Implementation and Analysis of DNS Amplification Attack Mitigation in Software-Defined Networks Using Access Control Lists
Mutiara Fanny Maulida, M. Teguh Kurniawan, Muhammad Fathinuddin · 2025
The increasing reliance on internet-based infrastructure has made modern networks more vulnerable to cyberattacks, particularly Distributed Denial of Service (DDoS) attacks such as DNS amplification. This type of attack exploits open DNS resolvers to flood a victim with amplified responses generated from spoofed DNS queries, often resulting in service degradation or complete disruption. DNS amplification is especially dangerous due to its high amplification factor and ease of execution, making it a preferred vector among attackers. To address this threat, this paper presents a real-time detection and mitigation system for DNS amplification attacks in Software Defined Networks (SDN), implemented using the Ryu controller. The detection mechanism utilizes a Support Vector Machine (SVM) classifier trained on flow-level traffic features, including protocol type, port numbers, packet length, and DNS-specific attributes. All features were normalized to ensure consistency, and the model was fine-tuned using grid search with cross-validation. Upon detection, the system dynamically applies Access Control List (ACL) rules to block matching malicious traffic at the switch level, reducing reliance on centralized decision-making and improving response time. The system was deployed and tested in a Mininet-based SDN simulation and evaluated using 9,824 test packets. The classifier achieved 94.6% accuracy with no false positives and a mitigation success rate of 89.4%, effectively blocking 4,391 attack packets while allowing all 4,912 normal packets to pass. Real-time testing demonstrated that classification latency remained below 2 milliseconds, and ACL rule injection was completed within 10 milliseconds. These results confirm that the proposed system offers a lightweight, responsive, and practical defense mechanism that enhances SDN infrastructure resilience against amplification-based DDoS threats without compromising normal traffic performance.