DDoS Attack Detection for Software-Defined Network Architecture Based on Artificial Intelligence
Bao Pham-Thai, My Nguyen-Le-Ha, Luan Van-Thien, Thuat Nguyen-Khanh, Quan Le‐Trung · 2025
The Software-Defined Networking (SDN) model provides significant advantages for network administrators by facilitating traffic initialization, control, and management. SDN optimizes bandwidth and resource utilization through efficient traffic routing and network management automation. Distributed Denial-of-Service (DDoS) attacks target websites and servers by disrupting network services and depleting application resources. In SDN, control functions are centralized in the control plane, while network devices handle packet forwarding. DDoS attacks in SDN impact all network layers, exploiting bandwidth and limiting infrastructure scalability. To mitigate DDoS attacks, Artificial Intelligence (AI)-based approaches, specifically Machine Learning (ML) and Deep Learning (DL), are integrated into Intrusion Detection and Prevention Systems for enhanced detection and response. Our proposed approach involves building an SDN network architecture, collecting traffic, and utilizing ML and DL models for DDoS detection. In ML models, feature extraction is performed before classification, while DL models preprocess network traffic by normalizing and converting it into images for classification. Among the evaluated models, Random Forest (RF) and DenseNet demonstrated the best performance, achieving a high accuracy of 99.87% and 99.4% while excelling in training time, inference speed, and model size.