{"title":"SDN网络中多类DDoS检测的混合深度学习模型","authors":"Ameur Salem Zaidoun, Zied Lachiri","doi":"10.1007/s12243-025-01085-1","DOIUrl":null,"url":null,"abstract":"<div><p>This paper, as an extended version of a communication presented at the ISIVC’2024 conference, deals with security issues in the software-defined networks (SDN); it introduces a Distributed Denial of Service (DDoS) detection system leveraging deep learning (DL) features. The main objective is to enhance SDN security by accurately classifying DDoS attacks, improving efficiency, particularly for zero-day attack detection, and enabling targeted mitigation strategies. Our contribution focuses on refining a hybrid DL model with a novel architecture that applies algorithms simultaneously to distinguish the normal SDN traffic and five carefully selected other classes covering various attack kinds, using an optimized CIC-DDoS2019 dataset for more efficient classification. Compared to the conference paper, the model has been reinforced by the use of attention mechanisms and transformer architectures in addition to layers’ adjustments and hyper-parameters re-settings. Additionally, the previously used training and testing data have been combined and split into three sets: 70% for training, 15% for validation (continuous partial evaluation), and 15% for final testing. The resulting solution (hybrid DNN-LSTM) demonstrated continuous exponential improvement of validation accuracy during the training step, recording a higher value near 99% and achieving a final testing accuracy of 98.84%. The improved model is suitable for real-world SDN systems, with its deployment, potential challenges, and practical benefits discussed.</p></div>","PeriodicalId":50761,"journal":{"name":"Annals of Telecommunications","volume":"80 and networking","pages":"459 - 472"},"PeriodicalIF":2.2000,"publicationDate":"2025-03-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A hybrid deep learning model for multi-class DDoS detection in SDN networks\",\"authors\":\"Ameur Salem Zaidoun, Zied Lachiri\",\"doi\":\"10.1007/s12243-025-01085-1\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>This paper, as an extended version of a communication presented at the ISIVC’2024 conference, deals with security issues in the software-defined networks (SDN); it introduces a Distributed Denial of Service (DDoS) detection system leveraging deep learning (DL) features. The main objective is to enhance SDN security by accurately classifying DDoS attacks, improving efficiency, particularly for zero-day attack detection, and enabling targeted mitigation strategies. Our contribution focuses on refining a hybrid DL model with a novel architecture that applies algorithms simultaneously to distinguish the normal SDN traffic and five carefully selected other classes covering various attack kinds, using an optimized CIC-DDoS2019 dataset for more efficient classification. Compared to the conference paper, the model has been reinforced by the use of attention mechanisms and transformer architectures in addition to layers’ adjustments and hyper-parameters re-settings. Additionally, the previously used training and testing data have been combined and split into three sets: 70% for training, 15% for validation (continuous partial evaluation), and 15% for final testing. The resulting solution (hybrid DNN-LSTM) demonstrated continuous exponential improvement of validation accuracy during the training step, recording a higher value near 99% and achieving a final testing accuracy of 98.84%. The improved model is suitable for real-world SDN systems, with its deployment, potential challenges, and practical benefits discussed.</p></div>\",\"PeriodicalId\":50761,\"journal\":{\"name\":\"Annals of Telecommunications\",\"volume\":\"80 and networking\",\"pages\":\"459 - 472\"},\"PeriodicalIF\":2.2000,\"publicationDate\":\"2025-03-29\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Annals of Telecommunications\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://link.springer.com/article/10.1007/s12243-025-01085-1\",\"RegionNum\":4,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"TELECOMMUNICATIONS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Annals of Telecommunications","FirstCategoryId":"94","ListUrlMain":"https://link.springer.com/article/10.1007/s12243-025-01085-1","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"TELECOMMUNICATIONS","Score":null,"Total":0}
A hybrid deep learning model for multi-class DDoS detection in SDN networks
This paper, as an extended version of a communication presented at the ISIVC’2024 conference, deals with security issues in the software-defined networks (SDN); it introduces a Distributed Denial of Service (DDoS) detection system leveraging deep learning (DL) features. The main objective is to enhance SDN security by accurately classifying DDoS attacks, improving efficiency, particularly for zero-day attack detection, and enabling targeted mitigation strategies. Our contribution focuses on refining a hybrid DL model with a novel architecture that applies algorithms simultaneously to distinguish the normal SDN traffic and five carefully selected other classes covering various attack kinds, using an optimized CIC-DDoS2019 dataset for more efficient classification. Compared to the conference paper, the model has been reinforced by the use of attention mechanisms and transformer architectures in addition to layers’ adjustments and hyper-parameters re-settings. Additionally, the previously used training and testing data have been combined and split into three sets: 70% for training, 15% for validation (continuous partial evaluation), and 15% for final testing. The resulting solution (hybrid DNN-LSTM) demonstrated continuous exponential improvement of validation accuracy during the training step, recording a higher value near 99% and achieving a final testing accuracy of 98.84%. The improved model is suitable for real-world SDN systems, with its deployment, potential challenges, and practical benefits discussed.
期刊介绍:
Annals of Telecommunications is an international journal publishing original peer-reviewed papers in the field of telecommunications. It covers all the essential branches of modern telecommunications, ranging from digital communications to communication networks and the internet, to software, protocols and services, uses and economics. This large spectrum of topics accounts for the rapid convergence through telecommunications of the underlying technologies in computers, communications, content management towards the emergence of the information and knowledge society. As a consequence, the Journal provides a medium for exchanging research results and technological achievements accomplished by the European and international scientific community from academia and industry.