Enhancing DDoS Attack Classification through SDN and Machine Learning: A Feature Ranking Analysis

Authors

  • Aymen AlAwadi Department of Computer Science, Faculty of Education, University of Kufa, Iraq – Najaf https://orcid.org/0000-0001-7581-1682
  • Kawthar Rasoul ALesawi Department of Computer Science, Faculty of Education, University of Kufa, Iraq - Najaf

DOI:

https://doi.org/10.30572/2018/KJE/160221

Keywords:

SDN, DDOS, Machine Learning, Classification, Feature Ranking

Abstract

Due to the growing dependence of digital services on the Internet, Distributed Denial of Service (DDoS) attacks are a common threat that can cause significant disruptions to online operations and financial losses. Machine learning (ML) offers a promising way for early DDoS attack detection due to its ability to analyze large datasets and identify patterns. However, adding too many features to the ML might reduce its effectiveness in identifying the attacks provided by central network paradigms such as the Software-Defined Network (SDN). In this research, we investigate the effectiveness of the ML methods such as (Random Forest (RF), Naive Base (NB), and K-Nearest Neighbor’s (KNN)) combining SDN to enhance the classification of DDoS attacks. We leverage three diverse datasets: DDoS attack SDN, CICDDoS2019, and SDN-DDOS-TCP-SYN dataset.  By leveraging cross-feature selection and feature ranking techniques, such as information gain, gain ratio, and Gini importance, we could identify the most relevant network features for DDoS attacks. We reduced the feature up to 5 effective features without compromising the classification accuracy. The experimental results show that the proposed models achieved an accuracy of 100% for both Random Forest (RF) and K-Nearest Neighbor (KNN), and 99.8% for Naive Bayes (NB). Due to their high accuracy and lower complexity, KNN and NB outperform ML algorithms in this study

Downloads

Download data is not yet available.

References

Ali, T.E., Chong, Y.W. and Manickam, S. (2023) ‘Comparison of ML/DL Approaches for Detecting DDoS Attacks in SDN’, Applied Sciences (Switzerland), 13(5). Available at: https://doi.org/10.3390/app13053033. DOI: https://doi.org/10.3390/app13053033

Aristovnik, A. et al. (2021) ‘Impacts of the Covid-19 Pandemic on Life of Higher Education Students: Global Survey Dataset from the First Wave’, Data in Brief, 39(January), pp. 1–34. Available at: https://doi.org/10.1016/j.dib.2021.107659. DOI: https://doi.org/10.1016/j.dib.2021.107659

Barznji, A.O. and Ameen, J.J.H. (2021) ‘Wi-Max Network Simulation for Salahaddin University New Campus’, Kufa Journal of Engineering, 12(4), pp. 1–13. Available at: https://doi.org/10.30572/2018/kje/120401. DOI: https://doi.org/10.30572/2018/kje/120401

Buczak, A.L. and Guven, E. (2016) ‘A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection’, IEEE Communications Surveys and Tutorials, 18(2), pp. 1153–1176. Available at: https://doi.org/10.1109/COMST.2015.2494502. DOI: https://doi.org/10.1109/COMST.2015.2494502

Deepa, V. (2019) ‘Design of Ensemble Learning Methods for DDoS Detection in SDN Environment’, 2019 International Conference on Vision Towards Emerging Trends in Communication and Networking (ViTECoN), pp. 1–6. DOI: https://doi.org/10.1109/ViTECoN.2019.8899682

Dong, S. and Sarem, M. (2020) ‘DDoS Attack Detection Method Based on Improved KNN with the Degree of DDoS Attack in Software-Defined Networks’, IEEE Access, 8, pp. 5039–5048. Available at: https://doi.org/10.1109/ACCESS.2019.2963077. DOI: https://doi.org/10.1109/ACCESS.2019.2963077

Gupta, Karan; Sharma, Shivam; Kumar, S. (2021) No Title. Available at: https://doi.org/10.17632/8nb4cdwc9h.1.

Han, D. et al. (2024) ‘Traffic Feature Selection and Distributed Denial of Service Attack Detection in Software-Defined Networks Based on Machine Learning’, Sensors, 24(13). Available at: https://doi.org/10.3390/s24134344. DOI: https://doi.org/10.3390/s24134344

Hosseini, S. and Azizi, M. (2019) ‘The hybrid technique for DDoS detection with supervised learning algorithms’, Computer Networks, 158, pp. 35–45. Available at: https://doi.org/10.1016/j.comnet.2019.04.027. DOI: https://doi.org/10.1016/j.comnet.2019.04.027

Laassiri, F., Moughit, M. and Idboufker, N. (2018) ‘An Improvement of Performance in 4G LTE Using Software Defined Network’, Colloquium in Information Science and Technology, CIST, 2018-Octob(12), pp. 508–513. Available at: https://doi.org/10.1109/CIST.2018.8596517. DOI: https://doi.org/10.1109/CIST.2018.8596517

