Enhancing Network Security in SDN: Detecting Low-Rate DDoS Attacks Using Decision Trees

Hasen Alomin, Amir Gargouri, M. Ghorbel · 2024

The pervasive threat of Distributed Denial of Service$(\text{DDoS})$attacks continues to challenge network security, with the emergence of low-rate$\text{DDoS}$attacks introducing new complexi-ties. These malicious attacks can overwhelm network resources and disrupt legitimate user access, making them exceedingly difficult to identify and mitigate. Software-defined networking (SDN) architecture has transformed network management and control with its centralized control plane and software-based controller. However, it has also introduced new vulnerabilities that adversaries exploit. In this paper, this paper propose a real-time method for detecting low-rate DDo s attacks in SDN environments based on Decision Tree techniques. In this re-search, we have crafted a robust classification model aimed at discerning between legitimate users and abnormal clients. Our focus lies in identifying features that significantly impact network behavior, with a special emphasis on enhancing low-rate$\text{DDoS}$attack detection within SDN environments. By curating distinct datasets tailored to SDN settings and employing advanced feature selection techniques, This research aim to improve the accuracy of low-rate$\text{DDoS}$attack identification. This experimental results showcase a noteworthy 91 % accuracy rate, underscoring the efficacy of the method. This approach not only provides network administrators with a powerful tool for real-time defense but also addresses the escalating threat of low-rate$\text{DDoS}$attacks in a more effective manner.

Read the paper · More papers on PaperTik