Modern Approaches to Detecting Cyberattacks in Software-Defined Networks
Abstract
The rapid deployment of software-defined networks provides high flexibility and scalability of network infrastructures, but at the same time creates new challenges for cybersecurity due to the centralization of control logic. The paper provides a comprehensive analysis of modern approaches to detecting cyberattacks in SDN environments. An analytical review of scientific publications showed that about 84.6% of existing solutions are focused specifically on detecting DDoS attacks, while other types of threats, including Man-inthe-Middle, ARP spoofing, brute force, malware, and U2R, are underrepresented. It was found that the most common are hybrid deep learning models that combine convolutional and recurrent neural networks, as well as approaches based on reinforcement learning, federated learning, and natural language processing methods. Despite the high values of efficiency metrics (over 95%), most solutions are characterized by limited coverage of attack types and lack of universality. The results obtained show that individual methods on average cover less than 50% of possible attack scenarios, which necessitates the integration of several complementary approaches. The results indicate the feasibility of developing complex multi-level detection systems capable of providing effective protection of SDN infrastructures from various cyber threats.