International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1710969

1710969 Vol 9 · Issue 3 Download Paper

Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach

Francis Onojah Prof. Prema Kirubakaran Dr. Ridwan Kolapo Dr. Temitope Olufunmi Atoyebi Dr. R. Renuga Dev

Subject area: Science,Engineering and Technology  ·  Area of research: Machine Learning

Abstract

(DDoS) Attacks remain a significant concern for network security, utilizing flood-like traffic at the volume, protocol, and application levels to exploit vulnerabilities in today's infrastructure. To lessen these risks, Software-Defined Networking (SDN) offers programmability and centralized control. However, current machine learning (ML)-based detection techniques have a high false positive rate, are not very flexible against zero-day attacks, and are ineffective when handling high-dimensional flow data. To enhance the detection of DDoS attacks in software-defined networks, this paper proposes a hybrid machine-learning approach. Tapping into SDNs broad view of all network flows, the system studies traffic in real time by merging supervised deep learning- in this case, Long Short-Term Memory- with unsupervised anomaly detection called Isolation Forest. The LSTM sorts incoming packets and learns new normal behavior, while the Isolation Forest flags any stray patterns that don?t fit.

Keywords

DDoS attacks, network security, Long Short-Term Memory (LSTM), CNN

References

[1] Kreutz, Diego & Ramos, Fernando & Veríssimo, Paulo & Esteve Rothenberg, Christian & Azodolmolky, Siamak & Uhlig, Stev. Software-Defined Networking: A Comprehensive Survey. ArXiv e-prints.2014, 103. 10.1109/JPROC.2014.2371999.

[2] Ha, Asmaa & Gunawan, Teddy & Habaebi, Mohamed & Halbouni, Murad & Kartiwi, Mira & Ahmad, Robiah. CNN-LSTM: Hybrid Deep Neural Network for Network Intrusion Detection System. IEEE Access.2022, PP. 1-1. 10.1109/ACCESS.2022.3206425.

[3] I. Sharafaldin, A. H. Lashkari, S. Hakak and A. A. Ghorbani, "Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy," 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India, 2019, pp. 1-8, doi: 10.1109/CCST.2019.8888419.

[4] D. Kreutz, F. M. V. Ramos, and P. Veríssimo, “Towards secure and dependable softwaredefined networks,” in Proc. ACM SIGCOMM Workshop Hot Topics Softw. Defined Netw., 2013, pp. 55–60.

[5] S. M. Mousavi and M. St-Hilaire, “Early detection of DDoS attacks against SDN controllers,” in Proc. Int. Conf. Comput. Netw. Commun., 2015, pp. 77–81.

[6] R. Braga, E. Mota, and A. Passito, “Lightweight DDoS flooding attack detection using NOX/OpenFlow,” in Proc. IEEE Local Comput. Netw., 2010, pp. 408–415.

[7] J. Li, Y. Zhao, and R. Li, “Hybrid machine learning for network intrusion detection in IoT environments,” IEEE Access, vol. 10, pp. 4962–4974, 2022.

[8] B. Hussain, J. Du, and Q. Sun, “A hybrid deep learning approach for zero-day attacks in 5G networks,” IEEE Trans. Netw. Serv. Manage., vol. 19, no. 3, pp. 2532–2545, 2022.

[9] H. Wang, Z. Lu, and X. Li, “A CNN-LSTM model for DDoS detection in software-defined networks,” IEEE Trans. Netw. Sci. Eng., vol. 9, no. 4, pp. 2339–2351, 2022.

[10] T. N. Nguyen, V. L. Nguyen, and D. Hoang, “Federated learning for DDoS mitigation in SDN-based edge computing,” IEEE Trans. Ind. Inform., vol. 18, no. 8, pp. 56855694, 2022

[11] S. Kumar et al., “DDoS Detection in SDN using Machine Learning Techniques,” Comput. Mater. Contin., vol. 71, no. 1, pp. 771–789, 2022, doi: 10.32604/cmc.2022.021669.

[12] S. Wang et al., “Detecting flooding DDoS attacks in software defined networks using supervised learning techniques,” Eng. Sci. Technol. Int. J., vol. 35, p. 101176, Nov. 2022, doi: 10.1016/j.jestch.2022.101176.

[13] Md. A. Hossain and Md. S. Islam, “Enhancing DDoS attack detection with hybrid feature selection and ensemble-based classifier: A promising solution for robust cybersecurity,” Meas. Sens., vol. 32, p. 101037, Apr. 2024, doi: 10.1016/j.measen.2024.101037.

How to cite this paper

Francis Onojah, Prof. Prema Kirubakaran, Dr. Ridwan Kolapo, Dr. Temitope Olufunmi Atoyebi, Dr. R. Renuga Dev "Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach" Iconic Research And Engineering Journals Volume 9 Issue 3 2025 Page 1840-1846
Francis Onojah, Prof. Prema Kirubakaran, Dr. Ridwan Kolapo, Dr. Temitope Olufunmi Atoyebi, Dr. R. Renuga Dev "Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach" Iconic Research And Engineering Journals, vol. 9, no. 3, Sep. 2025
Francis Onojah, Prof. Prema Kirubakaran, Dr. Ridwan Kolapo, Dr. Temitope Olufunmi Atoyebi, Dr. R. Renuga Dev (2025). Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach. Iconic Research And Engineering Journals, 9(3).
Francis Onojah, Prof. Prema Kirubakaran, Dr. Ridwan Kolapo, Dr. Temitope Olufunmi Atoyebi, Dr. R. Renuga Dev "Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach" Iconic Research And Engineering Journals, vol. 9, no. 3, Sep. 2025.
@article{1710969,
      author = {Francis Onojah, Prof. Prema Kirubakaran, Dr. Ridwan Kolapo, Dr. Temitope Olufunmi Atoyebi, Dr. R. Renuga Dev},
      title = {Improving DDoS Detection in Software-Defined Networks Through a Hybrid Machine Learning Approach},
      journal = {Iconic Research And Engineering Journals},
      year = {2025},
      volume = {9},
      number = {3},
      pages = {1840-1846},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1710969.pdf},
      abstract = {(DDoS) Attacks remain a significant concern for network security, utilizing flood-like traffic at the volume, protocol, and application levels to exploit vulnerabilities in today's infrastructure. To lessen these risks, Software-Defined Networking (SDN) offers programmability and centralized control. However, current machine learning (ML)-based detection techniques have a high false positive rate, are not very flexible against zero-day attacks, and are ineffective when handling high-dimensional flow data. To enhance the detection of DDoS attacks in software-defined networks, this paper proposes a hybrid machine-learning approach. Tapping into SDNs broad view of all network flows, the system studies traffic in real time by merging supervised deep learning- in this case, Long Short-Term Memory- with unsupervised anomaly detection called Isolation Forest. The LSTM sorts incoming packets and learns new normal behavior, while the Isolation Forest flags any stray patterns that don?t fit.},
      keywords = {DDoS attacks, network security, Long Short-Term Memory (LSTM), CNN},
      month = {September},
  }