SDN controllers,” in Proc. Int. Conf. Comput. Netw. Commun., 2015, pp. 77–81.
[6] R. Braga, E. Mota, and A. Passito, “Lightweight DDoS flooding attack detection using NOX/OpenFlow,” in Proc. IEEE Local Comput. Netw., 2010, pp. 408–415.
[7] J. Li, Y. Zhao, and R. Li, “Hybrid machine learning for network intrusion detection in IoT environments,” IEEE Access, vol. 10, pp. 4962–4974, 2022.
[8] B. Hussain, J. Du, and Q. Sun, “A hybrid deep learning approach for zero-day attacks in 5G networks,” IEEE Trans. Netw. Serv. Manage., vol. 19, no. 3, pp. 2532–2545, 2022.
[9] H. Wang, Z. Lu, and X. Li, “A CNN-LSTM model for DDoS detection in software-defined networks,” IEEE Trans. Netw. Sci. Eng., vol. 9, no. 4, pp. 2339–2351, 2022.
[10] T. N. Nguyen, V. L. Nguyen, and D. Hoang, “Federated learning for DDoS mitigation in SDN-based edge computing,” IEEE Trans. Ind. Inform., vol. 18, no. 8, pp. 56855694, 2022
[11] S. Kumar et al., “DDoS Detection in SDN using Machine Learning Techniques,” Comput. Mater. Contin., vol. 71, no. 1, pp. 771–789, 2022, doi: 10.32604/cmc.2022.021669.
[12] S. Wang et al., “Detecting flooding DDoS attacks in software defined networks using supervised learning techniques,” Eng. Sci. Technol. Int. J., vol. 35, p. 101176, Nov. 2022, doi: 10.1016/j.jestch.2022.101176.
[13] Md. A. Hossain and Md. S. Islam, “Enhancing DDoS attack detection with hybrid feature selection and ensemble-based classifier: A promising solution for robust cybersecurity,” Meas. Sens., vol. 32, p. 101037, Apr. 2024, doi: 10.1016/j.measen.2024.101037.
How to cite this paper
@article{1710969,
author = {Francis Onojah, Prof. Prema Kirubakaran, Dr. Ridwan Kolapo, Dr. Temitope Olufunmi Atoyebi, Dr. R. Renuga Dev},
title = {Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {3},
pages = {1840-1846},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1710969.pdf},
abstract = {(DDoS) Attacks remain a significant concern for network security, utilizing flood-like traffic at the volume, protocol, and application levels to exploit vulnerabilities in today's infrastructure. To lessen these risks, Software-Defined Networking (SDN) offers programmability and centralized control. However, current machine learning (ML)-based detection techniques have a high false positive rate, are not very flexible against zero-day attacks, and are ineffective when handling high-dimensional flow data. To enhance the detection of DDoS attacks in software-defined networks, this paper proposes a hybrid machine-learning approach. Tapping into SDNs broad view of all network flows, the system studies traffic in real time by merging supervised deep learning- in this case, Long Short-Term Memory- with unsupervised anomaly detection called Isolation Forest. The LSTM sorts incoming packets and learns new normal behavior, while the Isolation Forest flags any stray patterns that don?t fit.},
keywords = {DDoS attacks, network security, Long Short-Term Memory (LSTM), CNN},
month = {September},
}