Real-Time DDoS Attack Detection in SDN Based on En-CNN and OptiLGBM
Guoqing Yang, Xiaoying Wang, Chunhui Li, Xinyu Li, Jinsha Zhang, Fangfang Cui, Ruize Gu · IEEE Access · 2025
Distributed Denial-of-Service (DDoS) attacks pose serious risks to Software-Defined Networks (SDN), where existing detection methods often suffer from low accuracy, high latency, and high false positives. To address these issues, this study applies an adaptive Borderline-SMOTE (BS) method to balance the CICDDoS2019 dataset, effectively reducing false positives. Enhanced Convolutional Neural Networks (En-CNN) is designed to perform efficient traffic feature extraction with minimal latency, while Optimized LightGBM (OptiLGBM) provides fast and accurate classification through tuned parameters for rapid convergence. The proposed hybrid model integrates En-CNN and OptiLGBM. Both models are deployed within the Ryu SDN controller. Together, they form a real-time framework for DDoS attack detection and mitigation. Experimental results demonstrate an accuracy of 99.98% and an average response time of less than 1 second, outperforming baseline models. Real-network tests confirm that the system can block attacks and restore normal traffic within 3 seconds, highlighting its practical value for SDN security.