Optimizing DDoS Detection in SDNs Through Machine Learning Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Haque, Md. Ehsanul, Hossain, Amran, Alam, Md. Shafiqul, Siam, Ahsan Habib, Rabbi, Sayed Md Fazle, Rahman, Md. Muntasir
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915293227384832
author Haque, Md. Ehsanul
Hossain, Amran
Alam, Md. Shafiqul
Siam, Ahsan Habib
Rabbi, Sayed Md Fazle
Rahman, Md. Muntasir
author_facet Haque, Md. Ehsanul
Hossain, Amran
Alam, Md. Shafiqul
Siam, Ahsan Habib
Rabbi, Sayed Md Fazle
Rahman, Md. Muntasir
contents The emergence of Software-Defined Networking (SDN) has changed the network structure by separating the control plane from the data plane. However, this innovation has also increased susceptibility to DDoS attacks. Existing detection techniques are often ineffective due to data imbalance and accuracy issues; thus, a considerable research gap exists regarding DDoS detection methods suitable for SDN contexts. This research attempts to detect DDoS attacks more effectively using machine learning algorithms: RF, SVC, KNN, MLP, and XGB. For this purpose, both balanced and imbalanced datasets have been used to measure the performance of the models in terms of accuracy and AUC. Based on the analysis, we can say that RF and XGB had the perfect score, 1.0000, in the accuracy and AUC, but since XGB ended with the lowest Brier Score which indicates the highest reliability. MLP achieved an accuracy of 99.93%, SVC an accuracy of 97.65% and KNN an accuracy of 97.87%, which was the next best performers after RF and XGB. These results are consistent with the validity of SDNs as a platform for RF and XGB techniques in detecting DDoS attacks and highlights the importance of balanced datasets for improving detection against generative cyber attacks that are continually evolving.
format Preprint
id arxiv_https___arxiv_org_abs_2505_13493
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Optimizing DDoS Detection in SDNs Through Machine Learning Models
Haque, Md. Ehsanul
Hossain, Amran
Alam, Md. Shafiqul
Siam, Ahsan Habib
Rabbi, Sayed Md Fazle
Rahman, Md. Muntasir
Cryptography and Security
The emergence of Software-Defined Networking (SDN) has changed the network structure by separating the control plane from the data plane. However, this innovation has also increased susceptibility to DDoS attacks. Existing detection techniques are often ineffective due to data imbalance and accuracy issues; thus, a considerable research gap exists regarding DDoS detection methods suitable for SDN contexts. This research attempts to detect DDoS attacks more effectively using machine learning algorithms: RF, SVC, KNN, MLP, and XGB. For this purpose, both balanced and imbalanced datasets have been used to measure the performance of the models in terms of accuracy and AUC. Based on the analysis, we can say that RF and XGB had the perfect score, 1.0000, in the accuracy and AUC, but since XGB ended with the lowest Brier Score which indicates the highest reliability. MLP achieved an accuracy of 99.93%, SVC an accuracy of 97.65% and KNN an accuracy of 97.87%, which was the next best performers after RF and XGB. These results are consistent with the validity of SDNs as a platform for RF and XGB techniques in detecting DDoS attacks and highlights the importance of balanced datasets for improving detection against generative cyber attacks that are continually evolving.
title Optimizing DDoS Detection in SDNs Through Machine Learning Models
topic Cryptography and Security
url https://arxiv.org/abs/2505.13493