Low-rate DDoS attack detection in SDN using modified condense net and adaptive snow leopard optimization
摘要
SDN (Software-Defined Network) is an emerging technology which offers the environment with robust flexibility, scalability, and network programmability. The centralized control plane in SDN provides effective resource management by segregating the control and data planes and providing a global perspective of the core network architecture. Aside from the inherent advantages, the centralized SDN design raises significant security risks such as sniffing, spoofing, API exploitation, brute force, and denial of service, demanding close monitoring to ensure a secure network. Among those security dangers, Distributed Denial of Service (DDoS) along with its variant Low-Rate DDoS (LR-DDoS) are quite difficult to detect and prevent since the illicit user sends malicious network traffic at a low pace. Machine learning (ML) has demonstrated amazing success in detecting and mitigating such threats. Thus in this study, we present a novel model called Modified Condense Net that efficiently detect LR-DDoS in SDN environments. Furthermore, we employ the Adaptive Snow Leopard Optimization (ASLO) method for real-time switch activation, which impedes attackers, reduces energy sage, balances network load, and minimizes the controller’s computational and storage overhead by filtering malicious traffic. Furthermore, the Modified Condense Net (MCNet), which combines Condense Net with the parallel mixed attention mechanism module (PMAM) for flow classification, analyzes legitimate flows by assessing a variety of features to successfully distinguish among legitimate and malicious flows. The proposed model’s effectiveness has been investigated and evaluated using the LR-HR DDoS 2024dataset. The results indicated that the proposed model reduces energy consumption by 9 J to 34 J compared to other methods. In particular, it achieves an improvement of 4.2% in energy consumption, 5.1% in malicious traffic detection rate, 3.7% in defender success rate, 4.8% in attack success rate reduction. Notably, proposed MCNet + ASLO also achieve a 13% to 19% reduction in computation overhead compared to MCNet and ASLO individually.