TARU PUBLICATIONS
Journal of Discrete Mathematical Sciences and Cryptography cover
Hybrid ·Peer-reviewed·ISSN (Online): 2169-0065·ISSN (Print): 0972-0529

Monthly Journal: Publishes theoretical and applied research in all areas of Discrete Mathematical Sciences, Cryptography, Combinatorics, Elliptic Curves and Information Security.

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

Enhancing SDN security : Mitigating DDoS attacks with robust authentication and shapley analysis

* , ,

* Corresponding author · click or hover a name for details

pp. 249–265Vol. 28Issue 1February 2025DOI: 10.47974/JDMSC-2219 Crossmark XML
Received:
15 Oct 2024
Published Online:
28 Feb 2025
Article type:
Research Article
Language:
EN
Article no.:
JDMSC-2219
Pages:
249–265

Abstract

SDN (Software-Defined Networking) revolutionized network administration by splitting the control plane from the data plane, allowing for centralized control also improved network flexibility. However, SDN also introduces security vulnerabilities, particularly Distributed Denial of Service (DDoS) attacks, which can significantly disrupt network services. This research introduces a novel two-phase method to improve the security of SDN environments through the use of SHAP (Shapley Additive Explanations). To mitigate the risk of unauthorized access, initial phase entails the establishment of a secure authentication mechanism that prevents unauthorized nodes from accessing network services. The second phase is dedicated to the mitigation & detection of DDoS attacks that are initiated by verified nodes. A SHAP (Shapley Additive Explanations)-based detection system is created, trained on a variety of datasets, including CICDDoS2019, and incorporated into the SDN controller for real-time traffic analysis. The efficiency of the proposed methodology in enhancing detection accuracy, reducing false positive rates, and maintaining network performance is demonstrated through comprehensive evaluations using simulation tools. This investigation offers a solution that is adaptable, efficient, and robust to enhance the detection and mitigation of DDoS in SDN environments.

