Back to feed
Conference Open access

A Hybrid CNN-GRU Approach for Detecting DDoS Attacks in Software Defined Networks

2026 · E3S Web of Conferences · 0 citations · 11 references

Abstract

Software Defined Networking (SDN) introduces centralized control mechanisms that improve network programmability and management; however, this architectural shift also exposes the control plane to critical security threats, particularly Distributed Denial of Service (DDoS) attacks. This paper presents a hybrid deep learning–based detection framework that integrates Convolutional Neural Networks (CNN) with Gated Recurrent Units (GRU) to enhance DDoS detection in SDN environments. The proposed CNN-GRU architecture combines spatial feature extraction with temporal traffic modeling to improve detection accuracy while maintaining practical inference latency. Experiments conducted using the CICIDS2018 dataset demonstrate that the proposed model achieves an overall classification accuracy of 99.98%, with precision and recall values exceeding 99.9% across both benign and attack traffic classes. The model records an average detection latency of approximately 219.8 ms per traffic instance, offering a favorable balance between detection performance and computational efficiency. Comparative evaluation against existing machine learning and deep learning approaches indicates that the proposed framework achieves competitive accuracy while maintaining deployment-oriented processing speeds. These results suggest that the CNN-GRU model is well-suited for SDN security monitoring under controlled experimental conditions.

Read PDF