ABSTRACT As software‐defined networking (SDN) continues to expand in data centers, cloud systems, and new types of networks, secure network protection and successful detection of attacks has become a central concern. Despite the proposed machine learning (ML) and deep learning (DL)–based intrusion detection systems (IDS), the currently available research still bears the challenge of a high false alarm rate, limited ability to adapt to dynamic attacks, a large amount of resources, and low detection accuracy in a real‐time SDN setting. In order to overcome these shortcomings, the following paper introduces a new hybrid drive DL‐based model, AetherNet‐ID, of intelligent and context‐relevant detection of attack in the SDN environment. This work makes three most important contributions. On the one hand, a Maximal Information Coefficient Graph–based Feature Ranking (MIC‐Gra) approach is suggested to efficiently select the subset of discriminative as well as nonredundant features in the data of a complex traffic dataset. Second, an Attentive Temporal‐Hierarchical Network (AetherNet‐ID) is proposed, that is a combination of spatial feature encoders and a temporal sequence adapter in the attention‐based manner that aimsat learning fine‐grained behavioral details and large‐scale patterns of intrusion at the same time. Third, a Dual Revolutionary Optimization for Fusion (DRO‐Fuse) method is proposed to predict optimal fusion weights to multi‐stream fusion to improve reliability and robustness in the decisions. The proposed model was thoroughly tested against gold‐standard datasets based on InSDN, ToN‐IoT, and CIC‐DDoS2019. The test outcomes on the proposed model show high accuracy in detecting at almost 99% and high precision and recall of nearly 0.99 and detection time of only 0.15 s with smaller memory usage of only 60 MB, which are considerably better than the ML and the DL‐based models that currently exist.
R et al. (Tue,) studied this question.