Optimized Artificial Intelligence Model for DDoS Detection in SDN Environment

被引:13
作者
Al-Dunainawi, Yousif [1 ]
Al-Kaseem, Bilal R. [2 ]
Al-Raweshidy, Hamed S. [3 ]
机构
[1] AlShaab Univ, Coll Engn & Informat Technol, Dept Cybersecur Engn, Baghdad 10001, Iraq
[2] AlShaab Univ, Coll Engn & Informat Technol, Dept Commun Engn, Baghdad 10001, Iraq
[3] Brunel Univ London, Coll Engn Design & Phys Sci, Dept Elect & Elect Engn, London UB8 3PH, England
关键词
Artificial intelligence; distributed denial of service; hyperparameters tuning; mininet; NSGA-II; optimized model; Ryu controller; software defined networking; SOFTWARE-DEFINED NETWORKS; ATTACK DETECTION; MACHINE; SECURITY; IOT;
D O I
10.1109/ACCESS.2023.3319214
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service (DDoS) attacks continue to be a major security concern, threatening the availability and reliability of network services. Software-defined networking (SDN) has emerged as a promising solution to address this issue, enabling centralized network control and management. However, conventional SDN-based DDoS mitigation techniques often struggle to detect and mitigate sophisticated attacks due to their limited ability to analyze complex traffic patterns. This paper proposes an innovative and optimized approach that effectively combines mininet, Ryu controller, and one dimensional-convolutional neural network (1D-CNN) to detect and mitigate DDoS attacks in SDN environments. The proposed approach involves training the 1D-CNN model with labeled network traffic data to effectively identify abnormal patterns associated with DDoS attacks. Furthermore, seven hyperparameters of the trained 1D-CNN model were tuned using non-dominated sorting genetic algorithm II (NSGA-II) to achieve the best accuracy with minimum training time. Once the optimized 1D-CNN model detects an attack, the Ryu controller dynamically adapts the network policies and employs appropriate mitigation techniques to protect the network infrastructure. To evaluate the effectiveness of the optimized 1D-CNN model, extensive experiments were conducted using a simulated SDN environment with a realistic DDoS attack dataset. The experimental results demonstrate that the developed approach achieves significantly improved detection accuracy of 99.99% compared to other machine learning (ML) models. The NSGA-II enhances the optimized model accuracy with an improvement rate of 9.5%, 8%, 5.4%, and 2.6% when it is compared to logistic regression (LR), random forest (RF), support vector machine (SVM), and k-nearest neighbor (KNN) optimized models respectively. This research paves the way for future developments in leveraging deep learning (DL) driven techniques and SDN architectures to address evolving cybersecurity challenges.
引用
收藏
页码:106733 / 106748
页数:16
相关论文
共 38 条
  • [1] Security in Software Defined Networks: A Survey
    Ahmad, Ijaz
    Namal, Suneth
    Ylianttila, Mika
    Gurtov, Andrei
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04): : 2317 - 2346
  • [2] Automated DDOS attack detection in software defined networking
    Ahuja, Nisha
    Singal, Gaurav
    Mukhopadhyay, Debajyoti
    Kumar, Neeraj
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 187 (187)
  • [3] Migrating From Legacy to Software Defined Networks: A Network Reliability Perspective
    Al Mtawa, Yaser
    Haque, Anwar
    Lutfiyya, Hanan
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2021, 70 (04) : 1525 - 1541
  • [4] Ensemble Deep Learning Models for Mitigating DDoS Attack in Software-Defined Network
    Alanazi, Fatmah
    Jambi, Kamal
    Eassa, Fathy
    Khemakhem, Maher
    Basuhail, Abdullah
    Alsubhi, Khalid
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2022, 33 (02) : 923 - 938
  • [5] The (In)Security of Virtualization in Software Defined Networks
    Alharbi, Talal
    Portmann, Marius
    [J]. IEEE ACCESS, 2019, 7 : 66584 - 66594
  • [6] Two Novel SMOTE Methods for Solving Imbalanced Classification Problems
    Bao, Yuan
    Yang, Sibo
    [J]. IEEE ACCESS, 2023, 11 : 5816 - 5823
  • [7] Performance Evaluation Using RYU SDN Controller in Software-Defined Networking Environment
    Bhardwaj, Shanu
    Panda, S. N.
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2022, 122 (01) : 701 - 723
  • [8] Campesato O., 2020, Artificial Intelligence, Machine Learning, and Deep Learning
  • [9] SOFTWARE-DEFINED NETWORKING SECURITY: PROS AND CONS
    Dabbagh, Mehiar
    Hamdaoui, Bechir
    Guizani, Mohsen
    Rayes, Ammar
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 : 73 - 79
  • [10] DoS and DDoS attacks in Software Defined Networks: A survey of existing solutions and research challenges
    Eliyan, Lubna Fayez
    Di Pietro, Roberto
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 122 (122): : 149 - 171