SDN Intrusion Detection using Meta-Heuristic Optimization and K-Nearest Neighbors Classifier
Sanjana A More, Amit V Kachavimath · Procedia Computer Science · 2025
The rapid development of network technologies has made Software-Defined Networking (SDN) architectures more prevalent due to their enhanced flexibility and control over network resources. However, this flexibility introduces new vulnerabilities, necessitating strong security measures. Intrusion Detection Systems (IDS) are vital for protecting SDN environments from malicious activities. Meta-heuristic algorithms are optimization approaches that find near-optimal solutions to intricate issues by acquiring inspiration from natural processes or behaviors. We have proposed an innovative approach to intrusion detection in SDN using meta-heuristic and machine-learning techniques. By leveraging SDN’s programmability, we propose an approach that integrates real-time analytics with meta-heuristic feature selection processes and machine learning for Classification. Our system uses both supervised learning methods to detect intrusion patterns from network traffic flows and control plane interactions. Experimental results show that our IDS surpasses traditional signature-based systems in detection accuracy and response time. We trained the machine learning models on the InSDN dataset, covering various forms of network attacks, such as Distributed Denial of Service (DDoS), User-to-root (U2R), Botnet, Web Attack, Probe, and Brute Force Attack (BFA). The genetic algorithm outperformed the ant colony optimization technique by systematically selecting the most relevant features, thereby improving the Classification accuracy. The KNN classifier performed better than the other classifiers using these features. The system’s adaptive nature allows it to respond to emerging threats, maintaining protection in dynamic network environments.