Deep Learning for Multi-Class DDoS Detection in SDNs: A CNN-LSTM Based Approach
S S Mridhulaa, Mudigonda Lakshmi Sravya, Sindhu Ravindran, Fizza Ghulam Nabi, V. Shenbaga Priya · 2025
Recently Distributed Denial of Service (DDoS) attacks have increased extensively, taking about 35% of all cyber threats among which the attack characteristic rises around 300% within the past five years through ICMP, TCP SYN, and UDP based floods that threaten Software Defined Networks (SDN). In order to overcome this issue, we develop deep learning based model that merges both Convolutional Neural Networks (CNN) and Long Short Term Memory networks (LSTM) in which CNNs extract spatial features and LSTM provides sequential traffic patterns. To further enhance detection, we then incorporate Bidirectional LSTMs (BiLSTMs), along with an attention mechanism, to improve accuracy of feature representation and classification. Our experimental results using a real world DDoS dataset with ICMP, TCP, and UDP attack scenarios show that the CNN - LSTM model has an accuracy of 85.59%, CNN BiLSTM with 86.92%, and CNN BiLSTM with Attention to 87.65%. These results indicate that deep learning models are a viable path for real time DDoS detection in SDN and provide a method of scalability and robustness in improving network security and resilience.