Skip to content
Open access

Lightweight Rescaled Range R/S-Based Real-Time DDoS Detection for Software-Defined Networks

Aug 2026 · Network · Vol 6, pp. 62 · 0 citations · 61 references
Computer Science

TL;DR

A lightweight Rescaled Range (R/S)-based scheme for effective real-time DDoS attack detection in SDN that efficiently captures changes in self-similarity and detects TCP/UDP DDoS attacks in real time is proposed.

Abstract

Software-defined Networking (SDN) is a promising networking architecture that separates the control and data planes to allow flexible network management. However, the SDN architecture makes networks vulnerable to various security threats, such as Distributed Denial-of-Service (DDoS) attacks. A DDoS attack is one of the most common SDN threats, aiming to exhaust a network’s computational and bandwidth resources. Self-similarity is a statistical property of time series in which data patterns repeat at different time scales. Several studies have shown that network traffic exhibits increased self-similarity during DDoS attacks, making it a promising tool for DDoS detection. Despite the effectiveness of statistical methods for detecting DDoS, some methods, such as self-similarity, are discarded due to their high computational cost, leading to detection delays. This paper proposes a lightweight Rescaled Range (R/S)-based scheme for effective real-time DDoS attack detection in SDN. The scheme employs the Welford online algorithm to compute statistical parameters of the R/S scheme. Experimental results demonstrate that the proposed scheme efficiently captures changes in self-similarity and detects TCP/UDP DDoS attacks in real time. Moreover, it achieves high detection performance compared to other R/S methods, with a False Positive Rate (FPR) below 0.5% and an average computation time of 0.047 ms.

Read PDF

Similar papers

Conference Aug 2026

Real-Time DDoS Detection Using Centralized SDN Controller and MLP

Distributed Denial-of-Service (DDoS) attacks pose a significant threat to the availability and reliability of modern network infrastructures. Traditional detection mechanisms often lack scalability, adaptability, and real-time responsiveness, making them ineffective against evolving attack patterns. This paper proposes...

Maragani Venkata Naga Jagadeesh, K. S. S. Prasad, Raya Venkata Karthik Reddy et al. · 0 citations
Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...

Kamal Singh, Brijesh Kumar · 0 citations
Preprint Aug 2026

When Time Meets Space: Entropy Integration and Dynamic Threshold for Adaptive DDoS Detection in SDN

Entropy-based Distributed Denial of Service (DDoS) detection in Software-Defined Networking (SDN) commonly relies on spatial traffic distributions and static or loosely adaptive thresholds, making it vulnerable to legitimate traffic fluctuations in Internet of Things (IoT) environments. This paper proposes a lightweigh...

Zhaoyang Zhang, Shen Wang, Ahmad F. Taha et al. · 1 citation · ⚡1
Open access Aug 2026

A Multi-Class SDN Intrusion Detection Dataset with Synchronized OpenFlow Control-Plane Telemetry

LAN-SDN-NIDS is presented, a publicly available, multi-class flow-level dataset of 1,125,059 records generated in a fully containerized Containernet/OpenDaylight testbed across five standard network topologies, indicating that control-plane telemetry is decisive for detecting SDN-architectural attacks under the conditi...

Juliana Arévalo-Herrera, Jorge E. Camargo, J. I. M. Torre et al. · 0 citations
Open access Sep 2026

Towards Trustworthy Software-Defined Network Security: An Explainable and Computationally Efficient Machine Learning Framework for Intrusion Detection

This work proposes a scalable and transparent intrusion detection system (IDS) for SDNs using machine learning models that balance accuracy and computational efficiency, and explains the most important traffic characteristics, such as the length of the packets and the destination port, which are used to decide the deci...

Suhail Ashfaq Butt, Shakir M. Usman, M. Raza et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.