Self-similarity-based DDoS Detection for Software-defined Networks

Mohamad Khattar Awad, Ghazal Alsholi, Haniah Altabaa, Dania Hani Abu Daqar, Shahad Alshaher, Hamed Alazemi · 2025

The emergence of software-defined networks (SDN) has made the network flexible, programmable, and responsive to change. However, the architectural characteristics of SDN make the network vulnerable to various security attacks. Distributed denial of service (DDoS) is one such attack that aims to exhaust the network’s computational and bandwidth resources, blocking legitimate users’ access. This paper aims to study the effectiveness of using the self-similarity property, measured by the Hurst-exponent, in detecting DDoS attacks on the SDN controller. Simulation results have shown that normal and attack traffic flows captured at the controller have different degrees of self-similarity. Specifically, attack traffic flows show high levels of self-similarity, whereas normal traffic flows show lower degrees. Experiments demonstrated an average of 35% difference between the Hurst-exponent values of normal and attack traffic flows obtained, making it effective in classifying traffic flows and detecting attacks.

Read the paper · More papers on PaperTik