Research Article | Open Access | Download PDF
Volume 74 | Issue 7 | Year 2026 | Article Id. IJETT-V74I7P111 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I7P111Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques
Kamal Singh, Brijesh Kumar
| Received | Revised | Accepted | Published |
|---|---|---|---|
| 27 Feb 2026 | 12 Jun 2026 | 18 Jun 2026 | 28 Jul 2026 |
Citation :
Kamal Singh, Brijesh Kumar, "Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 7, pp. 160-178, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I7P111
Abstract
Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates the effectiveness of Machine Learning (ML) algorithms in detecting and addressing these attacks in real time. Using the Ryu controller, Mininet network emulator, and OpenFlow protocol, a realistic experimental environment was created to provide an accurate replica of the dynamic SDN behaviour under adverse circumstances. Empirical studies have demonstrated that distributed DDoS attacks, such as SYN, UDP, and ICMP flooding, substantially degrade network performance by reducing throughput, increasing packet loss, and exhausting switch flow table resources. To mitigate these effects, a suite of supervised machine learning classifiers, including Decision Tree, Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), and Naïve Bayes (NB), was instantiated and evaluated using traffic features captured on the emulated platform. The key performance indicators used to evaluate the classifiers included accuracy, precision, recall, and F1-score. The findings indicate that the Decision Tree and KNN models achieved detection rates above the 99% mark, with strong precision and recall scores, which in turn highlights their suitability for implementation in SDN-based security systems. This study provides experimental evidence that ML-based intrusion detection mechanisms can significantly enhance the resilience of SDNs to volumetric attacks. These results promote the implementation of adaptive and responsive security modules in SDN controllers, thereby increasing network resilience, particularly in large and dynamically programmable networks.
Keywords
SDN, DDoS Attacks, Machine Learning, OpenFlow, Ryu Controller, Intrusion Detection, Network Security.
References
[1] Open Networking
Foundation, SDN Architecture Overview, Open Networking Foundation,
2014. [Online]. Available:
https://opennetworking.org/wp-content/uploads/2013/02/SDN-architecture-overview-1.0.pdf
[2] RYU, Ryu SDN Framework, RYU, 2017. [Online].
Available: https://ryu-sdn.org/
[3] Mininet, Mininet
an Instant Virtual Network on your Laptop, 2022. [Online]. Available: https://mininet.org/
[4] Open Networking
Foundation, OpenFlow Switch Specification Version 1.5.1, Open
Networking Foundation, 2015. [Online]. Available:
https://opennetworking.org/wp-content/uploads/2014/10/openflow-switch-v1.5.1.pdf
[5] Yazdan Etedali, and
Mohamadreza Noorifard, “CatBoost Classifier for DDoS Detection in SDN using Ryu
Controller,” 2025
33rd International Conference on Electrical Engineering (ICEE), Isfahan, Iran, Islamic Republic of, pp. 1022-1026, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[6] Pooja Chaturvedi, and
Deepika Bishnoi, “Detection and Classification Approach of Denial of Service
Attack in SDN,” 2025 3rd International
Conference on Communication, Security, and Artificial Intelligence (ICCSAI), Greater Noida, India, pp. 551-554,
2025.
[CrossRef] [Google Scholar] [Publisher Link]
[7] Hasen Alomin, Amir
Gargouri, and Mohamed Ali Ghorbel, “Enhancing Network Security in SDN:
Detecting Low-Rate DDoS Attacks using Decision Trees,” 2024 IEEE
International Conference on Advanced Systems and Emergent Technologies
(IC_ASET), Hammamet, Tunisia, pp. 1-6, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[8] Shruti Keshari et al.,
“Enhancing SDN Security: Performance Analysis of POX and RYU Controllers Under
DDoS Attacks,” 2025
12th International Conference on Reliability, Infocom Technologies
and Optimization (Trends and Future Directions) (ICRITO), Noida NCR, India, pp. 1-5, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[9] Guoqing Yang et al.,
“Real-Time DDoS Attack Detection in SDN based on En-CNN and OptiLGBM,” IEEE
Access, vol. 13, pp. 161453-161471, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[10] Rong Cao, “Research on
DDoS Attack and Defence System based on SDN Controller,” 2025 5th International
Symposium on Computer Technology and Information Science (ISCTIS), Xi'an, China, pp. 594-598, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[11] Zakaria Abou El Houda,
Abdelhakim Senhaji Hafid, and Lyes Khoukhi, “A Novel Machine Learning Framework
for Advanced Attack Detection using SDN,” 2021 IEEE Global Communications
Conference (GLOBECOM), Madrid, Spain, pp. 1-6, 2021.
[CrossRef] [Google Scholar] [Publisher Link]
[12] Kishansmaran Puranik
et al., “A Two-Level DDoS Attack Detection using Entropy and Machine Learning
in SDN,” 2023 3rd International
Conference on Intelligent Technologies (CONIT), Hubli, India,
pp. 1-7, 2023.
