A hybrid deep learning model for multi-class DDoS detection in SDN networks

被引:0
作者
Zaidoun, Ameur Salem [1 ,2 ]
Lachiri, Zied [1 ]
机构
[1] Univ Tunis EL Manar, Natl Engn Sch Tunis, Res Lab Signal, Image, Rue Bechir Salem Belkhiria Campus Univ Farhat HACH, Tunis 1002, Tunisia
[2] Higher Inst Technol Studies Siliana, Dept Informat Technol, Siliana 6100, Tunisia
关键词
SDN; DDoS; Multi-class; Deep learning; DNN; LSTM; ATTACK DETECTION;
D O I
10.1007/s12243-025-01085-1
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
This paper, as an extended version of a communication presented at the ISIVC'2024 conference, deals with security issues in the software-defined networks (SDN); it introduces a Distributed Denial of Service (DDoS) detection system leveraging deep learning (DL) features. The main objective is to enhance SDN security by accurately classifying DDoS attacks, improving efficiency, particularly for zero-day attack detection, and enabling targeted mitigation strategies. Our contribution focuses on refining a hybrid DL model with a novel architecture that applies algorithms simultaneously to distinguish the normal SDN traffic and five carefully selected other classes covering various attack kinds, using an optimized CIC-DDoS2019 dataset for more efficient classification. Compared to the conference paper, the model has been reinforced by the use of attention mechanisms and transformer architectures in addition to layers' adjustments and hyper-parameters re-settings. Additionally, the previously used training and testing data have been combined and split into three sets: 70% for training, 15% for validation (continuous partial evaluation), and 15% for final testing. The resulting solution (hybrid DNN-LSTM) demonstrated continuous exponential improvement of validation accuracy during the training step, recording a higher value near 99% and achieving a final testing accuracy of 98.84%. The improved model is suitable for real-world SDN systems, with its deployment, potential challenges, and practical benefits discussed.
引用
收藏
页码:459 / 472
页数:14
相关论文
共 34 条
  • [1] Cyber Threats Detection in Smart Environments Using SDN-Enabled DNN-LSTM Hybrid Framework
    Al Razib, Mohammad
    Javeed, Danish
    Khan, Muhammad Taimoor
    Alkanhel, Reem
    Muthanna, Mohammed Saleh Ali
    [J]. IEEE ACCESS, 2022, 10 : 53015 - 53026
  • [2] Ensemble Deep Learning Models for Mitigating DDoS Attack in Software-Defined Network
    Alanazi, Fatmah
    Jambi, Kamal
    Eassa, Fathy
    Khemakhem, Maher
    Basuhail, Abdullah
    Alsubhi, Khalid
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2022, 33 (02) : 923 - 938
  • [3] Alashhab AA, 2022, INT J ADV COMPUT SC, V13, P371
  • [4] A survey on DoS/DDoS mitigation techniques in SDNs: Classification, comparison, solutions, testing tools and datasets
    Alhijawi, Bushra
    Almajali, Sufyan
    Elgala, Hany
    Salameh, Haythem Bany
    Ayyash, Moussa
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2022, 99
  • [5] Amandeep K., 2024, K-DDoS-SDN: a distributed DDoS attacks detection approach for protecting SDN environment
  • [6] Survival Classification in Heart Failure Patients by Neural Network-Based Crocodile and Egyptian Plover (CEP) Optimization Algorithm
    Akalin, Fatma
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2024, 49 (03) : 3897 - 3914
  • [7] Assis MarcosVO F CL, 2020, Computers & Electrical Engineering
  • [8] Secure SDN-IoT Framework for DDoS Attack Detection Using Deep Learning and Counter Based Approach
    Cherian, Mimi
    Varma, Satishkumar L.
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (03)
  • [9] Cybersecurity CI, 2023, DDoS evaluation dataset (CIC-DDoS2019)
  • [10] Dandotiya Monika, 2024, 2024 IEEE International Conference on Interdisciplinary Approaches in Technology and Management for Social Innovation (IATMSI), P1, DOI 10.1109/IATMSI60426.2024.10502843