MARATTO

article · Scientific Reports

An entropy and machine learning based approach for DDoS attacks detection in software defined networks

202430 citationsOpen accessAlexandria University

In plain language

Software-defined networks offer dynamic and efficient network management, but remain vulnerable to distributed denial-of-service attacks that can disrupt service availability. A hybrid detection framework pairs statistical monitoring with machine learning to identify and mitigate these threats. In the first phase, the system uses an entropy-based calculation to detect traffic anomalies. In the second phase, the k-means clustering algorithm assesses how active network users influence the measured entropy levels. Evaluated on three benchmark datasets, including CIC-IDS2017, CSE-CIC-2018, and CICIDS2019, the method effectively detects and halts sudden, high-speed attacks. By uniting statistical thresholds with unsupervised clustering, the approach strengthens network resilience, providing automated defence mechanisms suited to evolving attack methods within software-defined networking infrastructures.

Key takeaways

  • A hybrid system combines entropy-based statistical metrics with machine learning to identify distributed denial-of-service attacks in software-defined networks.
  • The k-means clustering algorithm is employed to analyse the effect of active network users on overall system entropy.
  • Experimental testing across three benchmark datasets confirms the framework can identify and block rapid attack traffic.

Why it matters

Modern digital services increasingly rely on software-defined networking for flexible data routing, making network availability critical. Distributed denial-of-service attacks deliberately flood these systems to shut down access. Enhancing detection systems through combined statistical and learning tools protects infrastructure from rapid service interruptions, ensuring continuous uptime and safeguarding online services against malicious traffic disruptions.

Commercialisation angle

This technology could be integrated into software-defined network management suites and cybersecurity monitoring platforms. Intended users include cloud service providers, enterprise network administrators, and telecommunications operators seeking automated defences against traffic floods. Given that the system has been validated experimentally against benchmark intrusion datasets rather than deployed in live operational environments, it represents an applied and tested method requiring production trials before commercial use.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

Software-defined networks (SDNs) have been growing rapidly due to their ability to provide an efficient network management approach compared to traditional methods. However, one of the major challenges facing SDNs is the threat of Distributed Denial of Service (DDoS) attacks, which can severely impact network availability. Detecting and mitigating such attacks is challenging, given the constantly evolving range of attack techniques. In this paper, a novel hybrid approach is proposed that combines statistical methods with machine-learning capabilities to address the detection and mitigation of DDoS attacks in SDN environments. The statistical phase of the approach utilizes an entropy-based detection mechanism, while the machine-learning phase employs a clustering mechanism to analyze the impact of active users on the entropy of the system. The k-means algorithm is used for clustering. The proposed approach was experimentally evaluated using three modern datasets, namely, CIC-IDS2017, CSE-CIC-2018, and CICIDS2019. The results demonstrate the effectiveness of the system in detecting and blocking sudden and rapid attacks, highlighting the potential of the proposed approach to significantly enhance security against DDoS attacks in SDN environments.

Research topics

  • Network Security and Intrusion Detection
  • Advanced Malware Detection Techniques
  • Smart Grid Security and Resilience

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1038/s41598-024-67984-w

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.