Using different machine learning models for address resolution protocol spoofing attack detection in software-defined network architecture

An Tran, Xuân Phúc Lê Ngô, Quốc Cường Nguyễn, Ninh Bui Trung, Thai-Mai Thi Dinh · International Journal of Pervasive Computing and Communications · 2025

Purpose The purpose of the study concludes detecting address resolution protocol (ARP) Spoofing attack in software-defined network (SDN) architecture meanwhile using different machine learning models to evaluate their effectiveness. Design/methodology/approach This research originates from building a SDN topology and researching into its changes under ARP Spoofing attack. Based on that, the authors propose four features which show obvious abnormalities in network under attack stage. The data collected from SDN controller is used to build a data set, which is then put into different machine learning models, which are: Artificial Neuron network (ANN), Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM), CNN-LSTM and Gated Recurrent Unit (GRU). Findings After applying this proposal in simulation and experimental environments, they achieve impressive performance metrics. In simulation environment, the GRU model stands out with the highest accuracy of 98.94%. In real environments, the CNN-LSTM model leads with a recall of 98.38% and an F1-Score of 98.57%, while the LSTM model has the highest precision (98.8%). The GRU model also performs strongly in real scenarios with a high accuracy of 97.65%. ANN, despite its reliability, struggles with lower recall and F1-Score across both environments. Originality/value This analysis emphasizes the importance of the proposed features when applied to different models and their high potential to conduct in practical environment.

Read the paper · More papers on PaperTik