[CrossRef] [Google Scholar] [Publisher Link]
[13] Admilson de Ribamar
Lima Ribeiro, Reneilson Yves Carvalho Santos, and Anderson Clayton Alves
Nascimento, “Anomaly Detection Technique for Intrusion Detection in SDN
Environment using Continuous Data Stream Machine Learning Algorithms,” 2021
IEEE International Systems Conference (SysCon), Vancouver, BC, Canada, pp. 1-7, 2021.
[CrossRef] [Google Scholar] [Publisher Link]
[14] Karrar Alhamami, and
Salah Albermany, “DDoS Attack Detection using Machine Learning Algorithm in SDN
Network,” 2023
Al-Sadiq International Conference on Communication and Information Technology
(AICCIT),
Al-Muthana, Iraq, pp. 97-102, 2023.
[CrossRef] [Google Scholar] [Publisher Link]
[15] Lingfeng Yang, and Hui
Zhao, “DDoS Attack Identification and Defence using SDN based on Machine
Learning Method,” 2018 15th International Symposium on Pervasive
Systems, Algorithms and Networks (I-SPAN), Yichang, China, pp. 174-178,
2018.
[CrossRef] [Google Scholar] [Publisher Link]
[16] Abimbola O. Sangodoyin
et al., “Detection and Classification of DDoS Flooding Attacks on
Software-Defined Networks: A Case Study for the Application of Machine
Learning,” IEEE Access, vol. 9, pp. 122495-122508, 2021.
[CrossRef] [Google Scholar] [Publisher Link]
[17] Abdoul Karim Tahirou,
Karim Konate, and Moussa Moindze Soidridine, “Detection and Mitigation of DDoS
Attacks in SDN using Machine Learning,” 2023
International Conference on Digital Age and Technological Advances for
Sustainable Development (ICDATA), Casablanca, Morocco, pp. 52-59, 2023.
[CrossRef] [Google Scholar] [Publisher Link]
[18] Parvathi Sanjana
Pericherla et al., “Early Detection of DDoS Attacks in SDN using Machine
Learning Techniques,” 2023 14th International Conference on Computing Communication
and Networking Technologies (ICCCNT), Delhi, India, pp. 1-7, 2023.
[CrossRef] [Google Scholar] [Publisher Link]
[19] Anshika Sharma, and
Himanshi Babbar, “Enhancing DDoS Attack Detection Deploying Machine Learning in
Software Defined Networking Environment,” 2024
4th International Conference on Intelligent Technologies (CONIT), Bangalore, India, pp. 1-6, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[20] Srinuvasarao Sanapala
et al., “Machine Learning based DDoS Attack Detection in Software Defined
Networks (SDN),” 2023 2nd International Conference on Edge
Computing and Applications (ICECAA), Namakkal, India, pp. 1124-1126, 2023.
[CrossRef] [Google Scholar] [Publisher Link]
[21] M. Kavitha et al.,
“Machine Learning Techniques for Detecting DDoS Attacks in SDN,” 2022 International Conference on
Automation, Computing and Renewable Systems (ICACRS), Pudukkottai, India, pp. 634-638,
2022.
[CrossRef] [Google Scholar] [Publisher Link]
[22] Lipeng Wan, and Guiqin
Yang, “Research on DDoS Attack with Learning Ability Detection in SDN
Environment,” 2022
IEEE 5th Advanced Information Management, Communicates, Electronic
and Automation Control Conference (IMCEC), Chongqing, China, pp. 1136-1140, 2022.
[CrossRef] [Google Scholar] [Publisher Link]
[23] Mohammed Ibrahim
Kareem, and Mahdi Nsaif Jasim, “The Current Trends of DDoS Detection in SDN
Environment,” 2021 2nd Information
Technology to Enhance e-Learning and other Application (IT-ELA), Baghdad, Iraq, pp. 29-34, 2021.
[CrossRef] [Google Scholar] [Publisher Link]
[24] Kali, Hping3, Kali, 2025. [Online].
Available: https://www.kali.org/tools/hping3/
[25] S. Padmakala et al.,
“Circle Search Algorithm with Convolutional Neural Network for Distributed
Denial-of-Service Attack Detection in Software-Defined Networks,” 2024 International Conference on
Distributed Systems, Computer Networks and Cybersecurity (ICDSCNC), Bengaluru, India, pp. 1-5, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[26] Ajit Karki, and Raktim
Deb, “Comprehensive Security Analysis and Threat Mitigation Strategies for
Software-Defined Networking (SDN) Environments,” 2025 3rd
International Conference on Intelligent Systems, Advanced Computing and
Communication (ISACC), Silchar, India, pp. 623-628, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[27] Zining Zheng, Qi
Zhong, and Uno Fang, “Enhancing Network Security: An SDN-Enabled Defence
Mechanism Against LDoS Attacks,” 2025 3rd International
Conference on Mobile Internet, Cloud Computing and Information Security
(MICCIS),
Dongguan, China, pp. 1-6, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[28] W. Aïda Ouedraogo
Rakissaga, P. Justin Kouraogo, and T. Fréderic Ouedraogo, “Preventing DDoS
Attacks in SDN Networks: A Model of Defence Against Packet-in Flooding,” 2025
IEEE World AI IoT Congress (AIIoT), Seattle, WA, USA, pp. 1025-1030,
2025.
[CrossRef] [Google Scholar] [Publisher Link]