Adaptive Rate Limiting for Distributed Denial of Service Mitigation in Software Defined Networks
R. Satheeskumar, S. Suruthi, Nalin Kumar N K, Kothapally Prem, N Vaseekaran, Vigneshwaran M · 2025
The strong evolution of Distributed Denial of Service (DDoS) attacks has made static rate-limiting methods less effective, as these methods use fixed thresholds and do not respond to dynamic patterns of attacks. To meet this challenge, we introduce an adaptive rate limiter that combines real-time traffic inspection and machine learning to dynamically fine-tune its defense strategy. This system constantly observes network traffic, creates a baseline of normal behavior, and detects anomalies that are characteristic of DDoS attacks By employing adaptive thresholds, it can differentiate between legitimate users and malicious actors, ensuring minimal disruption to genuine traffic while effectively mitigating attacks. Some of the major features of the suggested solution are traffic control granularity, scalability to manage high-volume attacks, and easy integration with current security infrastructure. The adaptive rate limiter not only improves the attack detection accuracy but also minimizes false positives, thus providing optimal utilization of resources. Through extensive testing and real-world deployment, the system demonstrates its ability to mitigate extensive vectors of DDoS attacks, including HTTP floods, SYN floods, and botnet-driven attacks. This innovative approach is a breakthrough in DDoS defense, with an active, intelligent, and dynamic solution that protects modern networks from continuously changing threats.