Aug 2026· International Conference on Data Technologies and Applications· 0 citations· 19 references
TL;DR
LAN-SDN-NIDS is presented, a publicly available, multi-class flow-level dataset of 1,125,059 records generated in a fully containerized Containernet/OpenDaylight testbed across five standard network topologies, indicating that control-plane telemetry is decisive for detecting SDN-architectural attacks under the conditions evaluated.
Abstract
Software-Defined Networking (SDN) separates the control and data planes, introducing a logically centralized controller that is itself a high-value attack target. Despite growing interest in SDN intrusion detection, publicly available datasets either restrict evaluation to binary normal-vs-DDoS classification or lack control-plane telemetry, leaving multi-class detection of SDN-architectural attacks without a dedicated benchmark. This work presents LAN-SDN-NIDS, a publicly available, multi-class flow-level dataset of 1,125,059 records generated in a fully containerized Containernet/OpenDaylight testbed across five standard network topologies. Each flow record combines 29 traffic-level features with 11 control-plane-aware metrics—including Packet-In and Flow-Mod counts and first-seen delay. The dataset covers five attack classes in two categories: three that exploit SDN control-plane mechanisms (link fabrication, host injection, and port hijack) alongside DDoS and port scan, plus normal traffic. An XGBoost classifier trained on the full feature set achieved a macro F1 of 0.94; an ablation study showed that removing OpenFlow features causes link fabrication F1 to collapse from 0.97 to 0.19, indicating that control-plane telemetry is decisive for detecting SDN-architectural attacks under the conditions evaluated. A UMAP embedding is consistent with class separability, except for a structural overlap between host injection and normal traffic attributable to their shared ARP protocol.
Distributed Denial-of-Service (DDoS) attacks pose a significant threat to the availability and reliability of modern network infrastructures. Traditional detection mechanisms often lack scalability, adaptability, and real-time responsiveness, making them ineffective against evolving attack patterns. This paper proposes...
Maragani Venkata Naga Jagadeesh, K. S. S. Prasad, Raya Venkata Karthik Reddy et al.· International Conference on...· 0 citations
Overall, the results show that KNIMEs no-code workflow framework can offer production-level DDoS detection comparable to conventional code-based techniques, providing a workable and extremely accurate way to safeguard programmable networks.
A sniffer-free detection pipeline that operates exclusively on the integer counters each mote already maintains for normal operation of RPL, indicating that detection in constrained IoT networks is bounded by what the mote reports, not by classifier sophistication.
E. Pacheco, C. Pedroso· IEEE Open Journal of the Com...· 0 citations
A lightweight Rescaled Range (R/S)-based scheme for effective real-time DDoS attack detection in SDN that efficiently captures changes in self-similarity and detects TCP/UDP DDoS attacks in real time is proposed.
M. Awad, Ghazal Alsholi, Haniah Altabaa et al.· Network· 0 citations
Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...
Kamal Singh, Brijesh Kumar· international journal of eng...· 0 citations
A cross-domain confidence-fusion framework that leverages lightweight edge-side messages to calibrate aggregation-controller decisions without sharing raw traffic data is proposed that is non-intrusive, communication-efficient, and incrementally deployable.