Hierarchical SDN DDoS Detection in IoT Networks via Shannon Entropy and Adaptive Thresholding
Abstract
Internet of Things (IoT) devices integrated with Software-Defined Networking (SDN) have increased network flexibility and centralized management. However, this architecture is increasingly vulnerable to volumetric Distributed Denial-of-Service (DDoS) attacks, which can degrade Quality of Service (QoS) and disrupt critical network services. Existing entropy-based detection approaches generally rely on flat SDN topologies and static thresholds, resulting in delayed attack isolation and increased false-positive rates during legitimate traffic surges. To address these limitations, this study proposes a lightweight DDoS detection and mitigation framework that combines Shannon Entropy with Adaptive Dynamic Thresholds in a hierarchical SDN architecture. The proposed system is implemented using Mininet, Open vSwitch, and Ryu Controller, and evaluated against UDP Flood, ICMP Flood, and TCP SYN Flood attacks. The hierarchical architecture enables mitigation at the Gateway layer, preventing malicious traffic from reaching the core network. Experimental results show that the proposed approach effectively recovers network performance after mitigation, increasing throughput from 0.09 Mbps during the attack to 6.36 Mbps while reducing packet loss from 100% to 0%. The classification performance achieves an overall accuracy of 91% with an AUC-ROC of 0.941, demonstrating strong capability in distinguishing malicious traffic from legitimate traffic. These results demonstrate that the proposed framework provides an effective and computationally efficient solution for securing SDN-based IoT networks against volumetric DDoS attacks while maintaining normal network performance.