International Journal of Engineering
Trends and Technology

Research Article | Open Access | Download PDF
Volume 74 | Issue 7 | Year 2026 | Article Id. IJETT-V74I7P111 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I7P111

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques


Kamal Singh, Brijesh Kumar

Received Revised Accepted Published
27 Feb 2026 12 Jun 2026 18 Jun 2026 28 Jul 2026

Citation :

Kamal Singh, Brijesh Kumar, "Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 7, pp. 160-178, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I7P111

Abstract

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates the effectiveness of Machine Learning (ML) algorithms in detecting and addressing these attacks in real time. Using the Ryu controller, Mininet network emulator, and OpenFlow protocol, a realistic experimental environment was created to provide an accurate replica of the dynamic SDN behaviour under adverse circumstances. Empirical studies have demonstrated that distributed DDoS attacks, such as SYN, UDP, and ICMP flooding, substantially degrade network performance by reducing throughput, increasing packet loss, and exhausting switch flow table resources. To mitigate these effects, a suite of supervised machine learning classifiers, including Decision Tree, Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), and Naïve Bayes (NB), was instantiated and evaluated using traffic features captured on the emulated platform. The key performance indicators used to evaluate the classifiers included accuracy, precision, recall, and F1-score. The findings indicate that the Decision Tree and KNN models achieved detection rates above the 99% mark, with strong precision and recall scores, which in turn highlights their suitability for implementation in SDN-based security systems. This study provides experimental evidence that ML-based intrusion detection mechanisms can significantly enhance the resilience of SDNs to volumetric attacks. These results promote the implementation of adaptive and responsive security modules in SDN controllers, thereby increasing network resilience, particularly in large and dynamically programmable networks.

Keywords

SDN, DDoS Attacks, Machine Learning, OpenFlow, Ryu Controller, Intrusion Detection, Network Security.

References

[1] Open Networking Foundation, SDN Architecture Overview, Open Networking Foundation, 2014. [Online]. Available: https://opennetworking.org/wp-content/uploads/2013/02/SDN-architecture-overview-1.0.pdf

[2] RYU, Ryu SDN Framework, RYU, 2017. [Online]. Available: https://ryu-sdn.org/

[3] Mininet, Mininet an Instant Virtual Network on your Laptop, 2022. [Online]. Available: https://mininet.org/

[4] Open Networking Foundation, OpenFlow Switch Specification Version 1.5.1, Open Networking Foundation, 2015. [Online]. Available: https://opennetworking.org/wp-content/uploads/2014/10/openflow-switch-v1.5.1.pdf

[5] Yazdan Etedali, and Mohamadreza Noorifard, “CatBoost Classifier for DDoS Detection in SDN using Ryu Controller,” 2025 33rd International Conference on Electrical Engineering (ICEE), Isfahan, Iran, Islamic Republic of, pp. 1022-1026, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[6] Pooja Chaturvedi, and Deepika Bishnoi, “Detection and Classification Approach of Denial of Service Attack in SDN,” 2025 3rd International Conference on Communication, Security, and Artificial Intelligence (ICCSAI), Greater Noida, India, pp. 551-554, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[7] Hasen Alomin, Amir Gargouri, and Mohamed Ali Ghorbel, “Enhancing Network Security in SDN: Detecting Low-Rate DDoS Attacks using Decision Trees,” 2024 IEEE International Conference on Advanced Systems and Emergent Technologies (IC_ASET), Hammamet, Tunisia, pp. 1-6, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[8] Shruti Keshari et al., “Enhancing SDN Security: Performance Analysis of POX and RYU Controllers Under DDoS Attacks,” 2025 12th International Conference on Reliability, Infocom Technologies and Optimization (Trends and Future Directions) (ICRITO), Noida NCR, India, pp. 1-5, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[9] Guoqing Yang et al., “Real-Time DDoS Attack Detection in SDN based on En-CNN and OptiLGBM,” IEEE Access, vol. 13, pp. 161453-161471, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[10] Rong Cao, “Research on DDoS Attack and Defence System based on SDN Controller,” 2025 5th International Symposium on Computer Technology and Information Science (ISCTIS), Xi'an, China, pp. 594-598, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[11] Zakaria Abou El Houda, Abdelhakim Senhaji Hafid, and Lyes Khoukhi, “A Novel Machine Learning Framework for Advanced Attack Detection using SDN,” 2021 IEEE Global Communications Conference (GLOBECOM), Madrid, Spain, pp. 1-6, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[12] Kishansmaran Puranik et al., “A Two-Level DDoS Attack Detection using Entropy and Machine Learning in SDN,” 2023 3rd International Conference on Intelligent Technologies (CONIT), Hubli, India, pp. 1-7, 2023.
[CrossRef] [Google Scholar] [Publisher Link]

