Javascript must be enabled to continue!
Detecting DDoS Attacks in Software-Defined Networks Through Feature Selection Methods and Machine Learning Models
View through CrossRef
Software Defined Networking (SDN) offers several advantages such as manageability, scaling, and improved performance. However, SDN involves specific security problems, especially if its controller is defenseless against Distributed Denial of Service (DDoS) attacks. The process and communication capacity of the controller is overloaded when DDoS attacks occur against the SDN controller. Consequently, as a result of the unnecessary flow produced by the controller for the attack packets, the capacity of the switch flow table becomes full, leading the network performance to decline to a critical threshold. In this study, DDoS attacks in SDN were detected using machine learning-based models. First, specific features were obtained from SDN for the dataset in normal conditions and under DDoS attack traffic. Then, a new dataset was created using feature selection methods on the existing dataset. Feature selection methods were preferred to simplify the models, facilitate their interpretation, and provide a shorter training time. Both datasets, created with and without feature selection methods, were trained and tested with Support Vector Machine (SVM), Naive Bayes (NB), Artificial Neural Network (ANN), and K-Nearest Neighbors (KNN) classification models. The test results showed that the use of the wrapper feature selection with a KNN classifier achieved the highest accuracy rate (98.3%) in DDoS attack detection. The results suggest that machine learning and feature selection algorithms can achieve better results in the detection of DDoS attacks in SDN with promising reductions in processing loads and times.
Title: Detecting DDoS Attacks in Software-Defined Networks Through Feature Selection Methods and Machine Learning Models
Description:
Software Defined Networking (SDN) offers several advantages such as manageability, scaling, and improved performance.
However, SDN involves specific security problems, especially if its controller is defenseless against Distributed Denial of Service (DDoS) attacks.
The process and communication capacity of the controller is overloaded when DDoS attacks occur against the SDN controller.
Consequently, as a result of the unnecessary flow produced by the controller for the attack packets, the capacity of the switch flow table becomes full, leading the network performance to decline to a critical threshold.
In this study, DDoS attacks in SDN were detected using machine learning-based models.
First, specific features were obtained from SDN for the dataset in normal conditions and under DDoS attack traffic.
Then, a new dataset was created using feature selection methods on the existing dataset.
Feature selection methods were preferred to simplify the models, facilitate their interpretation, and provide a shorter training time.
Both datasets, created with and without feature selection methods, were trained and tested with Support Vector Machine (SVM), Naive Bayes (NB), Artificial Neural Network (ANN), and K-Nearest Neighbors (KNN) classification models.
The test results showed that the use of the wrapper feature selection with a KNN classifier achieved the highest accuracy rate (98.
3%) in DDoS attack detection.
The results suggest that machine learning and feature selection algorithms can achieve better results in the detection of DDoS attacks in SDN with promising reductions in processing loads and times.
Related Results
Selection of Injectable Drug Product Composition using Machine Learning Models (Preprint)
Selection of Injectable Drug Product Composition using Machine Learning Models (Preprint)
BACKGROUND
As of July 2020, a Web of Science search of “machine learning (ML)” nested within the search of “pharmacokinetics or pharmacodynamics” yielded over 100...
A Framework for Detecting Distributed Denial of Services Attack in Cloud Enviorment using Machine Learning Techniques
A Framework for Detecting Distributed Denial of Services Attack in Cloud Enviorment using Machine Learning Techniques
Distributed Denial of Service (DDoS) persists in Online Applications as One of those significant threats. Attackers can execute DDoS by the more natural steps. Then with the high p...
DETECTING DISTRIBUTED DENIAL OF SERVICES USING MACHINE LANGUAGE LEARNING TECHNIQUES
DETECTING DISTRIBUTED DENIAL OF SERVICES USING MACHINE LANGUAGE LEARNING TECHNIQUES
Vulnerabilities caused by cyberattacks impact negatively on the increased dependence of society on information and communication technologies (ICT) to conduct personal and business...
Mitigating DDoS Attacks in Cloud Networks
Mitigating DDoS Attacks in Cloud Networks
Distributed Denial of Service (DDoS) attacks represent a significant and growing threat to cloud networks, capable of causing extensive service disruptions and substantial financia...
DDoS Attacks and Defense Mechanisms Using Machine Learning Techniques for SDN
DDoS Attacks and Defense Mechanisms Using Machine Learning Techniques for SDN
Distributed denial of service (DDoS) attack is one of the most disastrous attacks that compromises the resources and services of the server. DDoS attack makes the services unavaila...
Detecting DDoS Attacks in Network Traffic Based on Supervised Machine Learning Techniques
Detecting DDoS Attacks in Network Traffic Based on Supervised Machine Learning Techniques
One of the major concerns in network security that pose a big challenge to safeguarding networks is distributed denial-of-service (DDoS) attacks. Such attacks often lead to breache...
Designing of Blockchain-Based Cyber Security for the Protection of Distributed Denial of Service (DDoS) Attacks on Client-Server Networks
Designing of Blockchain-Based Cyber Security for the Protection of Distributed Denial of Service (DDoS) Attacks on Client-Server Networks
Abstract
The complexity and difficulty of the ongoing and unstoppable cybercrimes in the traditional or conventional Artificial Intelligence (AI) system create the worst pr...
Drift Adaptive Online DDoS Attack Detection Framework for IoT System
Drift Adaptive Online DDoS Attack Detection Framework for IoT System
Internet of Things (IoT) security is becoming important with the growing popularity of IoT devices and their wide applications. Recent network security reports revealed a sharp inc...

