Skip to content
Conference

SDN-based DDoS Attack Detection and Mitigation in IoT Networks

Jul 2026 · 2026 International Conference on Intelligent and Sustainable AI Systems (ICOSAAS) · pp. 444-450 · 0 citations · 8 references

Abstract

The rapid proliferation of Internet of Things (IoT) devices has fundamentally transformed global network infrastructure while simultaneously creating an expanding attack surface for advanced Distributed Denial of Service (DDoS) threats. IoT endpoints are inherently resource-constrained, making them vulnerable to exploitation as botnet nodes for large-scale DDoS campaigns. Conventional security mechanisms including statically configured firewalls and signature-based intrusion detection systems are insufficiently scalable and adaptive for heterogeneous IoT environments. This paper proposes a lightweight, hybrid Software-Defined Networking (SDN)-based framework for real-time DDoS detection and automated mitigation. The proposed system integrates Shannon entropy-based traffic anomaly detection at the data plane with a Random Forest (RF) classifier deployed at the Ryu SDN controller. Training and evaluation are performed on the CICDDoS2019 benchmark dataset, and end-to-end validation is conducted using Mininet network simulation. Experimental results demonstrate an average detection accuracy of 98.2%, a mean false positive rate (FPR) of 1.6%, a mean F1-score of 98.2%, and a mean mitigation time of 43 ms across four DDoS attack categories: UDP Flood, TCP SYN Flood, ICMP Flood, and HTTP Flood. The proposed approach achieves a favorable accuracy-overhead balance and outperforms state-of-the-art baselines in multiple evaluation dimensions.

View source