Machine Learning Approach for Distributed Daniel of Service Attack Detection in SDNs
Basem A. Almohagri, Mogeeb A. Saeed, Haroon M. Alazaby, Ayman I. Mohammed · 2023
Software-defined networks (SDN) have attracted substantial attention as a promising network technology, providing centralized control and programmability through the SDN controller, which provides resilience for network management and topology of the infrastructure network. Hence, the security of SDN controllers remains a significant concern, where Distributed Daniel of Service (DDoS) attacks pose a threat and obstruction, causing disability for the entire network or a potential failure point for the SDN control unit. In this paper, a machine learning (ML) approach for detecting DDoS attacks was proposed and created for SDN controllers. The ML approach mainly employs three classification algorithms: Extreme Gradient Boosting (XGBoost), Random Forest (RF) and Decision Tree (DT), and it is evaluated using the CICDDoS2019 dataset. The results of the research demonstrate the effectiveness of ML techniques, achieving remarkable accuracy scores of 99.94%, 99.93%, and 99.87%, respectively, for the aforementioned algorithms. These results highlight the ability of ML algorithms to accurately detect DDoS attack types in SDN environments.