Detection and Mitigation of DDoS Attack in SDN Using Feature Based SVM and Decision Tree Approach

A Ashwin, V. C. Sai Santhosh, R Thirupathi Venkatesh, N Gowthami, S. Tamilselvi · 2024

Software-Defined Networking (SDN) is an innovative network architecture that separates the control plane from the data plane, enabling centralized management and dynamic network resource configuration through software. However, the centralization of the SDN controller makes it a critical target for Distributed Denial of Service (DDoS) attacks. To effectively detect and mitigate these threats, deploying a robust machine learning-based solution is essential. This study utilized Particle Swarm Optimization (PSO) and Generalized Normal Distribution Optimization (GNDO) as feature selection techniques to extract the most relevant features from the SDN_DDoS_2020 dataset, which includes ICMP, TCP, and UDP traffic (Mendeley). The selected feature subsets were used to train and evaluate the performance of Support Vector Machine (SVM) and Decision Tree (DT) classifiers. Additionally, a dedicated mitigation framework was designed to counter flood traffic generated by TCP, UDP, and ICMP-based DDoS attacks. Among the models, the PSO-Decision Tree (PSO_DT) approach demonstrated superior performance, achieving an accuracy of 98.87% and a False Alarm Rate (FAR) of 0.7702, underscoring its effectiveness in reducing false positives and enhancing detection reliability.

Read the paper · More papers on PaperTik