Flow-Based DDoS Detection and Mitigation in Software-Defined Networking Using a Hybrid CNN-LSTM-Transformer Model

Authors

  • Tirtadi Muchtar Institut Teknologi Bandung
  • Kusprasapta Mutijarsa Institut Teknologi Bandung

DOI:

https://doi.org/10.59261/jequi.v8i3.371

Keywords:

Software-Defined Networking, DDoS Detection, CNN-LSTM-Transformer, OpenFlow, Ryu Controller

Abstract

Background: Software-Defined Networking (SDN) improves network programmability through centralized control, but this architecture also makes the controller vulnerable to Distributed Denial-of-Service (DDoS) attacks that may overload Packet-In processing, exhaust controller resources, and disrupt service availability.

Objective: This study aims to develop and evaluate a flow-based DDoS detection and mitigation approach in SDN using a hybrid CNN-LSTM-Transformer model.

Methods: The proposed model represents flow records as feature sequences, enabling CNN to capture local feature patterns, LSTM to learn sequential dependencies, and Transformer self-attention to model global inter-feature relationships. Offline evaluation was conducted on CIC-DDoS2019, inSDN, and CIC-IDS2017 using 71 features, stratified 70:20:10 training/validation/testing splits, and three independent seeds. A CNN-LSTM ablation model was used for comparison.

Results: The results show the proposed model achieved mean accuracies of 99.87%, 99.98%, and 99.93% on CIC-DDoS2019, inSDN, and CIC-IDS2017, respectively. Compared with CNN-LSTM, the proposed model produced lower mean validation losses and required fewer epochs across all datasets. In real-time validation, UDP, TCP, and ICMP flooding attacks were detected within 0.0693-0.2668s and mitigated using high-priority drop rules, reducing Ryu CPU usage from 52.6%-91.4% during attacks to 0.7%-1.7% after blocking.

Conclusion: The findings indicate CNN-LSTM-Transformer model provides an accurate, efficient, and deployment-oriented DDoS defense approach for emulated SDN environments. The proposed model not only achieved high accuracy in offline testing but also demonstrated feasibility in real-time SDN environments with relatively low computational overhead, achieving detection times of 0.0693–0.2668s and reducing Ryu CPU usage from up to 91.4% during attacks to below 1.7% after mitigation.

Downloads

Download data is not yet available.

References

Abdusalomov, A., Meliboev, A., Xamdamov, U., Melih Gul, O., Yazici, A., Elghirani, A., Nasimov, R., Cho, Y. I., & Gul, O. M. (2024). Enhanced Detection of DDoS Attacks in SDN Using Deep Learning Algorithms. 1–10.

Abid, Y. A., Wu, J., Xu, G., Fu, S., & Waqas, M. (2024). Multilevel Deep Neural Network Approach for Enhanced Distributed Denial-of-Service Attack Detection and Classification in Software-Defined Internet of Things Networks. IEEE Internet of Things Journal, 11(14), 24715–24725. https://doi.org/10.1109/JIOT.2024.3376578

Ahuja, N., Singal, G., Mukhopadhyay, D., & Kumar, N. (2021). Automated DDoS attack detection in software defined networking. Journal of Network and Computer Applications, 187, 103108. https://doi.org/10.1016/j.jnca.2021.103108

Al-Dunainawi, Y., Al-Kaseem, B. R., & Al-Raweshidy, H. S. (2023). Optimized Artificial Intelligence Model for DDoS Detection in SDN Environment. IEEE Access, 11, 106733–106748. https://doi.org/10.1109/ACCESS.2023.3319214

Alghazzawi, D., Bamasaq, O., Ullah, H., & Asghar, M. Z. (2021). Efficient detection of DDoS attacks using a hybrid deep learning model with improved feature selection. Applied Sciences (Switzerland), 11(24). https://doi.org/10.3390/app112411634

Ali, T. E., Chong, Y. W., & Manickam, S. (2023). Machine Learning Techniques to Detect a DDoS Attack in SDN: A Systematic Review. Applied Sciences (Switzerland), 13(5). https://doi.org/10.3390/app13053183

Altamemi, A. J., Abdulhassan, A., & Obeis, N. T. (2022). DDoS attack detection in software defined networking controller using machine learning techniques. Bulletin of Electrical Engineering and Informatics, 11(5), 2836–2844. https://doi.org/10.11591/eei.v11i5.4155

Ataa, M. S., Sanad, E. E., & El-khoribi, R. A. (2024). Intrusion detection in software defined network using deep learning approaches. Scientific Reports, 14(1), 1–15. https://doi.org/10.1038/s41598-024-79001-1

Ben, S. R., Sabir, Z., & Askerzade, I. (2023). CNN-BiLSTM: A Hybrid Deep Learning Approach for Network Intrusion Detection System in Software-Defined Networking With Hybrid Feature Selection. IEEE Access, 11(December), 138732–138747. https://doi.org/10.1109/ACCESS.2023.3340142

Benlloch, P., Romero, O., Leon, A., & Lloret, J. (2026). MLDAS: Machine Learning Dynamic Algorithm Selection for Software‐Defined Networking Security. Concurrency and Computation: Practice and Experience, 38(5), e70637.

Bilal, A., Sharif, K., Zhu, L., Li, F., Xu, C., & Karim, M. M. (2026). Evaluation to integration: Hybrid feature selection framework with ensemble machine learning for intrusion detection. IEEE Transactions on Dependable and Secure Computing.

