{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T01:52:47Z","timestamp":1782870767973,"version":"3.54.5"},"reference-count":38,"publisher":"Wiley","issue":"16","license":[{"start":{"date-parts":[[2019,6,14]],"date-time":"2019-06-14T00:00:00Z","timestamp":1560470400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"content-domain":{"domain":["onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["Concurrency and Computation"],"published-print":{"date-parts":[[2020,8,25]]},"abstract":"<jats:title>Summary<\/jats:title><jats:p>Summary Software\u2010Defined Networking (SDN) is an emerging network paradigm that has gained significant traction from many researchers to address the requirement of current data centers. Although central control is the major advantage of SDN, it is also a single point of failure if it is made unreachable by a Distributed Denial of Service (DDoS) attack. Despite the large number of traditional detection solutions that exist currently, DDoS attacks continue to grow in frequency, volume, and severity. This paper brings an analysis of the problem and suggests the implementation of four machine learning algorithms (SVM, MLP, Decision Tree, and Random Forest) with the purpose of classifying DDoS attacks in an SDN simulated environment (Mininet 2.2.2). With this goal, the DDoS attacks were simulated using the Scapy tool with a list of valid IPs, acquiring, as a result, the best accuracy with the Random Forest algorithm and the best processing time with the Decision Tree algorithm. Moreover, it is shown the most important features to classify DDoS attacks and some drawbacks in the implementation of a classifier to detect the three kinds of DDoS attacks discussed in this paper (controller attack, flow\u2010table attack, and bandwidth attack).<\/jats:p>","DOI":"10.1002\/cpe.5402","type":"journal-article","created":{"date-parts":[[2019,6,14]],"date-time":"2019-06-14T08:54:10Z","timestamp":1560502450000},"update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":168,"title":["Machine learning algorithms to detect DDoS attacks in SDN"],"prefix":"10.1002","volume":"32","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-9328-9744","authenticated-orcid":false,"given":"Reneilson","family":"Santos","sequence":"first","affiliation":[{"name":"PROCC Federal University of Sergipe  S\u00e3o Crist\u00f3v\u00e3o Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Danilo","family":"Souza","sequence":"additional","affiliation":[{"name":"PROCC Federal University of Sergipe  S\u00e3o Crist\u00f3v\u00e3o Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Walter","family":"Santo","sequence":"additional","affiliation":[{"name":"PROCC Federal University of Sergipe  S\u00e3o Crist\u00f3v\u00e3o Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Admilson","family":"Ribeiro","sequence":"additional","affiliation":[{"name":"PROCC Federal University of Sergipe  S\u00e3o Crist\u00f3v\u00e3o Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Edward","family":"Moreno","sequence":"additional","affiliation":[{"name":"PROCC Federal University of Sergipe  S\u00e3o Crist\u00f3v\u00e3o Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"311","published-online":{"date-parts":[[2019,6,14]]},"reference":[{"key":"e_1_2_9_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2371999"},{"key":"e_1_2_9_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2015.02.026"},{"key":"e_1_2_9_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2013.6553676"},{"key":"e_1_2_9_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1355734.1355746"},{"key":"e_1_2_9_6_1","doi-asserted-by":"crossref","unstructured":"Scott\u2010HaywardS O'CallaghanG SezerS.SDN security: a survey. Paper presented at: 2013 IEEE SDN for Future Networks and Services (SDN4FNS);2013;Trento Italy.","DOI":"10.1109\/SDN4FNS.2013.6702553"},{"key":"e_1_2_9_7_1","doi-asserted-by":"publisher","DOI":"10.1002\/0470099747"},{"key":"e_1_2_9_8_1","doi-asserted-by":"crossref","unstructured":"MousaviSM St\u2010HilaireM.Early detection of DDoS attacks against SDN controllers. Paper presented at: 2015 International Conference on Computing Networking and Communications (ICNC);2015;Garden Grove CA.","DOI":"10.1109\/ICCNC.2015.7069319"},{"key":"e_1_2_9_9_1","volume-title":"Sinais e Sistemas","author":"Oppenheim AV","year":"2010"},{"key":"e_1_2_9_10_1","doi-asserted-by":"crossref","unstructured":"\u00d6z\u00e7elikM ChalabianlooN G\u00fcrG.Software\u2010defined edge defense against IoT\u2010based DDoS. Paper presented at: 2017 IEEE International Conference on Computer and Information Technology (CIT);2017;Helsinki Finland.","DOI":"10.1109\/CIT.2017.61"},{"key":"e_1_2_9_11_1","doi-asserted-by":"crossref","unstructured":"TangTA MhamdiL McLernonD ZaidiSAR GhoghoM.Deep learning approach for network intrusion detection in software defined networking. Paper presented at: 2016 International Conference on Wireless Networks and Mobile Communications (WINCOM);2016;Fez Morocco.","DOI":"10.1109\/WINCOM.2016.7777224"},{"issue":"6","key":"e_1_2_9_12_1","first-page":"446","article-title":"A study on NSL\u2010KDD dataset for intrusion detection system based on classification algorithms","volume":"4","author":"Dhanabal L","year":"2015","journal-title":"Int J Adv Res Comput Commun Eng"},{"key":"e_1_2_9_13_1","doi-asserted-by":"crossref","unstructured":"PervezMS FaridDM.Feature selection and intrusion classification in NSL\u2010KDD cup 99 dataset employing SVMs. Paper presented at: The 8th International Conference on Software Knowledge Information Management and Applications (SKIMA);2014;Dhaka Bangladesh.","DOI":"10.1109\/SKIMA.2014.7083539"},{"key":"e_1_2_9_14_1","doi-asserted-by":"crossref","unstructured":"KokilaRT SelviST GovindarajanK.DDoS detection and analysis in SDN\u2010based environment using support vector machine classifier. Paper presented at: 2014 Sixth International Conference on Advanced Computing (ICoAC);2014;Chennai India.","DOI":"10.1109\/ICoAC.2014.7229711"},{"key":"e_1_2_9_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2014.2320577"},{"key":"e_1_2_9_16_1","unstructured":"FrankJ.Artificial intelligence and intrusion detection: current and future directions. In: Proceedings of the 17th National Computer Security Conference;1994;Baltimore MD."