This paper proposes a hybrid ICMP flood detection and mitigation strategy that combines a Support Vector Machine (SVM) classifier installed directly on the RYU controller with a real-time dynamic threshold mechanism (based on continuous mean and standard deviation computation).
Abstract
With programmability and centralized control, Software-Defined Networking (SDN) has become a revolutionary networking paradigm that makes network administration easier. Nevertheless, vulnerabilities are also introduced by this architectural flexibility, especially Internet Control Message Protocol (ICMP) flooding assaults, which significantly impair network availability and performance. Low detection accuracy and slow reaction times result from traditional static threshold-based detection techniques’ inability to adjust to the dynamic nature of network traffic. This paper proposes a hybrid ICMP flood detection and mitigation strategy that combines a Support Vector Machine (SVM) classifier installed directly on the RYU controller with a real-time dynamic threshold mechanism (based on continuous mean and standard deviation computation). While the SVM classifier, trained on labeled datasets, discerns between malicious and valid ICMP packets, the dynamic threshold allows adaptive traffic control based on flow statistics within predetermined time intervals. The RYU controller and Mininet emulator are used to create the suggested framework, which is then assessed in realistic SDN scenarios. According to experimental results, the SVM-based dynamic threshold solution adds only 8.9% CPU overhead to the controller while achieving 97.8% detection accuracy for pure ICMP flood attacks and maintaining 96.3% accuracy even with 25% mixed UDP traffic. 98% of legal ICMP traffic is preserved while fraudulent sources are blocked in 3.1 seconds thanks to the system’s automated OpenFlow rule installation. The results demonstrate that integrating machine learning and statistical flow analysis improves SDN resilience by offering flexible, real-time security against ICMP flood attacks with minimum computing overhead.
An explainable machine learning-based framework for accurate, transparent, and reliable DDoS attack detection in an SDN environment that combines reliable DDoS detection with transparent, analyst-oriented decision support for SDN security monitoring is developed.
J. Malik, N. Naz, Muhammad Saleem et al.· Italian National Conference...· 0 citations
This work proposes a scalable and transparent intrusion detection system (IDS) for SDNs using machine learning models that balance accuracy and computational efficiency, and explains the most important traffic characteristics, such as the length of the packets and the destination port, which are used to decide the deci...
Suhail Ashfaq Butt, Shakir M. Usman, M. Raza et al.· Journal of Computing & B...· 0 citations
Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...
Kamal Singh, Brijesh Kumar· international journal of eng...· 0 citations
The increasing complexity and volume of network traffic have made the accurate and timely detection of cyber-attacks a critical challenge. This study proposes a machine learning-based intrusion detection approach using Simple Network Management Protocol - Management Information Base (SNMP-MIB) data collected from four...
Emirhan Erdem, M. Karakose, Kürşat İnce· Automation, Control, and Inf...· 0 citations
A closed-loop framework that detects and blocks attacks in software-defined networks without operator involvement is presented, evaluating its performance against this stringent temporal constraint rather than relying exclusively on detection accuracy.
Overall, the results show that KNIMEs no-code workflow framework can offer production-level DDoS detection comparable to conventional code-based techniques, providing a workable and extremely accurate way to safeguard programmable networks.