Skip to content
Preprint

Cross-Domain Joint DDoS Detection in Multi-Controller SDN via Confidence-Based Entropy Fusion

Aug 2026 · 0 citations · 15 references
Computer Science

TL;DR

A cross-domain confidence-fusion framework that leverages lightweight edge-side messages to calibrate aggregation-controller decisions without sharing raw traffic data is proposed that is non-intrusive, communication-efficient, and incrementally deployable.

Abstract

In multi-controller Software-Defined Networking (SDN), Distributed Denial-of-Service (DDoS) attacks exhibit a"dispersed source, concentrated target"pattern across domains, i.e., attack traffic originates from multiple edge-controller domains but converges on a victim in a single aggregation controller domain. While entropy-based DDoS detectors are effective in single-controller settings, their direct application in multi-controller SDN reveals a previously overlooked anomaly. Through systematic experiments, we identify an aggregation bias: during the post-attack transition phase, the aggregation controller continues to generate excessive false positives, while edge controllers have already returned to normal. We attribute this phenomenon to the coupled effects of OpenFlow statistics lag and unconstrained dynamic-threshold drift. To address this issue, we propose a cross-domain confidence-fusion framework that leverages lightweight edge-side messages to calibrate aggregation-controller decisions without sharing raw traffic data. The framework is non-intrusive, communication-efficient, and incrementally deployable. Experiments on a three-controller linear Mininet testbed with 24 hosts over 10 runs show that the method preserves edge-controller performance while reducing the aggregation false positive rate from 8.87% to 1.96% and increasing the F1 score from 89.04% to 96.89%.

View source

Similar papers

Open access Aug 2026

A Multi-Class SDN Intrusion Detection Dataset with Synchronized OpenFlow Control-Plane Telemetry

LAN-SDN-NIDS is presented, a publicly available, multi-class flow-level dataset of 1,125,059 records generated in a fully containerized Containernet/OpenDaylight testbed across five standard network topologies, indicating that control-plane telemetry is decisive for detecting SDN-architectural attacks under the conditi...

Juliana Arévalo-Herrera, Jorge E. Camargo, J. I. M. Torre et al. · 0 citations
Preprint Aug 2026

When Time Meets Space: Entropy Integration and Dynamic Threshold for Adaptive DDoS Detection in SDN

Entropy-based Distributed Denial of Service (DDoS) detection in Software-Defined Networking (SDN) commonly relies on spatial traffic distributions and static or loosely adaptive thresholds, making it vulnerable to legitimate traffic fluctuations in Internet of Things (IoT) environments. This paper proposes a lightweigh...

Zhaoyang Zhang, Shen Wang, Ahmad F. Taha et al. · 1 citation · ⚡1
Conference Aug 2026

Real-Time DDoS Detection and Mitigation in SDN with an Ensemble Online Learning Approach

Software-Defined Networking (SDN) centralizes network control in a software controller, making it a high-value target for Distributed Denial-of-Service (DDoS) attacks. Existing machine learning defences are predominantly trained offline and require costly retraining to remain effective under evolving traffic patterns a...

Sodadasu Dharma Raj, N. Goud, K. Shailaja et al. · 0 citations
Conference Aug 2026

Real-Time DDoS Detection Using Centralized SDN Controller and MLP

Distributed Denial-of-Service (DDoS) attacks pose a significant threat to the availability and reliability of modern network infrastructures. Traditional detection mechanisms often lack scalability, adaptability, and real-time responsiveness, making them ineffective against evolving attack patterns. This paper proposes...

Maragani Venkata Naga Jagadeesh, K. S. S. Prasad, Raya Venkata Karthik Reddy et al. · 0 citations
Open access Aug 2026

Lightweight Rescaled Range R/S-Based Real-Time DDoS Detection for Software-Defined Networks

A lightweight Rescaled Range (R/S)-based scheme for effective real-time DDoS attack detection in SDN that efficiently captures changes in self-similarity and detects TCP/UDP DDoS attacks in real time is proposed.

M. Awad, Ghazal Alsholi, Haniah Altabaa et al. · 0 citations
Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...

Kamal Singh, Brijesh Kumar · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.