Enhanced Hybrid Approach for Multi-Class DDoS Attack Detection and Classification in Software-Defined Networks Using Remote Sensing and Data Analytics
摘要
In the rapidly evolving landscape of Software-Defined Networks (SDNs), mitigating Distributed Denial of Service (DDoS) attacks presents significant security challenges. This paper introduces a sensor-enhanced hybrid approach for real-time multi-class detection and classification of DDoS attacks, incorporating remote sensing techniques to enhance data collection and analysis. The proposed framework integrates advanced network sensors and remote sensing technologies that continuously monitor traffic patterns and collect vital performance metrics across distributed environments, providing a comprehensive dataset for analysis. Utilizing an Adaptive Ensemble of Modular Classifiers (AEMC), the approach combines signature-based, anomaly-based, and behavior-based detection techniques, each tailored to identify specific attack vectors while adapting to evolving threats. The integration of sensor and remote sensing data enables adaptive feature selection and enhances the robustness of the ensemble learning process, allowing the system to dynamically adjust its response based on real-time network conditions. Central to this framework is the application of One-vs-Rest (OvR) classifiers, which effectively differentiate between various DDoS attack types, such as SYN flood, UDP flood, and HTTP flood, alongside normal traffic. Evaluation through real-world datasets and simulated scenarios demonstrates the framework’s efficacy, achieving high precision and recall rates in DDoS detection and classification. This research contributes to advancing network security in SDNs by providing a scalable, adaptive solution that enhances detection accuracy and enables proactive defense mechanisms against sophisticated DDoS threats.