An adaptive framework for real-time detection and mitigation of DDoS attacks in software-defined networks
摘要
Distributed Denial of Service (DDoS) attacks present a significant threat to Software-Defined Networks (SDNs) by taking advantage of their centralized control structure and adaptable design. This research proposes a novel machine learning-driven framework for real-time DDoS attack detection and mitigation in SDN environments using the RYU controller. By integrating advanced machine learning techniques with SDN’s programmable infrastructure, the framework aims to accurately identify and swiftly mitigate DDoS attack patterns, overcoming the limitations of traditional rule-based approaches. The study develops a comprehensive machine-learning pipeline for feature engineering, model training, and real-time traffic classification. Multiple machine learning classifiers were evaluated on realistic traffic scenarios, with Decision Tree and Random Forest models achieving the highest accuracy of 99.93%, precision of 99.93%, and F1 score of 99.93%, while maintaining very low false negative and false positive rates. In contrast, Naïve Bayes performed poorly with an accuracy of 62.52%. Mitigation effectiveness was demonstrated through significant reductions in malicious traffic, and scalability was validated under increasing traffic volumes and network sizes. These results establish the framework as a robust and adaptive solution that outperforms traditional rule-based methods, enhancing SDN resilience against evolving DDoS threats.