A Review of Machine Learning Approaches for DDoS Attack Detection and Mitigation in Software-Defined Networking
Keywords:
software-defined networking; distributed denial-of-service; DDoS detection; SDN security; machine learning; open datasets; cyberattack mitigation.Abstract
Software-defined networking (SDN) has changed the way networks are designed and controlled by separating the control plane from the data plane. This separation gives administrators a more programmable, centralized, and flexible way to manage traffic. At the same time, the SDN controller becomes a critical point of exposure. Distributed denial-of-service (DDoS) attacks can overload the controller, switches, links, or servers and can prevent legitimate users from accessing network services. The reviewed paper examines DDoS threats in SDN by discussing attack categories, public datasets, detection methods, and mitigation frameworks. It emphasizes the importance of open datasets for reproducible experiments and highlights that many available datasets are either outdated, not SDN-specific, or limited in attack diversity. The study also shows that machine learning and deep learning models have become central tools for detection, although their real-world usefulness depends on dataset quality, controller overhead, scalability, and false-positive control.
References
Hill, W., Acquaah, Y. T., Mason, J., Limbrick, D., Teixeira-Poit, S., Coates, C., & Roy, K. (2024). DDoS in SDN: a review of open datasets, attack vectors and mitigation strategies. Discover Applied Sciences, 6, Article 472. https://doi.org/10.1007/s42452-024-06172-x
S. Sezer et al., “Are we ready for SDN? Implementation challenges for software-defined networks,” IEEE Commun. Mag., vol. 51, no. 7, pp. 36–43, Jul. 2013.
I.A. Valdovinos et al., “Emerging DDoS attack detection and mitigation strategies in software-defined networks: Taxonomy, challenges and future directions,” J. Netw. Comput. Appl., vol. 187, 2021, Art. no. 103093.
Open Networking Foundation, Jun. 2014. [Online]. Available: https://www.opennetworking.org/
C. Hu, L. Han, and S.M. Yiu, “Efficient and secure multi-functional searchable symmetric encryption schemes,” Secur. Commun. Netw., vol. 9, pp. 34–42, 2016.
A.Praseed and P.S. Thilagam, “DDoS attacks at the application layer: Challenges and research perspectives for safeguarding web applications,” IEEE Commun. Surv. Tutor., vol. 21, pp. 661–685, 2019.
T.Mahjabin, Y.Xiao, G.Sun, and W.Jiang, “A survey of distributed denial of-service attack, prevention, and mitigation techniques,” Int. J. Distrib. Sens. Netw., vol. 13, 2017.
M.A.M. Yusof, F.H.M. Ali, and M.Y. Darus, “Detection and Defense Algorithms of Different Types of DDoS Attacks,” Int. J. Eng. Technol., vol. 9, pp. 410–444, 2018.
N. Ahuja, G. Singal, and D. Mukhopadhyay, “DDOS attack SDN Dataset,” Mendeley Data, V1, 2020, doi: 10.17632/jxpfjc64kr.1. Available: https://www.kaggle.com/datasets/aikenkazin/ddos-sdn-dataset
I.Sharafaldin, A.H. Lashkari, S. Hakak, and A.A. Ghorbani, “Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Tax onomy,” in Proc. 2019 Int. Carnahan Conf. Security Technol. (ICCST), Chennai, India, 2019, pp. 1-8, doi: 10.1109/CCST.2019.8888419.
Ö. Tonkal, H. Polat, E. Başaran, Z. Cömert, and R. Kocaoğlu, “Machine Learning Approach Equipped with Neighbourhood Component Analysis for DDoS Attack Detection in Software-Defined Networking,”Electronics, vol. 10, no. 1227, 2021.
J.A. Perez-Diaz, I.A. Valdovinos, K.K.R. Choo, and D. Zhu, “A Flex ible SDN-Based Architecture for Identifying and Mitigating Low-Rate DDoS Attacks Using Machine Learning,” IEEE Access, vol. 8, pp. 155859–155872, 2020.
N. Ravi and S.M. Shalinie, “Learning-Driven Detection and Mitigation of DDoS Attack in IoT via SDN-Cloud Architecture,” IEEE Internet Things J., vol. 7, pp. 3559–3570, 2020.
H. Polat, O. Polat, and A. Cetin, “Detecting DDoS Attacks in Software Defined Networks Through Feature Selection Methods and Machine Learning Models,” Sustainability, vol. 12, no. 1035, 2020.
M. AbdulRaheem, I.D. Oladipo, and A.L. Imoize, “Machine learning assisted snort and zeek in detecting DdoS attacks in software-defined networking,” Int. J. Inf. Technol., 2023. Available: https://doi.org/10.1007/s41870-023-01469-3
A.Makuvaza, D.S. Jat, and A.M. Gamundani, “Deep Neural Network (DNN) Solution for Real-time Detection of Distributed Denial of Service (DDoS)Attacks in Software Defined Networks (SDNs),” SN Comput. Sci., vol. 2, 2021.
M. Mittal, K. Kumar, and S. Behal, “DL-2P-DDoSADF: Deep learning based two-phase DDoS attack detection framework,” J. Inf. Secur. Appl., vol. 78, 2023, Art. no. 103609.
A.Makuvaza, D.S. Jat, and A.M. Gamundani, “Hybrid deep learning model for real-time detection of distributed denial of service attacks in soft ware defined networks,” in Emerging Trends in Data Driven Computing and Communications: Proc. DDCIoT 2021, Springer Singapore, 2021, pp. 1-13.
S. Haider, A. Akhunzada, G. Ahmed, and M. Raza, “Deep Learning based Ensemble Convolutional Neural Network Solution for Distributed Denial of Service Detection in SDNs,” in Proc. 2019 UK/China Emerging Technologies (UCET), 2019, pp. 1-4, doi: 10.1109/UCET.2019.8881856.
C. Li, Y. Wu, X. Yuan, Z. Sun, W. Wang, X. Li, and L. Gong, “Detection and defense of DDoS attack–based on deep learning in OpenFlow-based SDN,” Int. J. Commun. Syst., vol. 31, no. 5, p. e3497, 2018.
T. E. Ali, Y.-W. Chong, and S. Manickam, "Machine learning techniques to detect a DDoS attack in SDN: A systematic review," Applied Sciences, vol. 13, no. 5, p. 3183, 2023.
A.Hamarshe, H. I. Ashqar, and M. Hamarsheh, "Detection of DDoS At tacks in Software Defined Networking Using Machine Learning Models," in *International Conference on Advances in Computing Research*, 2023, pp. 640–651.
A. Alashhab, M. S. Zahid, B. Isyaku, A. A. Elnour, W. Nagmeldin, A. Abdelmaboud, T. A. A. Abdullah, and U. Maiwada, "Enhancing DDoS attack detection and mitigation in SDN using an ensemble online machine learning model," IEEE Access, 2024.
Downloads
Additional Files
Published
Issue
Section
License
Copyright (c) 2026 Both journal and authors

This work is licensed under a Creative Commons Attribution 4.0 International License.




