IoT Flooding Attack Defense in SDN: A Real-Data Machine Learning Approach

Carlos González, Salim Mahamat Charfadine · 2023

Software-defined networking (SDN) has become a promising paradigm for mitigating the limitations intrinsic to legacy network architectures. By decentralizing the control logic from the underlying data-forwarding plane, SDN radically transforms the fundamental principles and practices of network engineering. This study introduces a comprehensive security framework tailored for SDN networks, leveraging the power of machine learning to detect and prevent flooding attacks initiated by poisoned IoT devices. Although the concept of using machine learning for network security is not entirely novel, what sets this research apart is its reliance on real-time data for training and testing a machine learning model. On one hand, the framework consists of a traffic monitoring component that collects network traffic data and identifies potential anomalous traffic flows based on packet size features. On the other hand, a machine learning component then uses this real-data to train a model that can identify and classify attacks. The efficacy of our framework was assessed using a dataset comprising real-time network-traffic data. These results underscore the high level of accuracy achieved by our framework in the detection and classification of attacks. We also demonstrate that our framework can be used to mitigate attacks by blocking malicious traffic. In the classification model, the best-performing machine-learning algorithm was a neural network with an average accuracy of 95 %. Based on our empirical analysis, it has been established that the application of machine-learning techniques holds substantial promise for accurately identifying and mitigating IoT attacks in real time within the context of SDN. The utilization of our framework offers the potential to improve the security of SDN and make it more resilient to other types of attacks.

Read the paper · More papers on PaperTik