From Signatures to AI: A Comprehensive Review of DDoS Detection Strategies in IoT & SDN

Shehroze Ahmed Khan, Syed Ihtesham Hussain, Jawaid Iqbal · International Journal on Robotics Automation and Sciences · 2025

In the ever-evolving landscape of the Internet of Things (IoT) and Software-Defined Networks (SDN), the rapid growth of interconnected devices has enhanced ease and efficiency. However, this evolution has also paved the way for the ominous cyber-attack: Distributed Denial of Service (DDoS). These attacks, which make systems unavailable for legitimate users, threaten the data integrity, confidentiality, and availability in IoT and SDN infrastructure. This paper delves into the critical issue of DDoS attacks within the IoT and SDN environments, offering a comprehensive exploration of detection mechanisms by categorizing them into traditional (signature-based) and anomaly-based approaches i.e., Machine Learning (ML), Deep Learning (DL), and statistical techniques. Our key findings reveal that while signature-based methods effectively identify known attack patterns, they fall short against novel threats. In contrast, AI-based approaches, particularly ML and DL, demonstrate superior performance in detecting previously unseen attacks. However, their efficiency is highly dependent on the quality of training data and model robustness. Our comparative analysis indicates that ML and DL methods achieve higher detection rates and lower false positives in experimental settings, underscoring the importance of high-quality datasets and resilient models. By highlighting the strengths and limitations of both approaches, this study provides valuable insights for researchers and cybersecurity experts. The need for an effective and diversified DDoS detection mechanism in the developing IoT and SDN domains is evident. While conventional methods remain relevant, AI-based strategies offer a dynamic avenue for enhancing security.

Read the paper · More papers on PaperTik