SDN-Based Framework for Real-Time DDoS Detection and Mitigation using Mininet, POX, and Snort
Gollapudi Mounika, Venkat Sai, V. Yeshaswini, P. Hemalatha, A. Sai Sharan · 2025
Distributed denial of service (DDoS) attacks have increased in size and sophistication, and they often overpower and evade traditional network security defenses, resulting in substantial service disruption. This project presents an exceptionally strong, software-defined networking (SDN) based solution to detect and mitigate DDoS attacks in real time, by utilizing Mininet, the POX controller and Snort Intrusion Detection System (IDS). Mininet is used to simulate a scalable virtual network infrastructure so that realistic attack scenarios can be set up and tested. Snort serves as the primary IDS component and is constantly monitoring the network traffic, using both signature and anomaly based detection methods to find anomalous patterns of behavior in the network traffic and raise alerts when suspicious traffic is observed, e.g., extreme SYN requests, ICMP floods, UDP amplification attacks, etc. When Snort raises real-time alerts, it pushes the alerts directly to the POX controller that has central control of the network via OpenFlow. The controller will observe the alert to identify the source and nature of the attack and then dynamically modify the OpenFlow switch flow tables to drop, block, rate-limit or forward the malicious traffic. Legitimate users will be minimally impacted while the DDoS attack can be disrupted and service quality, and availability can be assured. The SDN model provides real-time updates to security policies in response to changing threats. The modularity of the framework accommodates integration of such improvements as machine learning classifiers or visual dashboards. Being based on open-source tools, this solution is affordable and acceptable for academic research, laboratory settings, and practical deployment. It also provides a hands-on environment for students of cybersecurity to experiment with SDN-based security. The architecture can be extended further with distributed controllers, load balancing, and cloud-native to enhance scalability. In conclusion, the project illustrates how SDN integrated with intrusion detection gives a pre-assault, smart, and flexible method to combat DDoS attacks and enhances contemporary network security measures.