Ma, R. et al. (2023) ‘Real-Time Detection of DDoS Attacks Based on Random Forest in SDN’, Applied Sciences (Switzerland), 13(13). Available at: https://doi.org/10.3390/app13137872. DOI: https://doi.org/10.3390/app13137872

Mansoor, A. et al. (2023) ‘Deep Learning-Based Approach for Detecting DDoS Attack on Software-Defined Networking Controller’, pp. 1–21. DOI: https://doi.org/10.3390/systems11060296

Nadeem, M.W. et al. (2022) ‘Ddos detection in sdn usingmachine learning techniques’, Computers, Materials and Continua, 71(1), pp. 771–789. Available at: https://doi.org/10.32604/cmc.2022.021669. DOI: https://doi.org/10.32604/cmc.2022.021669

Najar, A.A. and Manohar Naik, S. (2024) ‘Cyber-Secure SDN: A CNN-Based Approach for Efficient Detection and Mitigation of DDoS attacks’, Computers and Security, 139, p. 103716. Available at: https://doi.org/10.1016/j.cose.2024.103716. DOI: https://doi.org/10.1016/j.cose.2024.103716

Nisha Ahuja Singal, Gaurav Mukhopadhyay, D. (2020) Dataset”, “DDOS attack SDN, 27 Sep 2020. Available at: https://doi.org/10.17632/jxpfjc64kr.1.

O. Hasan, A. (2022) ‘Application Based performance monitoring heavy data transmission of Local Area Network’, Kufa Journal of Engineering, 13(3), pp. 14–40. Available at: https://doi.org/10.30572/2018/kje/130302. DOI: https://doi.org/10.30572/2018/kje/130302

Orange Data Mining (2024) 2024.

Piñeiro, V. et al. (2020) ‘A scoping review on incentives for adoption of sustainable agricultural practices and their outcomes’, Nature Sustainability, 3(10), pp. 809–820. Available at: https://doi.org/10.1038/s41893-020-00617-y. DOI: https://doi.org/10.1038/s41893-020-00617-y

Polat, H. and Polat, O. (2020) ‘Detecting DDoS Attacks in Software-Defined Networks Through Feature Selection Methods and Machine Learning Models.pdf’, Mdpi [Preprint]. DOI: https://doi.org/10.3390/su12031035

Sadhwani, S. et al. (2023) ‘A Lightweight Model for DDoS Attack Detection Using Machine Learning Techniques’, Applied Sciences (Switzerland), 13(17). Available at: https://doi.org/10.3390/app13179937. DOI: https://doi.org/10.3390/app13179937

Samaan, S.S. and Jeiad, H.A. (2023) ‘Feature-based real-time distributed denial of service detection in SDN using machine learning and Spark’, Bulletin of Electrical Engineering and Informatics, 12(4), pp. 2302–2312. Available at: https://doi.org/10.11591/eei.v12i4.4711. DOI: https://doi.org/10.11591/beei.v12i4.4711

Santos, R. et al. (2020) ‘Machine learning algorithms to detect DDoS attacks in SDN’, Concurrency and Computation: Practice and Experience, 32(16), pp. 1–14. Available at: https://doi.org/10.1002/cpe.5402. DOI: https://doi.org/10.1002/cpe.5402

Talukder, Md Alamin; Uddin, M.A. (2023) “CIC-DDoS2019 Dataset”, 3 March 2023 | Version 1. Available at: https://doi.org/10.17632/ssnc74xm6r.1.

Tonkal, Ö. et al. (2021) ‘Machine Learning Approach Equipped with Neighbourhood Component Analysis for DDoS Attack Detection in Software-Defined Networking’, Electronics, 10(11), p. 1227. Available at: https://doi.org/10.3390/electronics10111227. DOI: https://doi.org/10.3390/electronics10111227

Urbanowicz, R.J. et al. (2018) ‘Relief-based feature selection: Introduction and review’, Journal of Biomedical Informatics, 85, pp. 189–203. Available at: https://doi.org/10.1016/j.jbi.2018.07.014. DOI: https://doi.org/10.1016/j.jbi.2018.07.014

Xing, E.P., Jordan, M.I. and Karp, R.M. (2001) ‘Feature selection for high-dimensional genomic microarray data’, Proceedings of the 18th International Conference on Machine Learning, pp. 601–608.

Downloads

Published

2025-04-30

How to Cite

AlAwadi, Aymen, and Kawthar Rasoul ALesawi. “Enhancing DDoS Attack Classification through SDN and Machine Learning: A Feature Ranking Analysis”. Kufa Journal of Engineering, vol. 16, no. 2, Apr. 2025, pp. 344-66, https://doi.org/10.30572/2018/KJE/160221.

Share