Enhanced Detection of DoS/DDoS Attacks in SDN Using Ensemble and Hybrid CNN-LSTM Models
Maharin Afroj, Khan Md Sadbin Rifat, Md. Saifur Rahman · 2024
Software-Defined Networking (SDN) faces significant challenges in mitigating Attacks known as denial of service (DoS) and distributed DDoS due to its centralized control plane architecture. This centralization makes the control plane an attractive target for attackers, highlighting the need for effective detection and mitigation strategies. In this study, we propose three innovative methodologies to enhance the accuracy of detecting DoS/DDoS attacks in SDN environments. Our first methodology employs an ensemble model with a voting classifier, which achieves a detection accuracy of 97.4%. This approach leverages multiple weak learners to enhance the robustness of detection. The second methodology utilizes an ensemble with a stacking technique, attaining a superior accuracy of 99%, demonstrating the efficacy of integrating multiple base models in a hierarchical fashion. The third approach introduces a novel hybrid model that blends LSTM networks with CNN, achieving a competitive accuracy of 98.51%. A comparative analysis of these methods reveals that, while all three significantly enhance detection rates, the stacking ensemble technique outperforms the others. This finding underscores the potential of advanced ensemble techniques in effectively addressing the dynamic and evolving cyber threats within SDN environments. Our study offers valuable insights into strengthening SDN infrastructures against DoS/DDoS attacks, contributing to the ongoing efforts to secure modern network architectures.