- Research Article
- 10.1142/s0219265925500239
Leveraging the Power of Machine Learning Techniques for Intrusion Detection in Software-Defined Networks
- Oct 14, 2025
- Journal of Interconnection Networks
- Soheyb Ayad + 2 more +2
Software-Defined Networks (SDN) is a new network paradigm that was developed to reduce complexity by controlling and managing the entire network from a centralized location. It is now widely used in various data center environments. Nevertheless, this type of network presents also vulnerabilities, which makes it prone to different cyber-attacks like DoS and DDoS, where the attackers seek to make servers or network resources unavailable temporarily or indefinitely, the problem becomes critical when the SDN controller is targeted. Moreover, machine learning methods have started to play an important role in most modern systems. Several contributions in the literature have addressed the problem related to intrusion detection based on Machine Learning (ML) techniques. Most of the published works use outdated datasets, which are not based on SDN environments like the KDD’99, NSL-KDD and Kyoto datasets, and that makes the proposed models not adapted to such network architectures. Recently, a new dataset called “InSDN” was published, it contains a history of various attacks generated in SDN-based networks. In this work, we proposed supervised learning models for detecting the DoS/DDoS attacks based on the InSDN dataset. The contribution in the paper goes through several steps including the preparation and preprocessing of the used dataset, best features selection, modeling, implementing, and evaluating some ML algorithms. Three classification models are proposed and evaluated, Support Vector Machines (SVM), Random Forest (RF), and Artificial Neural Networks (ANN). Also, a comparison was done with some recent works on the InSDN dataset, and the results were very satisfying.
Read more