DDOS attack detection using machine learning algorithm in SDN network
Karrar E. Alhamami, Salah Abdulhadi Albermany · 2023
In this research, we highlight SDN networks that exist in wide applications to manage several routers and switches by a small number of engineers that face several types of attacks, the most important of which is a DDOS attack, as it leads to the prohibitions of networks from working and to solve such a problem by identifying and discovering such attacks. We need fast algorithms like machine learning to detect attacks. specifically focusing on the OpenDaylight controller. We employ the Mininet network simulator to emulate the SDN network and implement the OpenFlow protocol to enable communication between the controller and the network devices. The primary objective of this study is to evaluate the effectiveness of various machine learning algorithms in predicting DDoS attacks in real time to protect the SDN infrastructure. To achieve this goal, we analyze the performance of several machine learning classifiers, including XGBoost, Logistic Regression (LR), Support Vector Machine (SVM), Naive Bayes (NB), and K-Nearest Neighbors (KNN), on a simulated dataset replicating real-world DDoS attack conditions. Our empirical results demonstrate that XGBoost, LR, SVM, and KNN show strong classification performance; with XGBoost, we get the best accuracy of 99.26%, and LR of 99.24 %, standing out for their computational efficiency. In contrast, the NB classifier exhibits limitations in classification accuracy. This study contributes to the growing body of research on SDN security, highlighting the potential of machine learning algorithms in detecting and mitigating DDoS attacks in SDN environments.