Skip to content
Open access

Detection and Prevention of Internet Control Message Protocol Flood Attack in Software-Defined Network Using Dynamic Threshold and Machine Learning

2026 · IEEE Access · Vol 14, pp. 133264-133284 · 0 citations · 23 references

Abstract

With programmability and centralized control, Software-Defined Networking (SDN) has become a revolutionary networking paradigm that makes network administration easier. Nevertheless, vulnerabilities are also introduced by this architectural flexibility, especially Internet Control Message Protocol (ICMP) flooding assaults, which significantly impair network availability and performance. Low detection accuracy and slow reaction times result from traditional static threshold-based detection techniques’ inability to adjust to the dynamic nature of network traffic. This paper proposes a hybrid ICMP flood detection and mitigation strategy that combines a Support Vector Machine (SVM) classifier installed directly on the RYU controller with a real-time dynamic threshold mechanism (based on continuous mean and standard deviation computation). While the SVM classifier, trained on labeled datasets, discerns between malicious and valid ICMP packets, the dynamic threshold allows adaptive traffic control based on flow statistics within predetermined time intervals. The RYU controller and Mininet emulator are used to create the suggested framework, which is then assessed in realistic SDN scenarios. According to experimental results, the SVM-based dynamic threshold solution adds only 8.9% CPU overhead to the controller while achieving 97.8% detection accuracy for pure ICMP flood attacks and maintaining 96.3% accuracy even with 25% mixed UDP traffic. 98% of legal ICMP traffic is preserved while fraudulent sources are blocked in 3.1 seconds thanks to the system’s automated OpenFlow rule installation. The results demonstrate that integrating machine learning and statistical flow analysis improves SDN resilience by offering flexible, real-time security against ICMP flood attacks with minimum computing overhead.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.