Flow-Based DDoS Detection and Mitigation in Software-Defined Networking Using a Hybrid CNN-LSTM-Transformer Model
DOI:
https://doi.org/10.59261/jequi.v8i3.371Keywords:
Software-Defined Networking, DDoS Detection, CNN-LSTM-Transformer, OpenFlow, Ryu ControllerAbstract
Background: Software-Defined Networking (SDN) improves network programmability through centralized control, but this architecture also makes the controller vulnerable to Distributed Denial-of-Service (DDoS) attacks that may overload Packet-In processing, exhaust controller resources, and disrupt service availability.
Objective: This study aims to develop and evaluate a flow-based DDoS detection and mitigation approach in SDN using a hybrid CNN-LSTM-Transformer model.
Methods: The proposed model represents flow records as feature sequences, enabling CNN to capture local feature patterns, LSTM to learn sequential dependencies, and Transformer self-attention to model global inter-feature relationships. Offline evaluation was conducted on CIC-DDoS2019, inSDN, and CIC-IDS2017 using 71 features, stratified 70:20:10 training/validation/testing splits, and three independent seeds. A CNN-LSTM ablation model was used for comparison.
Results: The results show the proposed model achieved mean accuracies of 99.87%, 99.98%, and 99.93% on CIC-DDoS2019, inSDN, and CIC-IDS2017, respectively. Compared with CNN-LSTM, the proposed model produced lower mean validation losses and required fewer epochs across all datasets. In real-time validation, UDP, TCP, and ICMP flooding attacks were detected within 0.0693-0.2668s and mitigated using high-priority drop rules, reducing Ryu CPU usage from 52.6%-91.4% during attacks to 0.7%-1.7% after blocking.
Conclusion: The findings indicate CNN-LSTM-Transformer model provides an accurate, efficient, and deployment-oriented DDoS defense approach for emulated SDN environments. The proposed model not only achieved high accuracy in offline testing but also demonstrated feasibility in real-time SDN environments with relatively low computational overhead, achieving detection times of 0.0693–0.2668s and reducing Ryu CPU usage from up to 91.4% during attacks to below 1.7% after mitigation.
Downloads
References
Abdusalomov, A., Meliboev, A., Xamdamov, U., Melih Gul, O., Yazici, A., Elghirani, A., Nasimov, R., Cho, Y. I., & Gul, O. M. (2024). Enhanced Detection of DDoS Attacks in SDN Using Deep Learning Algorithms. 1–10.
Abid, Y. A., Wu, J., Xu, G., Fu, S., & Waqas, M. (2024). Multilevel Deep Neural Network Approach for Enhanced Distributed Denial-of-Service Attack Detection and Classification in Software-Defined Internet of Things Networks. IEEE Internet of Things Journal, 11(14), 24715–24725. https://doi.org/10.1109/JIOT.2024.3376578
Ahuja, N., Singal, G., Mukhopadhyay, D., & Kumar, N. (2021). Automated DDoS attack detection in software defined networking. Journal of Network and Computer Applications, 187, 103108. https://doi.org/10.1016/j.jnca.2021.103108
Al-Dunainawi, Y., Al-Kaseem, B. R., & Al-Raweshidy, H. S. (2023). Optimized Artificial Intelligence Model for DDoS Detection in SDN Environment. IEEE Access, 11, 106733–106748. https://doi.org/10.1109/ACCESS.2023.3319214
Alghazzawi, D., Bamasaq, O., Ullah, H., & Asghar, M. Z. (2021). Efficient detection of DDoS attacks using a hybrid deep learning model with improved feature selection. Applied Sciences (Switzerland), 11(24). https://doi.org/10.3390/app112411634
Ali, T. E., Chong, Y. W., & Manickam, S. (2023). Machine Learning Techniques to Detect a DDoS Attack in SDN: A Systematic Review. Applied Sciences (Switzerland), 13(5). https://doi.org/10.3390/app13053183
Altamemi, A. J., Abdulhassan, A., & Obeis, N. T. (2022). DDoS attack detection in software defined networking controller using machine learning techniques. Bulletin of Electrical Engineering and Informatics, 11(5), 2836–2844. https://doi.org/10.11591/eei.v11i5.4155
Ataa, M. S., Sanad, E. E., & El-khoribi, R. A. (2024). Intrusion detection in software defined network using deep learning approaches. Scientific Reports, 14(1), 1–15. https://doi.org/10.1038/s41598-024-79001-1
Ben, S. R., Sabir, Z., & Askerzade, I. (2023). CNN-BiLSTM: A Hybrid Deep Learning Approach for Network Intrusion Detection System in Software-Defined Networking With Hybrid Feature Selection. IEEE Access, 11(December), 138732–138747. https://doi.org/10.1109/ACCESS.2023.3340142
Benlloch, P., Romero, O., Leon, A., & Lloret, J. (2026). MLDAS: Machine Learning Dynamic Algorithm Selection for Software‐Defined Networking Security. Concurrency and Computation: Practice and Experience, 38(5), e70637.
Bilal, A., Sharif, K., Zhu, L., Li, F., Xu, C., & Karim, M. M. (2026). Evaluation to integration: Hybrid feature selection framework with ensemble machine learning for intrusion detection. IEEE Transactions on Dependable and Secure Computing.
