Skip to content
Open access

An Adaptive and Scalable DDoS Prevention Framework for Software Defined Networks

Jul 2026 · International journal of computer information systems and industrial management applications · Vol 18, pp. 863-872 · 0 citations

TL;DR

The adaptive outline lessens controller CPU utilization, speeds up mitigation response times, lowers end-to-end latency, and keeps higher throughput when compared to static mitigation procedures, according to experimental evaluations carried out in a precise SDN emulation environment.

Abstract

Central governance and flexible network administration are made possible by Software Defined Networking (SDN); still, this architectural benefit also makes the control plane vulnerable to Distributed Denial of Service (DDoS) attacks. An extreme number of flow requests and packet-in events can significantly reduce controller effectiveness and interfere with network functions in the context of such attacks. In this work, we change and estimate an adaptive DDoS prevention framework based on knowledge gained from SDN emulation tests. Relatively than relying on predetermined mitigation thresholds, the framework dynamically adjusts mitigation strategies based on the attack's severity and the controller's present load. The proposed approach reduces unnecessary interactions in the control plane while maintaining service quality for authorized traffic by incorporating controller-aware decision-making. The adaptive outline lessens controller CPU utilization, speeds up mitigation response times, lowers end-to-end latency, and keeps higher throughput when compared to static mitigation procedures, according to experimental evaluations carried out in a precise SDN emulation environment

Read PDF

Similar papers

Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates the effectiveness of Machine Learning (ML) algorithms in detecting and addressing these attacks in real time. Using the Ryu controller, Mininet network emulator, and OpenFlow protocol, a realistic experimental environment was created to provide an accurate replica of the dynamic SDN behaviour under adverse circumstances. Empirical studies have demonstrated that distributed DDoS attacks, such as SYN, UDP, and ICMP flooding, substantially degrade network performance by reducing throughput, increasing packet loss, and exhausting switch flow table resources. To mitigate these effects, a suite of supervised machine learning classifiers, including Decision Tree, Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), and Naïve Bayes (NB), was instantiated and evaluated using traffic features captured on the emulated platform. The key performance indicators used to evaluate the classifiers included accuracy, precision, recall, and F1-score. The findings indicate that the Decision Tree and KNN models achieved detection rates above the 99% mark, with strong precision and recall scores, which in turn highlights their suitability for implementation in SDN-based security systems. This study provides experimental evidence that ML-based intrusion detection mechanisms can significantly enhance the resilience of SDNs to volumetric attacks. These results promote the implementation of adaptive and responsive security modules in SDN controllers, thereby increasing network resilience, particularly in large and dynamically programmable networks.

Kamal Singh, B. Kumar · 0 citations
Review Open access Aug 2026

Software-Defined Networking Security: Architecture, Attack Surface, and Resilient Mechanisms

Software-Defined Networking (SDN) is a new way of thinking about networking in which the networking function is split into two planes: control plane and data plane. The aim of SDN is to give network managers greater control over network configuration, increased programmability, flexibility, and efficient use of network resources. These features have driven the rapid-fire uptake of SDN in today's communications networks, cloud and data center. However, all these appealing features can create additional security problems, increasing the attack surface and putting critical elements at risk of breaches. With the rapid emergence of SDN, network security and resilience are emerging top topics of researchers' interests. This paper provides a comprehensive survey of the SDN security by covering its architecture, key benefits and potential vulnerabilities. It explores potential attacks on the data plane, attacks on the communication channels outside the control plane, security challenges in the control plane, and existing approaches and proposed countermeasures from the literature. Moreover, the paper presents a survey of existing work, lists open challenges, research gaps and future research directions and implements some new trends related to secure, scalable and resilient SDN environments.

AJIT Karki, V. R, H. A. Akarte et al. · 0 citations
Open access 2026

DDoS Defense Model on 5G Network Slices

A 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN is proposed.

Kun-Lin Tsai, Shih-Ting Chiu, Chihhsiong Shih et al. · 0 citations
Conference Jul 2026

Towards a Reference Architecture for Intelligent Anomaly Detection in Software-Defined Networks

Emerging technologies such as Cloud Computing, 5G, the Internet of Things (IoT), and Edge Computing demand the management of large-scale and highly dynamic network infrastructures. Traditional network configuration does not scale efficiently, whereas Software-Defined Networking (SDN) enables centralized control and simplified management. Despite these benefits, SDN environments still face significant challenges related to security and fine-grained anomaly detection. Several studies have demonstrated the effectiveness of computational intelligence (CI) techniques for anomaly detection in SDN. However, the diversity of network anomalies and CI-based solutions introduces substantial heterogeneity, making model selection and integration challenging. This paper proposes a reference architecture designed to validate, promote, and explain the suitability of different CI techniques for distinct network anomaly scenarios. The proposed architecture adopts a hexagonal microservices design and a unified information model aligned with the application, information, and process layers of the TM Forum Open Digital Architecture (ODA). Validation was performed through a proofof-concept prototype using two datasets and seven machine learning algorithms. The results demonstrate the importance of architectural flexibility, enabling the dynamic integration and replacement of CI models to support adaptive and scalable SDN anomaly detection.

Rivaldo Fernandes, B. Dalmazo, A. Riker et al. · 0 citations
Open access Aug 2026

Lightweight Rescaled Range R/S-Based Real-Time DDoS Detection for Software-Defined Networks

Software-defined Networking (SDN) is a promising networking architecture that separates the control and data planes to allow flexible network management. However, the SDN architecture makes networks vulnerable to various security threats, such as Distributed Denial-of-Service (DDoS) attacks. A DDoS attack is one of the most common SDN threats, aiming to exhaust a network’s computational and bandwidth resources. Self-similarity is a statistical property of time series in which data patterns repeat at different time scales. Several studies have shown that network traffic exhibits increased self-similarity during DDoS attacks, making it a promising tool for DDoS detection. Despite the effectiveness of statistical methods for detecting DDoS, some methods, such as self-similarity, are discarded due to their high computational cost, leading to detection delays. This paper proposes a lightweight Rescaled Range (R/S)-based scheme for effective real-time DDoS attack detection in SDN. The scheme employs the Welford online algorithm to compute statistical parameters of the R/S scheme. Experimental results demonstrate that the proposed scheme efficiently captures changes in self-similarity and detects TCP/UDP DDoS attacks in real time. Moreover, it achieves high detection performance compared to other R/S methods, with a False Positive Rate (FPR) below 0.5% and an average computation time of 0.047 ms.

M. Awad, Ghazal Alsholi, Haniah Altabaa et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.