[13] Admilson de Ribamar Lima Ribeiro, Reneilson Yves Carvalho Santos, and Anderson Clayton Alves Nascimento, “Anomaly Detection Technique for Intrusion Detection in SDN Environment using Continuous Data Stream Machine Learning Algorithms,” 2021 IEEE International Systems Conference (SysCon), Vancouver, BC, Canada, pp. 1-7, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[14] Karrar Alhamami, and Salah Albermany, “DDoS Attack Detection using Machine Learning Algorithm in SDN Network,” 2023 Al-Sadiq International Conference on Communication and Information Technology (AICCIT), Al-Muthana, Iraq, pp. 97-102, 2023.
[CrossRef] [Google Scholar] [Publisher Link]

[15] Lingfeng Yang, and Hui Zhao, “DDoS Attack Identification and Defence using SDN based on Machine Learning Method,” 2018 15th International Symposium on Pervasive Systems, Algorithms and Networks (I-SPAN), Yichang, China, pp. 174-178, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[16] Abimbola O. Sangodoyin et al., “Detection and Classification of DDoS Flooding Attacks on Software-Defined Networks: A Case Study for the Application of Machine Learning,” IEEE Access, vol. 9, pp. 122495-122508, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[17] Abdoul Karim Tahirou, Karim Konate, and Moussa Moindze Soidridine, “Detection and Mitigation of DDoS Attacks in SDN using Machine Learning,” 2023 International Conference on Digital Age and Technological Advances for Sustainable Development (ICDATA), Casablanca, Morocco, pp. 52-59, 2023.
[CrossRef] [Google Scholar] [Publisher Link]

[18] Parvathi Sanjana Pericherla et al., “Early Detection of DDoS Attacks in SDN using Machine Learning Techniques,” 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT), Delhi, India, pp. 1-7, 2023.
[CrossRef] [Google Scholar] [Publisher Link]

[19] Anshika Sharma, and Himanshi Babbar, “Enhancing DDoS Attack Detection Deploying Machine Learning in Software Defined Networking Environment,” 2024 4th International Conference on Intelligent Technologies (CONIT), Bangalore, India, pp. 1-6, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[20] Srinuvasarao Sanapala et al., “Machine Learning based DDoS Attack Detection in Software Defined Networks (SDN),” 2023 2nd International Conference on Edge Computing and Applications (ICECAA), Namakkal, India, pp. 1124-1126, 2023.
[CrossRef] [Google Scholar] [Publisher Link]

[21] M. Kavitha et al., “Machine Learning Techniques for Detecting DDoS Attacks in SDN,” 2022 International Conference on Automation, Computing and Renewable Systems (ICACRS), Pudukkottai, India, pp. 634-638, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[22] Lipeng Wan, and Guiqin Yang, “Research on DDoS Attack with Learning Ability Detection in SDN Environment,” 2022 IEEE 5th Advanced Information Management, Communicates, Electronic and Automation Control Conference (IMCEC), Chongqing, China, pp. 1136-1140, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[23] Mohammed Ibrahim Kareem, and Mahdi Nsaif Jasim, “The Current Trends of DDoS Detection in SDN Environment,” 2021 2nd Information Technology to Enhance e-Learning and other Application (IT-ELA), Baghdad, Iraq, pp. 29-34, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[24] Kali, Hping3, Kali, 2025. [Online]. Available: https://www.kali.org/tools/hping3/

[25] S. Padmakala et al., “Circle Search Algorithm with Convolutional Neural Network for Distributed Denial-of-Service Attack Detection in Software-Defined Networks,” 2024 International Conference on Distributed Systems, Computer Networks and Cybersecurity (ICDSCNC), Bengaluru, India, pp. 1-5, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[26] Ajit Karki, and Raktim Deb, “Comprehensive Security Analysis and Threat Mitigation Strategies for Software-Defined Networking (SDN) Environments,” 2025 3rd International Conference on Intelligent Systems, Advanced Computing and Communication (ISACC), Silchar, India, pp. 623-628, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[27] Zining Zheng, Qi Zhong, and Uno Fang, “Enhancing Network Security: An SDN-Enabled Defence Mechanism Against LDoS Attacks,” 2025 3rd International Conference on Mobile Internet, Cloud Computing and Information Security (MICCIS), Dongguan, China, pp. 1-6, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[28] W. Aïda Ouedraogo Rakissaga, P. Justin Kouraogo, and T. Fréderic Ouedraogo, “Preventing DDoS Attacks in SDN Networks: A Model of Defence Against Packet-in Flooding,” 2025 IEEE World AI IoT Congress (AIIoT), Seattle, WA, USA, pp. 1025-1030, 2025.
[CrossRef] [Google Scholar] [Publisher Link]