Keywords

Subject Classifications

68M2568P25

References

[1] R. Priya, R. Selvakumari, K. R. Chandrakala, S. Krithika, H. Rai, and K. Binith Muthukrishnan, “Analyzing cryptographic protocols to strengthen HR information security,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 8, pp. 2495–2509 (2024). DOI: 10.47974/JDMSC-2134.
[2] K. Kavita, R. Kulkarni, A. H. Prasad, B. Jeyakumar, M. Thaile, and S. Gore, “A novel optimization-based blockchain technology using health care data for enhancing security and privacy in the medical system,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 8, pp. 2483–2494 (2024). DOI: 10.47974/JDMSC-2132.
[3] M. Shrestha, Y. Kim, J. Oh, J. Rhee, Y. R. Choe, F. Zuo, M. Park, and G. Qian, “ProvSec: Open cybersecurity system provenance analysis benchmark dataset with labels,” International Journal of Network and Distributed Computing, vol. 11, pp. 112–123 (2023), doi: 10.1007/s44227-023-00014-9.
[4] H. C. Huang, C. H. Tsai, and H. C. Lin, “Development of 5G Cyber-Physical Production System,” International Journal of Network and Distributed Computing, vol. 11, pp. 9–19 (2023). DOI: 10.1007/s44227-022-00003-4.
[5] S. K. Zaw and S. Vasupongayya, “Enhancing Case-based Reasoning Approach using Incremental Learning Model for Automatic Adaptation of Classifiers in Mobile Phishing Detection,” International Journal of Network and Distributed Computing, vol. 8, pp. 152–161 (2020).
[6] M. Dandotiya and R. R. S. Makwana, “DDoS Attack Detection and Mitigation in SDN Environment: A Deep Learning Perspective,” 2024 IEEE International Conference on Interdisciplinary Approaches in Technology and Management for Social Innovation (IATMSI), vol. 2, pp. 1–6 (2024).
[7] M. Dandotiya, P. Rahi, A. Khunteta, A. Anushya, and S. S. Ahmad, “SAFE: A Secure Authenticated & Integrated Framework for E-learning,” in Proceedings of the 4th International Conference on Information Management & Machine Intelligence (ICIMMI ‘22), Association for Computing Machinery, New York, NY, USA, Article 89, pp. 1–9 (2023). DOI: 10.1145/3590837.3590926.
[8] S. Arvind, B. Unhelkar, S. S. Shankar, P. Chakrabarti, and S. V. Devika, “Advancing cyber threat detection through deep learning in management information systems,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 8, pp. 2409–2417 (2024). DOI: 10.47974/JDMSC-2014.
[9] K. Kaur, S. Chakraborty, and A. K. Sagar, “Unleashing a cascade of machine learning for turbocharged sequence alignment in discrete mathematical sciences using GPU,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 4, pp. 1129–1138 (2024). DOI: 10.47974/JDMSC-1968.
[10] M. J. Jaber, Z. J. Jaber, and A. J. Obaid, “An efficient hybrid chaotic map-based encryption technique for multiple image security systems,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 5, pp. 1507–1522 (2024). DOI: 10.47974/JDMSC-1934.
[11] S. Agha and O. Rehman, “Improving Discrimination Accuracy Rate of DDoS Attacks and Flash Events,” (2020).
[12] C. Li, Y. Wu, X. Yuan, Z. Sun, W. Wang, X. Li, and L. Gong, “Detection and defense of DDoS attack–based on deep learning in OpenFlow-based SDN,” International Journal of Communication Systems, vol. 31, no. 2, p. e3497 (2018), doi: 10.1002/dac.3497.
[13] O. Rahman, M. A. G. Quraishi, and C. H. Lung, “DDoS attacks detection and mitigation in SDN using machine learning,” (2019).
[14] A. Örsdemir, H. Nazari, and D. Akgün, “DDoS Attack Detection on SDN with Conv1D and LSTM,” EasyChair Preprint (2022).
[15] N. P. Mwanza and J. Kalita, “Detecting DDoS Attacks in Software Defined Networks Using Deep Learning Techniques: A Survey,” International Journal of Network Security (2023).
[16] G. Nawaz et al., “Detecting and Mitigating DDoS Attacks in SDNs Using Deep Neural Network,” Computers, Materials & Continua (2023).
[17] D. M. Rajan and D. D. J. Aravindhar, “Detection and Mitigation of DDoS Attack in SDN Environment Using Hybrid CNN-LSTM,” Migration Letters (2023).
[18] M. A. Setitra, M. Fan, B. L. Y. Agbley, and Z. E. A. Bensalem, “Optimized MLP-CNN Model to Enhance Detecting DDoS Attacks in SDN Environment,” Network (2023).
[19] V. K. Singh, “DDoS attack detection and mitigation using statistical and machine learning methods in SDN,” M.S. thesis, Coll. Irel. (2020).
[20] S. Sadeghpour, N. Vlajic, P. Madani, and D. Stevanovic, “Unsupervised ML based detection of malicious web sessions with automated feature selection: Design and real-world validation,” (2021).
