<p>Software-Defined Networking (SDN) gains significant traction in cloud computing, IoT, and big data. However, its susceptibility to security challenges, particularly Distributed Denial of Service (DDoS) attacks, poses a significant threat. This research addresses this issue by proposing a robust security mechanism for SDN networks. The proposed security mechanism integrates an ensemble feature selection technique with a Multi-Layer Perceptron (MLP)-based deep learning model to detect variable rates of DDoS flooding attacks targeting an SDN controller. The proposed mechanism is evaluated across six experimental scenarios, demonstrating consistently high accuracy, precision, recall, and <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="11036_2025_2458_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="18" /> </InlineMediaObject> <EquationSource Format="TEX">\(F_{1}\)</EquationSource> <EquationSource Format="MATHML"><math> <msub> <mi>F</mi> <mn>1</mn> </msub> </math></EquationSource> </InlineEquation>-Score while maintaining low false positive and negative rates. It effectively detects various DDoS attack types, including TCP, UDP, and ICMP floods, across different attack intensities and traffic patterns. Moreover, the proposed mechanism outperforms existing mechanisms, achieving superior accuracy and lower false positive rates, reinforcing its robustness and efficiency in identifying such threats against an SDN controller.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Deep Learning-Based Mechanism for Detecting Variable-Rate DDoS Attacks in Software-Defined Networks

  • Abdullah Ahmed Bahashwan,
  • Mohammed Anbar,
  • Selvakumar Manickam,
  • Taief Alaa Al-Amiedy,
  • Mohammad Adnan Aladaileh,
  • Ali Abdulqader Bin-Salem

摘要

Software-Defined Networking (SDN) gains significant traction in cloud computing, IoT, and big data. However, its susceptibility to security challenges, particularly Distributed Denial of Service (DDoS) attacks, poses a significant threat. This research addresses this issue by proposing a robust security mechanism for SDN networks. The proposed security mechanism integrates an ensemble feature selection technique with a Multi-Layer Perceptron (MLP)-based deep learning model to detect variable rates of DDoS flooding attacks targeting an SDN controller. The proposed mechanism is evaluated across six experimental scenarios, demonstrating consistently high accuracy, precision, recall, and \(F_{1}\) F 1 -Score while maintaining low false positive and negative rates. It effectively detects various DDoS attack types, including TCP, UDP, and ICMP floods, across different attack intensities and traffic patterns. Moreover, the proposed mechanism outperforms existing mechanisms, achieving superior accuracy and lower false positive rates, reinforcing its robustness and efficiency in identifying such threats against an SDN controller.