Çavşi Zaim, H., & Yolaçan, E. N. (2025). FPE–Transformer: A Feature Positional Encoding-Based Transformer Model for Attack Detection. Applied Sciences (Switzerland), 15(3). https://doi.org/10.3390/app15031252

Chaymae, E. Y., Abdellatif, K., Khalid, C., & Jalel, B. O. (2024). Intrusion Detection System using Transformer Encoder and CNN-BiLSTM in Software-Defined Networks. Proceedings - IEEE Global Communications Conference, GLOBECOM, Ml, 2214–2219. https://doi.org/10.1109/GLOBECOM52923.2024.10901492

Chen, L., Wang, Z., Huo, R., & Huang, T. (2023). An Adversarial DBN-LSTM Method for Detecting and Defending against DDoS Attacks in SDN Environments. Algorithms, 16(4). https://doi.org/10.3390/a16040197

Çil, A., & Demirci, M. (2026). SARE: Secure, Automated, and Regulatory‐Compliant Platform for Improving Forensic Readiness in Software‐Defined Networks. International Journal of Communication Systems, 39(1), e70299.

Hnamte, V., & Hussain, J. (2023). An efficient DDoS attack detection mechanism in SDN environment. International Journal of Information Technology (Singapore), 15(5), 2623–2636. https://doi.org/10.1007/s41870-023-01332-5

Hssayeni, M. D., & Mahgoub, I. (2026). A Transformer-Based Intrusion Detection System for Zero-Day Attack Detection in IoT Networks. Future Internet, 18(6), 282.

Li, M., Zhang, B., Wang, G., Zhuge, B., Jiang, X., & Dong, L. (2022). A DDoS attack detection method based on deep learning two-level model CNN-LSTM in SDN network. Proceedings - 2022 International Conference on Cloud Computing, Big Data Applications and Software Engineering, CBASE 2022, 282–287. https://doi.org/10.1109/CBASE57816.2022.00062

Liu, Z., Wang, Y., Feng, F., Liu, Y., Li, Z., & Shan, Y. (2023). A DDoS Detection Method Based on Feature Engineering and Machine Learning in Software-Defined Networks. Sensors, 23(13). https://doi.org/10.3390/s23136176

Mansoor, A., Anbar, M., Bahashwan, A. A., Alabsi, B. A., & Rihan, S. D. A. (2023). Deep Learning-Based Approach for Detecting DDoS Attack on Software-Defined Networking Controller. Systems, 11(6), 1–21. https://doi.org/10.3390/systems11060296

Mbasuva, U., & Zodi, G. A. L. (2022). Designing Ensemble Deep Learning Intrusion Detection System for DDoS attacks in Software Defined Networks. Proceedings of the 2022 16th International Conference on Ubiquitous Information Management and Communication, IMCOM 2022. https://doi.org/10.1109/IMCOM53663.2022.9721785

Muchtar, T., & Mutijarsa, K. (2025). Machine Learning for DDoS Attack Detection in SDN: A Systematic Literature Review. In 2025 IEEE 2nd International Conference on Cryptography, Informatics, and Cybersecurity (ICoCICs) (pp. 224–229). IEEE. https://doi.org/10.1109/ICoCICs68032.2025.11384079

Musa, N. S., Mirza, N. M., Rafique, S. H., Abdallah, A. M., & Murugan, T. (2024). Machine Learning and Deep Learning Techniques for Distributed Denial of Service Anomaly Detection in Software Defined Networks - Current Research Solutions. IEEE Access, 12(January), 17982–18011. https://doi.org/10.1109/ACCESS.2024.3360868

NetScout Systems, I. (2023). NETSCOUT Identified Nearly 7.9 Million DDoS Attacks in 1H2023 According to Its Latest DDoS Threat Intelligence Report.

Said, R. Ben, & Askerzade, I. (2023). Attention-Based CNN-BiLSTM Deep Learning Approach for Network Intrusion Detection System in Software Defined Networks. 2023 5th International Conference on Problems of Cybernetics and Informatics, PCI 2023, 1–5. https://doi.org/10.1109/PCI60110.2023.10325985

Sangodoyin, A. O., Akinsolu, M. O., Pillai, P., & Grout, V. (2021). Detection and Classification of DDoS Flooding Attacks on Software-Defined Networks: A Case Study for the Application of Machine Learning. IEEE Access, 9, 122495–122508. https://doi.org/10.1109/ACCESS.2021.3109490

Sheikh, M. N. A., Raza, M. S., Hwang, I.-S., Hossain, M. A., Ullah, I., Hasan, T., & Ab-Rahman, M. S. (2025). SDN-Enabled IoT based transport layer DDoS attacks detection using RNNs. Computers, Materials, & Continua, 85(2), 4043.

Wainwright, R., Bagheri, M., Salama, A., & Saatchi, R. (2025). Software-Defined Networking Security Detection Strategies and Their Limitations with a Focus on Distributed Denial-of-Service for Small to Medium-Sized Enterprises. Applied Sciences (Switzerland), 15(23), 1–19. https://doi.org/10.3390/app152312389

Wang, H., & Li, W. (2021). DDosTC: A transformer-based network attack detection hybrid mechanism in SDN. Sensors, 21(15). https://doi.org/10.3390/s21155047

Wang, J., & Wang, L. (2022). SDN-Defend: A Lightweight Online Attack Detection and Mitigation System for DDoS Attacks in SDN. Sensors, 22(21). https://doi.org/10.3390/s22218287

Wang, J., Wang, L., & Wang, R. (2023). A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers. Entropy, 25(8). https://doi.org/10.3390/e25081210

Yungaicela-Naula, N. M., Vargas-Rosales, C., & Perez-Diaz, J. A. (2021). SDN-based architecture for transport and application layer DDoS attack detection by using machine and deep learning. IEEE Access, 9, 108495–108512. https://doi.org/10.1109/ACCESS.2021.3101650

Downloads

Published

2026-09-03