Skip to content
Open access

Towards Trustworthy Software-Defined Network Security: An Explainable and Computationally Efficient Machine Learning Framework for Intrusion Detection

Sep 2026 · Journal of Computing & Biomedical Informatics · Vol 11 · 0 citations

TL;DR

This work proposes a scalable and transparent intrusion detection system (IDS) for SDNs using machine learning models that balance accuracy and computational efficiency, and explains the most important traffic characteristics, such as the length of the packets and the destination port, which are used to decide the decision process of the model.

Abstract

Software-defined networking (SDN) offers flexibility and scalability but also introduces new cybersecurity challenges. We propose a scalable and transparent intrusion detection system (IDS) for SDNs using machine learning models that balance accuracy and computational efficiency. Our results show that the decision tree model achieves 99.6% accuracy with minimal missed attacks and lower computational costs compared with random forests. The training time increased with the dataset size, but the prediction time remained stable, even with 24,000 samples. Our simulation results showed that the training complexity of Random Forest increases with the number of samples, whereas the calculation time for inference is comparatively low–a finding that makes Random Forest particularly suitable for real-time detections in Software-Defined Networking (SDN) environments. By using the SHAP-based explainability analysis, we explain the most important traffic characteristics, such as the length of the packets and the destination port, which are used to decide the decision process of the model. This methodological approach ensures high recall detection without compromising performance, thus providing a high-performance and efficient solution for SDN security.

Read PDF

Similar papers

#software testing Open access Sep 2026

Intelligent DDoS Attack Detection in Software-Defined Networks Using Explainable Machine Learning

An explainable machine learning-based framework for accurate, transparent, and reliable DDoS attack detection in an SDN environment that combines reliable DDoS detection with transparent, analyst-oriented decision support for SDN security monitoring is developed.

J. Malik, N. Naz, Muhammad Saleem et al. · 0 citations
Open access 2026

Detection and Prevention of Internet Control Message Protocol Flood Attack in Software-Defined Network Using Dynamic Threshold and Machine Learning

This paper proposes a hybrid ICMP flood detection and mitigation strategy that combines a Support Vector Machine (SVM) classifier installed directly on the RYU controller with a real-time dynamic threshold mechanism (based on continuous mean and standard deviation computation).

Tsehaynesh Babil Wassie, Bayew Dessie Fenta, Habtamu Molla Belachew et al. · 0 citations
Open access Aug 2026

Explainable Machine Learning for DDoS Attack Detection with Physical Network Validation

This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation, indicating that offline benchmarks alone are insufficient for validating IDS readiness.

Muhammad Azzam Anshori, R. Amri · 0 citations
#artificial intelligence Preprint Sep 2026

XAI-SDN: An Explainable Entropy-Guided Machine Learning Framework for Real-Time DDoS Detection in Software Defined Networks

One of the biggest risks faced by Software Defined Networks (SDN) is the Distributed Denial of Service (DDoS) attack in which a compromised controller can make an entire network unusable. To address these challenges, we suggest an entropy-guided machine learning framework, called XAI-SDN, for real-time DDoS detection i...

Adeel Ahmad, Ali Akarma, Ahmad Ali et al. · 0 citations

Real-time detection of cryptographic key misuse in software-defined networks using incremental learning

An incremental learning based framework to detect anomalous traffic patterns which may indicate any key misuse in Software-Defined Networks in dynamic and real-time environments in modern SDN environments is proposed.

Gineeth Rajeshkhanna, Tamilarasi Kathirvel Murugan, Logeswari Govindaraj et al. · 0 citations
Conference Sep 2026

Network Intrusion Detection Using SNMP MIB Data: A Multi-Device Machine Learning Approach

The increasing complexity and volume of network traffic have made the accurate and timely detection of cyber-attacks a critical challenge. This study proposes a machine learning-based intrusion detection approach using Simple Network Management Protocol - Management Information Base (SNMP-MIB) data collected from four...

Emirhan Erdem, M. Karakose, Kürşat İnce · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.