[21] S. Lee, G. Kim, and S. Kim, “Sequence-order-independent network profiling for detecting application layer DDoS attacks,” Eurasip Journal on Wireless Communications and Networking (2011).
[22] M. A. Ribeiro, M. S. Pereira Fonseca, and J. de Santi, “Detecting and mitigating DDoS attacks with moving target defense approach based on automated flow classification in SDN networks,” Computers & Security (2023).
[23] B. Venkatesh and J. Anuradha, “A review of Feature Selection and its methods,” Cybernetics and Information Technologies (2019).
[24] R. F. Fouladi, O. Ermiş, and E. Anarim, “A DDoS attack detection and defense scheme using time-series analysis for SDN,” Journal of Information Security and Applications (2020).
[25] K. Karthick, G. Kiruthiga, P. Saraswathi, B. Dhiyanesh, and R. Radha, “A Subset Scaling Recursive Feature Collection Based DDoS Detection Using Behavioural Based Ideal Neural Network for Security in A Cloud Environment,” (2022).
[26] H. Alubaidan, R. Alzaher, M. AlQhatani, and R. Mohammed, “DDoS Detection in Software-Defined Network (SDN) Using Machine Learning,” International Journal of Cybernetics and Informatics (2023).
[27] S. S. Samaan and H. A. Jeiad, “Feature-based real-time distributed denial of service detection in SDN using machine learning and Spark,” Bulletin of Electrical Engineering and Informatics (2023).
[28] H. Zhou, Y. Zheng, X. Jia, and J. Shu, “Collaborative prediction and detection of DDoS attacks in edge computing: A deep learning-based approach with distributed SDN,” Computer Networks (2023).
[29] T. A. Tang, D. McLernon, L. Mhamdi, S. A. R. Zaidi, and M. Ghogho, “Intrusion detection in SDN-based networks: Deep recurrent neural network approach,” Advanced Sciences and Technologies for Security Applications (2019).
[30] T. Khempetch and P. Wuttidittachotti, “DDoS attack detection using deep learning,” IAES International Journal of Artificial Intelligence (2021).
[31] X. Duan and X. Wang, “Fast authentication in 5G HetNet through SDN enabled weighted secure-context-information transfer,” in Proceedings of the 2016 IEEE International Conference on Communications (ICC), Kuala Lumpur, Malaysia, pp. 1–6 (2016).
[32] E. Dubrova, M. Näslund, and G. Selander, “CRC-Based Message Authentication for 5G Mobile Technology,” in Proceedings of the 2015 IEEE Trustcom/BigDataSE/ISPA, Helsinki, Finland, pp. 1–8 (2015).
[33] K. Gai, M. Qiu, L. Tao, and Y. Zhu, “Intrusion detection techniques for mobile cloud computing in heterogeneous 5G,” Security and Communication Networks (2015).
[34] A. Y. Ding, J. Crowcroft, S. Tarkoma, and H. Flinck, “Software defined networking for security enhancement in wireless mobile networks,” Computer Networks, vol. 66, pp. 94–101 (2014).
[35] S. Roschke, F. Cheng, and C. Meinel, “An Extensible and Virtualization-Compatible IDS Management Architecture,” in Proceedings of the 2009 Fifth International Conference on Information Assurance and Security (IAS), Xi’an, China, pp. 130–134 (2009).
[36] C. V. Gonzalez Zelaya, “Towards explaining the effects of data preprocessing on machine learning,” 2019 IEEE 35th International Conference on Data Engineering (ICDE) (2019).
[37] T. Peng, C. Leckie, and K. Ramamohanarao, “Proactively detecting distributed denial of service attacks using source IP address monitoring,” in Lecture Notes in Computer Science (including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), pp. 1–12 (2004).
[38] J. Cheng, J. Yin, C. Wu, B. Zhang, and Y. Liu, “DDoS attack detection method based on linear prediction model,” Emerging Intelligent Computing Technology and Applications: 5th International Conference on Intelligent Computing, ICIC 2009, Ulsan, South Korea, September 16-19 (2009).
[39] M. Dandotiya and R. R. S. Makwana, “Secured DDoS Attack Detection in SDN Using TS-RBDM With MDPP-Streebog Based User Authentication,” Transactions on Emerging Telecommunications Technologies, vol. 36, no. 2,p. e70052 (2025), doi: 10.1002/ett.70052.
[40] A. Naithani, S. N. Singh, K. Kant Singh and S. Kumar, “Machine Learning forCloud-Based DDoS Attack Detection: A Comprehensive Algorithmic Evaluation,” 2024 14th International Conference on Cloud Computing, DataScience & Engineering (Confluence), Noida, India, pp. 561-567 (2024), doi: 10.1109/Confluence60223.2024.10463504.

Views: 244Downloads: 87Citations: 1