Home / Current Issue / Paper 1710969
Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach
Subject area: Science,Engineering and Technology · Area of research: Machine Learning
Abstract
(DDoS) Attacks remain a significant concern for network security, utilizing flood-like traffic at the volume, protocol, and application levels to exploit vulnerabilities in today's infrastructure. To lessen these risks, Software-Defined Networking (SDN) offers programmability and centralized control. However, current machine learning (ML)-based detection techniques have a high false positive rate, are not very flexible against zero-day attacks, and are ineffective when handling high-dimensional flow data. To enhance the detection of DDoS attacks in software-defined networks, this paper proposes a hybrid machine-learning approach. Tapping into SDNs broad view of all network flows, the system studies traffic in real time by merging supervised deep learning- in this case, Long Short-Term Memory- with unsupervised anomaly detection called Isolation Forest. The LSTM sorts incoming packets and learns new normal behavior, while the Isolation Forest flags any stray patterns that don?t fit.
Keywords
DDoS attacks, network security, Long Short-Term Memory (LSTM), CNN
How to cite this paper
@article{1710969,
author = {Francis Onojah, Prof. Prema Kirubakaran, Dr. Ridwan Kolapo, Dr. Temitope Olufunmi Atoyebi, Dr. R. Renuga Dev},
title = {Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {3},
pages = {1840-1846},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1710969.pdf},
abstract = {(DDoS) Attacks remain a significant concern for network security, utilizing flood-like traffic at the volume, protocol, and application levels to exploit vulnerabilities in today's infrastructure. To lessen these risks, Software-Defined Networking (SDN) offers programmability and centralized control. However, current machine learning (ML)-based detection techniques have a high false positive rate, are not very flexible against zero-day attacks, and are ineffective when handling high-dimensional flow data. To enhance the detection of DDoS attacks in software-defined networks, this paper proposes a hybrid machine-learning approach. Tapping into SDNs broad view of all network flows, the system studies traffic in real time by merging supervised deep learning- in this case, Long Short-Term Memory- with unsupervised anomaly detection called Isolation Forest. The LSTM sorts incoming packets and learns new normal behavior, while the Isolation Forest flags any stray patterns that don?t fit.},
keywords = {DDoS attacks, network security, Long Short-Term Memory (LSTM), CNN},
month = {September},
}