PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
August 17, 2025Future Internet3 citationsOpen Access

DDoS Defense Strategy Based on Blockchain and Unsupervised Learning Techniques in SDN

View Full Paper
SPShengmin PengJTJialin TianXZXiangyu Zheng

Key Points

  • Implementing a dual-layer defense strategy reduces DDoS attack impacts and enhances security.
  • The average round-trip time (RTT) improves by about 38.86% with this strategy in SDN networks.
  • The methodology utilizes blockchain and unsupervised learning for detecting and mitigating DDoS attacks.
  • High detection accuracy of 97.66% demonstrates the effectiveness of the proposed approach.

Abstract

With the rapid development of technologies such as cloud computing, big data, and the Internet of Things (IoT), Software-Defined Networking (SDN) is emerging as a new network architecture for the modern Internet. SDN separates the control plane from the data plane, allowing a central controller, the SDN controller, to quickly direct the routing devices within the topology to forward data packets, thus providing flexible traffic management for communication between information sources. However, traditional Distributed Denial of Service (DDoS) attacks still significantly impact SDN systems. This paper proposes a novel dual-layer strategy capable of detecting and mitigating DDoS attacks in an SDN network environment. The first layer of the strategy enhances security by using blockchain technology to replace the SDN flow table storage container in the northbound interface of the SDN controller. Smart contracts are then used to process the stored flow table information. We employ the time window algorithm and the token bucket algorithm to construct the first layer strategy to defend against obvious DDoS attacks. To detect and mitigate less obvious DDoS attacks, we design a second-layer strategy that uses a composite data feature correlation coefficient calculation method and the Isolation Forest algorithm from unsupervised learning techniques to perform binary classification, thereby identifying abnormal traffic. We conduct experimental validation using the publicly available DDoS dataset CIC-DDoS2019. The results show that using this strategy in the SDN network reduces the average deviation of round-trip time (RTT) by approximately 38.86% compared with the original SDN network without this strategy. Furthermore, the accuracy of DDoS attack detection reaches 97.66% and an F1 score of 92.2%. Compared with other similar methods, under comparable detection accuracy, the deployment of our strategy in small-scale SDN network topologies provides faster detection speeds for DDoS attacks and exhibits less fluctuation in detection time. This indicates that implementing this strategy can effectively identify DDoS attacks without affecting the stability of data transmission in the SDN network environment.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Peng et al. (2025) studied this question.

synapsesocial.com/papers/68a36a3f0a429f797332e99ahttps://doi.org/10.3390/fi17080367
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Enhanced DDoS Defense in SDN: Double-Layered Strategy with Blockchain Integration2024 · 2 citations
  2. 2A random forest guided tour2016 · 4,041 citations
  3. 3Real-Time Detection of DDoS Attacks Based on Random Forest in SDN2023 · 50 citations
  4. 4Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy2019 · 1,129 citations
  5. 5Normalized Mutual Information Feature Selection2009 · 1,304 citations