Enhancing DDoS Attack Classification through SDN and Machine Learning: A Feature Ranking Analysis
DOI:
https://doi.org/10.30572/2018/KJE/160221Keywords:
SDN, DDOS, Machine Learning, Classification, Feature RankingAbstract
Due to the growing dependence of digital services on the Internet, Distributed Denial of Service (DDoS) attacks are a common threat that can cause significant disruptions to online operations and financial losses. Machine learning (ML) offers a promising way for early DDoS attack detection due to its ability to analyze large datasets and identify patterns. However, adding too many features to the ML might reduce its effectiveness in identifying the attacks provided by central network paradigms such as the Software-Defined Network (SDN). In this research, we investigate the effectiveness of the ML methods such as (Random Forest (RF), Naive Base (NB), and K-Nearest Neighbor’s (KNN)) combining SDN to enhance the classification of DDoS attacks. We leverage three diverse datasets: DDoS attack SDN, CICDDoS2019, and SDN-DDOS-TCP-SYN dataset. By leveraging cross-feature selection and feature ranking techniques, such as information gain, gain ratio, and Gini importance, we could identify the most relevant network features for DDoS attacks. We reduced the feature up to 5 effective features without compromising the classification accuracy. The experimental results show that the proposed models achieved an accuracy of 100% for both Random Forest (RF) and K-Nearest Neighbor (KNN), and 99.8% for Naive Bayes (NB). Due to their high accuracy and lower complexity, KNN and NB outperform ML algorithms in this study
Downloads
References
Ali, T.E., Chong, Y.W. and Manickam, S. (2023) ‘Comparison of ML/DL Approaches for Detecting DDoS Attacks in SDN’, Applied Sciences (Switzerland), 13(5). Available at: https://doi.org/10.3390/app13053033. DOI: https://doi.org/10.3390/app13053033
Aristovnik, A. et al. (2021) ‘Impacts of the Covid-19 Pandemic on Life of Higher Education Students: Global Survey Dataset from the First Wave’, Data in Brief, 39(January), pp. 1–34. Available at: https://doi.org/10.1016/j.dib.2021.107659. DOI: https://doi.org/10.1016/j.dib.2021.107659
Barznji, A.O. and Ameen, J.J.H. (2021) ‘Wi-Max Network Simulation for Salahaddin University New Campus’, Kufa Journal of Engineering, 12(4), pp. 1–13. Available at: https://doi.org/10.30572/2018/kje/120401. DOI: https://doi.org/10.30572/2018/kje/120401
Buczak, A.L. and Guven, E. (2016) ‘A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection’, IEEE Communications Surveys and Tutorials, 18(2), pp. 1153–1176. Available at: https://doi.org/10.1109/COMST.2015.2494502. DOI: https://doi.org/10.1109/COMST.2015.2494502
Deepa, V. (2019) ‘Design of Ensemble Learning Methods for DDoS Detection in SDN Environment’, 2019 International Conference on Vision Towards Emerging Trends in Communication and Networking (ViTECoN), pp. 1–6. DOI: https://doi.org/10.1109/ViTECoN.2019.8899682
Dong, S. and Sarem, M. (2020) ‘DDoS Attack Detection Method Based on Improved KNN with the Degree of DDoS Attack in Software-Defined Networks’, IEEE Access, 8, pp. 5039–5048. Available at: https://doi.org/10.1109/ACCESS.2019.2963077. DOI: https://doi.org/10.1109/ACCESS.2019.2963077
Gupta, Karan; Sharma, Shivam; Kumar, S. (2021) No Title. Available at: https://doi.org/10.17632/8nb4cdwc9h.1.
