Ddos Attack Detection and Mitigation Using Machine Learning in a Balanced Multi-Controller Software-Defined Networking
Binod Sapkota, Babu Ram Dawadi, Shashidhar R. Joshi, Bibat Thokar · 2025
This research work proposes an efficient approach for establishing a well-balanced multicontroller software-defined networking (SDN) system capable of detecting and mitigating distributed denial of service (DDoS) attacks using various machine learning (ML) models. Due to the limited capacity of a single controller, handling the high traffic generated by numerous intelligent devices becomes challenging. To address this, multiple controllers are utilized. However, dynamic network traffic can lead to an uneven distribution of loads among controllers, necessitating a balanced network. To achieve this, switch migration based on latency is employed to ensure proper load balancing. Under normal circumstances, this maintains network stability, but the occurrence of a DDoS attack disrupts this equilibrium. The proposed approach continuously monitors incoming packets and identifies DDoS attacks using ML models such as XGBoost, LightGBM, and CatBoost. A comparative analysis based on test accuracy, precision, and F1 score reveals that CatBoost outperforms XGBoost and LightGBM. The methodology is assessed through emulation in Mininet, with detection and mitigation mechanisms implemented in the RYU controller. Experimental findings indicate enhancements in key performance metrics, including attack detection time, response delay for legitimate requests during an attack, and overall CPU utilization. The system effectively detects and mitigates DDoS attacks within the SDN control plane, thereby improving network security and stability.