Çavşi Zaim, H., & Yolaçan, E. N. (2025). FPE–Transformer: A Feature Positional Encoding-Based Transformer Model for Attack Detection. Applied Sciences (Switzerland), 15(3). https://doi.org/10.3390/app15031252
Chaymae, E. Y., Abdellatif, K., Khalid, C., & Jalel, B. O. (2024). Intrusion Detection System using Transformer Encoder and CNN-BiLSTM in Software-Defined Networks. Proceedings - IEEE Global Communications Conference, GLOBECOM, Ml, 2214–2219. https://doi.org/10.1109/GLOBECOM52923.2024.10901492
Chen, L., Wang, Z., Huo, R., & Huang, T. (2023). An Adversarial DBN-LSTM Method for Detecting and Defending against DDoS Attacks in SDN Environments. Algorithms, 16(4). https://doi.org/10.3390/a16040197
Çil, A., & Demirci, M. (2026). SARE: Secure, Automated, and Regulatory‐Compliant Platform for Improving Forensic Readiness in Software‐Defined Networks. International Journal of Communication Systems, 39(1), e70299.
Hnamte, V., & Hussain, J. (2023). An efficient DDoS attack detection mechanism in SDN environment. International Journal of Information Technology (Singapore), 15(5), 2623–2636. https://doi.org/10.1007/s41870-023-01332-5
Hssayeni, M. D., & Mahgoub, I. (2026). A Transformer-Based Intrusion Detection System for Zero-Day Attack Detection in IoT Networks. Future Internet, 18(6), 282.
Li, M., Zhang, B., Wang, G., Zhuge, B., Jiang, X., & Dong, L. (2022). A DDoS attack detection method based on deep learning two-level model CNN-LSTM in SDN network. Proceedings - 2022 International Conference on Cloud Computing, Big Data Applications and Software Engineering, CBASE 2022, 282–287. https://doi.org/10.1109/CBASE57816.2022.00062
Liu, Z., Wang, Y., Feng, F., Liu, Y., Li, Z., & Shan, Y. (2023). A DDoS Detection Method Based on Feature Engineering and Machine Learning in Software-Defined Networks. Sensors, 23(13). https://doi.org/10.3390/s23136176
Mansoor, A., Anbar, M., Bahashwan, A. A., Alabsi, B. A., & Rihan, S. D. A. (2023). Deep Learning-Based Approach for Detecting DDoS Attack on Software-Defined Networking Controller. Systems, 11(6), 1–21. https://doi.org/10.3390/systems11060296
Mbasuva, U., & Zodi, G. A. L. (2022). Designing Ensemble Deep Learning Intrusion Detection System for DDoS attacks in Software Defined Networks. Proceedings of the 2022 16th International Conference on Ubiquitous Information Management and Communication, IMCOM 2022. https://doi.org/10.1109/IMCOM53663.2022.9721785
Muchtar, T., & Mutijarsa, K. (2025). Machine Learning for DDoS Attack Detection in SDN: A Systematic Literature Review. In 2025 IEEE 2nd International Conference on Cryptography, Informatics, and Cybersecurity (ICoCICs) (pp. 224–229). IEEE. https://doi.org/10.1109/ICoCICs68032.2025.11384079
Musa, N. S., Mirza, N. M., Rafique, S. H., Abdallah, A. M., & Murugan, T. (2024). Machine Learning and Deep Learning Techniques for Distributed Denial of Service Anomaly Detection in Software Defined Networks - Current Research Solutions. IEEE Access, 12(January), 17982–18011. https://doi.org/10.1109/ACCESS.2024.3360868
NetScout Systems, I. (2023). NETSCOUT Identified Nearly 7.9 Million DDoS Attacks in 1H2023 According to Its Latest DDoS Threat Intelligence Report.
Said, R. Ben, & Askerzade, I. (2023). Attention-Based CNN-BiLSTM Deep Learning Approach for Network Intrusion Detection System in Software Defined Networks. 2023 5th International Conference on Problems of Cybernetics and Informatics, PCI 2023, 1–5. https://doi.org/10.1109/PCI60110.2023.10325985
Sangodoyin, A. O., Akinsolu, M. O., Pillai, P., & Grout, V. (2021). Detection and Classification of DDoS Flooding Attacks on Software-Defined Networks: A Case Study for the Application of Machine Learning. IEEE Access, 9, 122495–122508. https://doi.org/10.1109/ACCESS.2021.3109490
Sheikh, M. N. A., Raza, M. S., Hwang, I.-S., Hossain, M. A., Ullah, I., Hasan, T., & Ab-Rahman, M. S. (2025). SDN-Enabled IoT based transport layer DDoS attacks detection using RNNs. Computers, Materials, & Continua, 85(2), 4043.
Wainwright, R., Bagheri, M., Salama, A., & Saatchi, R. (2025). Software-Defined Networking Security Detection Strategies and Their Limitations with a Focus on Distributed Denial-of-Service for Small to Medium-Sized Enterprises. Applied Sciences (Switzerland), 15(23), 1–19. https://doi.org/10.3390/app152312389
Wang, H., & Li, W. (2021). DDosTC: A transformer-based network attack detection hybrid mechanism in SDN. Sensors, 21(15). https://doi.org/10.3390/s21155047
Wang, J., & Wang, L. (2022). SDN-Defend: A Lightweight Online Attack Detection and Mitigation System for DDoS Attacks in SDN. Sensors, 22(21). https://doi.org/10.3390/s22218287
Wang, J., Wang, L., & Wang, R. (2023). A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers. Entropy, 25(8). https://doi.org/10.3390/e25081210
Yungaicela-Naula, N. M., Vargas-Rosales, C., & Perez-Diaz, J. A. (2021). SDN-based architecture for transport and application layer DDoS attack detection by using machine and deep learning. IEEE Access, 9, 108495–108512. https://doi.org/10.1109/ACCESS.2021.3101650
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Tirtadi Muchtar, Kusprasapta Mutijarsa

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.




