Towards a Reference Architecture for Intelligent Anomaly Detection in Software-Defined Networks
Abstract
Emerging technologies such as Cloud Computing, 5G, the Internet of Things (IoT), and Edge Computing demand the management of large-scale and highly dynamic network infrastructures. Traditional network configuration does not scale efficiently, whereas Software-Defined Networking (SDN) enables centralized control and simplified management. Despite these benefits, SDN environments still face significant challenges related to security and fine-grained anomaly detection. Several studies have demonstrated the effectiveness of computational intelligence (CI) techniques for anomaly detection in SDN. However, the diversity of network anomalies and CI-based solutions introduces substantial heterogeneity, making model selection and integration challenging. This paper proposes a reference architecture designed to validate, promote, and explain the suitability of different CI techniques for distinct network anomaly scenarios. The proposed architecture adopts a hexagonal microservices design and a unified information model aligned with the application, information, and process layers of the TM Forum Open Digital Architecture (ODA). Validation was performed through a proofof-concept prototype using two datasets and seven machine learning algorithms. The results demonstrate the importance of architectural flexibility, enabling the dynamic integration and replacement of CI models to support adaptive and scalable SDN anomaly detection.