Implementation and Analysis of Mitigation of Distributed Denial of Service Network Time Protocol Amplification Attacks on Software Defined Networks Using Access Control Lists
Christine Nathalia Limbong, M. Teguh Kurniawan, Muhammad Fathinuddin · 2025
Network Time Protocol amplification attacks can really mess up Software-Defined Networking setups, hammering controllers and throwing IoT networks into chaos. We built a framework that mixes Support Vector Machine detection with Access Control List mitigation, all running on the Ryu controller, to fight back. By zeroing in on inter-arrival time and packet details—not just counting packets like Gondim et al. did—our SVM nailed 94.35% accuracy without flagging any legit traffic. Okay, so in Mininet tests with 11,553 data points, NTP attacks tanked throughput to$\mathbf{4 5}$Mbps, but our ACLs bounced it back to 96 Mbps, doing better than Gondim's firewalls. This setup works great for IoT and SDN data centers needing quick fixes. Here's the thing: an 8.08 % miss rate and Mininet's tiny 15 -host topology mean real networks might be tougher. Next up, we're itching to try dynamic thresholds or maybe Random Forest to catch more attacks and beef up SDN security.