Traffic Classification in Software-Defined Networking (SDN): Application of Machine Learning Models for Flooding DDoS Attack Detection
Lucas Leal Bosi, André Chaves Mendes, Raphael Melo Guedes, Ronaldo Moreira Salles · 2024
Among the advantages offered by the SDN paradigm over traditional networks is the centralized implementation of comprehensive security policies. From this perspective, this study develops, trains, and tests several machine learning algorithms for traffic classification, distinguishing between legitimate traffic and three types of DDoS flooding attacks (HTTP, UDP, and TCP). The dataset used for training was employed both in its raw and preprocessed forms, and was generated in a reference study. The Random Forest and Gradient Boosting algorithms achieved the highest results in terms of accuracy and F1-score. Additionally, a comparison of the results of the studies is conducted.