Han, D. et al. (2024) ‘Traffic Feature Selection and Distributed Denial of Service Attack Detection in Software-Defined Networks Based on Machine Learning’, Sensors, 24(13). Available at: https://doi.org/10.3390/s24134344. DOI: https://doi.org/10.3390/s24134344
Hosseini, S. and Azizi, M. (2019) ‘The hybrid technique for DDoS detection with supervised learning algorithms’, Computer Networks, 158, pp. 35–45. Available at: https://doi.org/10.1016/j.comnet.2019.04.027. DOI: https://doi.org/10.1016/j.comnet.2019.04.027
Laassiri, F., Moughit, M. and Idboufker, N. (2018) ‘An Improvement of Performance in 4G LTE Using Software Defined Network’, Colloquium in Information Science and Technology, CIST, 2018-Octob(12), pp. 508–513. Available at: https://doi.org/10.1109/CIST.2018.8596517. DOI: https://doi.org/10.1109/CIST.2018.8596517
Ma, R. et al. (2023) ‘Real-Time Detection of DDoS Attacks Based on Random Forest in SDN’, Applied Sciences (Switzerland), 13(13). Available at: https://doi.org/10.3390/app13137872. DOI: https://doi.org/10.3390/app13137872
Mansoor, A. et al. (2023) ‘Deep Learning-Based Approach for Detecting DDoS Attack on Software-Defined Networking Controller’, pp. 1–21. DOI: https://doi.org/10.3390/systems11060296
Nadeem, M.W. et al. (2022) ‘Ddos detection in sdn usingmachine learning techniques’, Computers, Materials and Continua, 71(1), pp. 771–789. Available at: https://doi.org/10.32604/cmc.2022.021669. DOI: https://doi.org/10.32604/cmc.2022.021669
Najar, A.A. and Manohar Naik, S. (2024) ‘Cyber-Secure SDN: A CNN-Based Approach for Efficient Detection and Mitigation of DDoS attacks’, Computers and Security, 139, p. 103716. Available at: https://doi.org/10.1016/j.cose.2024.103716. DOI: https://doi.org/10.1016/j.cose.2024.103716
Nisha Ahuja Singal, Gaurav Mukhopadhyay, D. (2020) Dataset”, “DDOS attack SDN, 27 Sep 2020. Available at: https://doi.org/10.17632/jxpfjc64kr.1.
O. Hasan, A. (2022) ‘Application Based performance monitoring heavy data transmission of Local Area Network’, Kufa Journal of Engineering, 13(3), pp. 14–40. Available at: https://doi.org/10.30572/2018/kje/130302. DOI: https://doi.org/10.30572/2018/kje/130302
Orange Data Mining (2024) 2024.
Piñeiro, V. et al. (2020) ‘A scoping review on incentives for adoption of sustainable agricultural practices and their outcomes’, Nature Sustainability, 3(10), pp. 809–820. Available at: https://doi.org/10.1038/s41893-020-00617-y. DOI: https://doi.org/10.1038/s41893-020-00617-y
Polat, H. and Polat, O. (2020) ‘Detecting DDoS Attacks in Software-Defined Networks Through Feature Selection Methods and Machine Learning Models.pdf’, Mdpi [Preprint]. DOI: https://doi.org/10.3390/su12031035
Sadhwani, S. et al. (2023) ‘A Lightweight Model for DDoS Attack Detection Using Machine Learning Techniques’, Applied Sciences (Switzerland), 13(17). Available at: https://doi.org/10.3390/app13179937. DOI: https://doi.org/10.3390/app13179937
Samaan, S.S. and Jeiad, H.A. (2023) ‘Feature-based real-time distributed denial of service detection in SDN using machine learning and Spark’, Bulletin of Electrical Engineering and Informatics, 12(4), pp. 2302–2312. Available at: https://doi.org/10.11591/eei.v12i4.4711. DOI: https://doi.org/10.11591/beei.v12i4.4711
Santos, R. et al. (2020) ‘Machine learning algorithms to detect DDoS attacks in SDN’, Concurrency and Computation: Practice and Experience, 32(16), pp. 1–14. Available at: https://doi.org/10.1002/cpe.5402. DOI: https://doi.org/10.1002/cpe.5402
Talukder, Md Alamin; Uddin, M.A. (2023) “CIC-DDoS2019 Dataset”, 3 March 2023 | Version 1. Available at: https://doi.org/10.17632/ssnc74xm6r.1.
Tonkal, Ö. et al. (2021) ‘Machine Learning Approach Equipped with Neighbourhood Component Analysis for DDoS Attack Detection in Software-Defined Networking’, Electronics, 10(11), p. 1227. Available at: https://doi.org/10.3390/electronics10111227. DOI: https://doi.org/10.3390/electronics10111227
Urbanowicz, R.J. et al. (2018) ‘Relief-based feature selection: Introduction and review’, Journal of Biomedical Informatics, 85, pp. 189–203. Available at: https://doi.org/10.1016/j.jbi.2018.07.014. DOI: https://doi.org/10.1016/j.jbi.2018.07.014
Xing, E.P., Jordan, M.I. and Karp, R.M. (2001) ‘Feature selection for high-dimensional genomic microarray data’, Proceedings of the 18th International Conference on Machine Learning, pp. 601–608.
Downloads
Published
Issue
Section
License
Copyright (c) 2025 Aymen AlAwadi, Kawthar Rasoul ALesawi

This work is licensed under a Creative Commons Attribution 4.0 International License.












