MARATTO

article · IEEE Access

CNN-BiLSTM: A Hybrid Deep Learning Approach for Network Intrusion Detection System in Software-Defined Networking With Hybrid Feature Selection

2023101 citationsOpen accessIbn Tofail University

In plain language

Software-Defined Networking centralises network management from a single control point, making controllers appealing targets for malicious attacks such as distributed denial-of-service, web attacks, and user-to-root intrusions. Hijacking a controller allows attackers to reroute traffic maliciously across the network. Deep learning offers potential for network intrusion detection in software-defined environments, but existing systems often struggle with data redundancy and unbalanced training datasets, which degrade anomaly detection performance. To address these problems, a hybrid deep learning model combines a convolutional neural network with bidirectional long short-term memory architecture for binary and multiclass classification. Evaluated against common benchmark datasets, namely UNSW-NB15 and NSL-KDD, as well as the dedicated InSDN dataset, the model demonstrates high detection accuracy while requiring less training time.

Key takeaways

  • Software-defined network controllers are vulnerable to high-impact threats including denial-of-service, web attacks, and user-to-root breaches.
  • Data redundancy and unbalanced datasets undermine the resilience and performance of deep learning models used for network intrusion detection.
  • A hybrid architecture combining convolutional neural networks and bidirectional long short-term memory supports both binary and multiclass intrusion classification.
  • Testing on standard benchmarks and dedicated software-defined network data demonstrates high accuracy and reduced training time.

Why it matters

Modern data centres increasingly rely on centralised software-defined networks to manage traffic, making controller security critical. Compromising a controller can jeopardise an entire digital infrastructure. By delivering accurate, faster-training threat detection that accounts for flawed data, this research helps protect vital network control systems from sophisticated cyber threats and service disruptions.

Commercialisation angle

The model could be integrated into intrusion detection tools used by data centre operators and network administrators managing software-defined environments. Because it was evaluated only on benchmark and domain-specific datasets rather than live production networks, the technology remains early-stage applied research that requires further validation in real-world operational environments before commercial deployment.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

A Software-Defined Network (SDN) was designed to simplify network management by allowing the control and management of the entire network from a single place. SDN is commonly used in today’s data center network infrastructures, but new forms of threats such as Distributed Denial-of-Service (DDoS), web attack, and the U2R (User to Root) attack are significant issues that might restrict the widespread adoption of SDNs. Intruders are attractive to SDN controllers because they are valuable targets. An SDN controller can be hijacked by an attacker and used to route traffic in accordance with its own needs, resulting in catastrophic consequences for the whole network. While the unified vision of SDN and deep learning methods opens new possibilities for the security of IDS deployment, the effectiveness of the detection models is dependent on the quality of the training datasets. Even though deep learning for NIDSs has lately shown promising results for a number of issues, the majority of the studies overlooked the impact of data redundancy and an unbalanced dataset. As a consequence, this may adversely affect the resilience of the anomaly detection system, resulting in suboptimal model performance. In this study, we created a hybrid Convolutional Neural Network (CNN) and bidirectional long short-term memory (BiLSTM) network to enhance network intrusion detection using binary and multiclass classification. The effectiveness of the proposed model was tested and assessed using the most frequently used datasets (UNSW-NB15 and NSL-KDD). In addition, we used the InSDN dataset, which is specifically dedicated to SDN. The outcomes demonstrate the efficiency of the proposed model in achieving high accuracy and requiring less training time.

Research topics

  • Network Security and Intrusion Detection
  • Software-Defined Networks and 5G
  • Internet Traffic Analysis and Secure E-voting

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/access.2023.3340142

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.