Jul 2026· 2026 International Conference on Intelligent and Sustainable AI Systems (ICOSAAS)· pp. 444-450· 0 citations· 8 references
Abstract
The rapid proliferation of Internet of Things (IoT) devices has fundamentally transformed global network infrastructure while simultaneously creating an expanding attack surface for advanced Distributed Denial of Service (DDoS) threats. IoT endpoints are inherently resource-constrained, making them vulnerable to exploitation as botnet nodes for large-scale DDoS campaigns. Conventional security mechanisms including statically configured firewalls and signature-based intrusion detection systems are insufficiently scalable and adaptive for heterogeneous IoT environments. This paper proposes a lightweight, hybrid Software-Defined Networking (SDN)-based framework for real-time DDoS detection and automated mitigation. The proposed system integrates Shannon entropy-based traffic anomaly detection at the data plane with a Random Forest (RF) classifier deployed at the Ryu SDN controller. Training and evaluation are performed on the CICDDoS2019 benchmark dataset, and end-to-end validation is conducted using Mininet network simulation. Experimental results demonstrate an average detection accuracy of 98.2%, a mean false positive rate (FPR) of 1.6%, a mean F1-score of 98.2%, and a mean mitigation time of 43 ms across four DDoS attack categories: UDP Flood, TCP SYN Flood, ICMP Flood, and HTTP Flood. The proposed approach achieves a favorable accuracy-overhead balance and outperforms state-of-the-art baselines in multiple evaluation dimensions.
Internet of Things (IoT) devices integrated with Software-Defined Networking (SDN) have increased network flexibility and centralized management. However, this architecture is increasingly vulnerable to volumetric Distributed Denial-of-Service (DDoS) attacks, which can degrade Quality of Service (QoS) and disrupt criti...
This thesis presents an efficient and adversarial-resilient IDS framework to detect existing and previously unseen cyberattacks for SDN-based IoT networks.
Manlaibaatar Tserenkhuu, Y. Kadobayashi· 0 citations
Distributed Denial-of-Service (DDoS) attacks pose a significant threat to the availability and reliability of modern network infrastructures. Traditional detection mechanisms often lack scalability, adaptability, and real-time responsiveness, making them ineffective against evolving attack patterns. This paper proposes...
Maragani Venkata Naga Jagadeesh, K. S. S. Prasad, Raya Venkata Karthik Reddy et al.· International Conference on...· 0 citations
—As cyberattacks targeting Internet of Things (IoT) networks grow more sophisticated, the demand for models capable of accurately detecting and mitigating these threats becomes increasingly urgent existing detection systems often concentrate on a single attack surface which leads to critical blind spots in IoT network...
Rania A. Al-Ali, Mohammad M. Alnabhan, Q. A. Al-Haija· Journal of Advances in Infor...· 0 citations
This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks that integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while re...
Ruthwik Palem, Likhith Reddy Peketi, Vanathi M et al.· Cureus Journal of Computer S...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.