Real-Time DDoS Detection Using Centralized SDN Controller and MLP
Abstract
Distributed Denial-of-Service (DDoS) attacks pose a significant threat to the availability and reliability of modern network infrastructures. Traditional detection mechanisms often lack scalability, adaptability, and real-time responsiveness, making them ineffective against evolving attack patterns. This paper proposes a real-time DDoS detection framework leveraging the programmability of Software Defined Networking (SDN) and machine learning techniques. The proposed system utilizes a centralized SDN controller (Ryu) integrated with a Multi-Layer Perceptron (MLP) classifier to analyze flow-level traffic statistics collected from an emulated network environment using Mininet. The classifier distinguishes between benign and malicious traffic in real time. Upon detection, strategies such as traffic filtering, rate limiting, and flow rule updates are applied. Experimental results demonstrate that the proposed framework achieves a detection accuracy of 97% with low latency and minimal controller overhead. The results highlight the effectiveness of integrating SDN with lightweight machine learning models for proactive and scalable network security.