Skip to content
Open access

An Adaptive and Scalable DDoS Prevention Framework for Software Defined Networks

Jul 2026 · International journal of computer information systems and industrial management applications · Vol 18, pp. 863-872 · 0 citations

TL;DR

The adaptive outline lessens controller CPU utilization, speeds up mitigation response times, lowers end-to-end latency, and keeps higher throughput when compared to static mitigation procedures, according to experimental evaluations carried out in a precise SDN emulation environment.

Abstract

Central governance and flexible network administration are made possible by Software Defined Networking (SDN); still, this architectural benefit also makes the control plane vulnerable to Distributed Denial of Service (DDoS) attacks. An extreme number of flow requests and packet-in events can significantly reduce controller effectiveness and interfere with network functions in the context of such attacks. In this work, we change and estimate an adaptive DDoS prevention framework based on knowledge gained from SDN emulation tests. Relatively than relying on predetermined mitigation thresholds, the framework dynamically adjusts mitigation strategies based on the attack's severity and the controller's present load. The proposed approach reduces unnecessary interactions in the control plane while maintaining service quality for authorized traffic by incorporating controller-aware decision-making. The adaptive outline lessens controller CPU utilization, speeds up mitigation response times, lowers end-to-end latency, and keeps higher throughput when compared to static mitigation procedures, according to experimental evaluations carried out in a precise SDN emulation environment

Read PDF

Similar papers

Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...

Kamal Singh, Brijesh Kumar · 0 citations
Review Open access Aug 2026

Software-Defined Networking Security: Architecture, Attack Surface, and Resilient Mechanisms

A comprehensive survey of the SDN security by covering its architecture, key benefits and potential vulnerabilities, and explores potential attacks on the data plane, attacks on the communication channels outside the control plane, security challenges in the control plane, and existing approaches and proposed counterme...

AJIT Karki, V. R, H. A. Akarte et al. · 0 citations

Automatic, Verifiable and Optimized Policy-based Security Enforcement for SDN-aware IoT networks

A novel methodology which leverages Maximum Satisfiability Modulo Theories (MaxSMT) to automatically compute a formally correct and optimized allocation scheme and configuration of SDN switches by refining security policies, user-defined or derived from detected attacks is proposed.

Daniele Bringhenti, Jalolliddin Yusupov, A. M. Zarca et al. · 8 citations
Open access 2026

DDoS Defense Model on 5G Network Slices

A 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN is proposed.

Kun-Lin Tsai, Shih-Ting Chiu, Chihhsiong Shih et al. · 0 citations
Conference Jul 2026

Towards a Reference Architecture for Intelligent Anomaly Detection in Software-Defined Networks

Emerging technologies such as Cloud Computing, 5G, the Internet of Things (IoT), and Edge Computing demand the management of large-scale and highly dynamic network infrastructures. Traditional network configuration does not scale efficiently, whereas Software-Defined Networking (SDN) enables centralized control and sim...

Rivaldo Fernandes, B. Dalmazo, A. Riker et al. · 0 citations
Open access Aug 2026

Lightweight Rescaled Range R/S-Based Real-Time DDoS Detection for Software-Defined Networks

A lightweight Rescaled Range (R/S)-based scheme for effective real-time DDoS attack detection in SDN that efficiently captures changes in self-similarity and detects TCP/UDP DDoS attacks in real time is proposed.

M. Awad, Ghazal Alsholi, Haniah Altabaa et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.