},{"key":"e_1_2_9_17_1","doi-asserted-by":"crossref","unstructured":"BragaR MotaE PassitoA.Lightweight DDoS flooding attack detection using NOX\/OpenFlow. Paper presented at: IEEE Local Computer Network Conference;2010;Denver CO.","DOI":"10.1109\/LCN.2010.5735752"},{"key":"e_1_2_9_18_1","unstructured":"DaoNN ParkJ ParkM ChoS.A feasible method to combat against DDoS attack in SDN network. Paper presented at: 2015 International Conference on Information Networking (ICOIN);2015;Cambodia."},{"key":"e_1_2_9_19_1","doi-asserted-by":"crossref","unstructured":"NandaS ZafariF DeCusatisC WedaaE YangB.Predicting network attack patterns in SDN using machine learning approach. Paper presented at: 2016 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV\u2010SDN);2016;Palo Alto CA.","DOI":"10.1109\/NFV-SDN.2016.7919493"},{"key":"e_1_2_9_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2983637"},{"key":"e_1_2_9_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2017.2785660"},{"key":"e_1_2_9_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2758754"},{"key":"e_1_2_9_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2015.7081075"},{"key":"e_1_2_9_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2487361"},{"key":"e_1_2_9_25_1","doi-asserted-by":"crossref","unstructured":"WangR JiaZ JuL.An entropy\u2010based distributed DDoS detection mechanism in software\u2010defined networking. Paper presented at: 2015 IEEE Trustcom\/BigDataSE\/ISPA;2015;Helsinki Finland.","DOI":"10.1109\/Trustcom.2015.389"},{"key":"e_1_2_9_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.bjp.2013.10.014"},{"key":"e_1_2_9_27_1","unstructured":"daSilvaAS WickboldtJA GranvilleLZ Schaeffer\u2010FilhoA.ATLANTIC: a framework for anomaly traffic detection classification and mitigation in SDN. Paper presented at: 2016 IEEE\/IFIP Network Operations and Management Symposium (NOMS);2016;Istanbul Turkey."},{"key":"e_1_2_9_28_1","unstructured":"ShinSW PorrasP YegneswaraV FongM GuG TysonM.Fresco: modular composable security services for software\u2010defined networks. Paper presented at: 20th Annual Network and Distributed System Security Symposium;2013;San Diego CA."},{"key":"e_1_2_9_29_1","doi-asserted-by":"crossref","unstructured":"DotcenkoS VladykoA LetenkoI.A fuzzy logic\u2010based information security management for software\u2010defined networks. Paper presented at: 16th International Conference on Advanced Communication Technology;2014;Pyeongchang South Korea.","DOI":"10.1109\/ICACT.2014.6778942"},{"key":"e_1_2_9_30_1","unstructured":"LiHC WaP.Implementation of an SDN\u2010based security defense mechanism against DDoS attacks. Paper presented at: 2016 International Conference on Economics and Management Engineering (ICEME) and International Conference on Economics and Business Management (EBM);2016;Wuhan China."},{"key":"e_1_2_9_31_1","doi-asserted-by":"crossref","unstructured":"MartinsJS CamposMB.A security architecture proposal for detection and response to threats in SDN networks. Paper presented at: 2016 IEEE ANDESCON;2016;Arequipa Peru.","DOI":"10.1109\/ANDESCON.2016.7836244"},{"key":"e_1_2_9_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2016.05.019"},{"key":"e_1_2_9_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13369-017-2414-5"},{"key":"e_1_2_9_34_1","doi-asserted-by":"crossref","unstructured":"LazarevicA ErtozL KumarV OzgurA SrivastavaJ.A comparative study of anomaly detection schemes in network intrusion detection. In: Proceedings of the 2003 SIAM International Conference on Data Mining;2003;San Francisco CA.","DOI":"10.1137\/1.9781611972733.3"},{"key":"e_1_2_9_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-7597-2_2"},{"key":"e_1_2_9_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-29044-2"},{"key":"e_1_2_9_37_1","first-page":"528","volume-title":"Encyclopedia of Software Engineering, Volume 2","author":"Basili VR","year":"1994"},{"key":"e_1_2_9_38_1","first-page":"2825","article-title":"Scikit\u2010learn: machine learning in python","volume":"12","author":"Pedregosa F","year":"2011","journal-title":"J Mach Learn Res"},{"key":"e_1_2_9_39_1","volume-title":"Machine Learning: An Artificial Intelligence Approach","author":"Michalski RS","year":"2013"}],"container-title":["Concurrency and Computation: Practice and Experience"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fcpe.5402","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/cpe.5402","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/full-xml\/10.1002\/cpe.5402","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/cpe.5402","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,5]],"date-time":"2023-09-05T04:19:54Z","timestamp":1693887594000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/10.1002\/cpe.5402"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6,14]]},"references-count":38,"journal-issue":{"issue":"16","published-print":{"date-parts":[[2020,8,25]]}},"alternative-id":["10.1002\/cpe.5402"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/cpe.5402","archive":["Portico"],"relation":{},"ISSN":["1532-0626","1532-0634"],"issn-type":[{"value":"1532-0626","type":"print"},{"value":"1532-0634","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,6,14]]},"assertion":[{"value":"2018-11-16","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-05-18","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-06-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"e5402"}}