PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
September 20, 2025Telecom5 citationsOpen Access

DDoS Attacks Detection in SDN Through Network Traffic Feature Selection and Machine Learning Models

View Full Paper
ECEdith Paola Estupiñán CuestaJQJuan Carlos Martínez QuinteroJPJohn Palma

Key Points

  • The Random Forest model achieved a high accuracy of 99.99% for DDoS detection in SDNs.
  • Using the NTL-Dataset, the lowest false negative rate of 0.00001 was attained with the Random Forest model.
  • Accurate flow generation was achieved with the CICFlowMeter and NTLFlowLyzer tools during the study.
  • Comparative assessment of feature selection methods shows the effectiveness of machine learning for DDoS detection.

Abstract

This research presents a methodology for the detection of distributed denial-of-service (DDoS) attacks in software-defined networks (SDNs). An SDN was configured using the Mininet simulator, the Open Daylight controller, and a web server, which acted as the target to execute a DDoS attack on the HTTP protocol. The attack tools GoldenEye, Slowloris, HULK, Slowhttptest, and XerXes were used, and two datasets were built using the CICFlowMeter and NTLFlowLyzer flow and feature generation tools, with 424,922 and 731,589 flows, respectively, as well as two independent test datasets. These tools were used to compare their functionalities and efficiency in generating flows and features. Finally, the XGBoost and Random Forest models were evaluated with each dataset, with the objective of identifying the model that provides the best classification result in the detection of malicious traffic. For the XGBoost model, the accuracy results were 99.48% and 97.61%, while for the Random Forest model, better results were obtained with 99.97% and 99.99% using the CIC-Dataset and NTL-Dataset, respectively, in both cases. This allows determining that the Random Forest model outperformed XGBoost in classification, as it achieved the lowest false negative rate of 0.00001 using the NTL-Dataset.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Cuesta et al. (2025) studied this question.

synapsesocial.com/papers/68d46fc631b076d99fa69c87https://doi.org/10.3390/telecom6030069
Ask AI
Helpful
Bookmark
Share
View Full Paper