Skip to content
Open access

A Multi-Class SDN Intrusion Detection Dataset with Synchronized OpenFlow Control-Plane Telemetry

Aug 2026 · International Conference on Data Technologies and Applications · 0 citations · 19 references

TL;DR

LAN-SDN-NIDS is presented, a publicly available, multi-class flow-level dataset of 1,125,059 records generated in a fully containerized Containernet/OpenDaylight testbed across five standard network topologies, indicating that control-plane telemetry is decisive for detecting SDN-architectural attacks under the conditions evaluated.

Abstract

Software-Defined Networking (SDN) separates the control and data planes, introducing a logically centralized controller that is itself a high-value attack target. Despite growing interest in SDN intrusion detection, publicly available datasets either restrict evaluation to binary normal-vs-DDoS classification or lack control-plane telemetry, leaving multi-class detection of SDN-architectural attacks without a dedicated benchmark. This work presents LAN-SDN-NIDS, a publicly available, multi-class flow-level dataset of 1,125,059 records generated in a fully containerized Containernet/OpenDaylight testbed across five standard network topologies. Each flow record combines 29 traffic-level features with 11 control-plane-aware metrics—including Packet-In and Flow-Mod counts and first-seen delay. The dataset covers five attack classes in two categories: three that exploit SDN control-plane mechanisms (link fabrication, host injection, and port hijack) alongside DDoS and port scan, plus normal traffic. An XGBoost classifier trained on the full feature set achieved a macro F1 of 0.94; an ablation study showed that removing OpenFlow features causes link fabrication F1 to collapse from 0.97 to 0.19, indicating that control-plane telemetry is decisive for detecting SDN-architectural attacks under the conditions evaluated. A UMAP embedding is consistent with class separability, except for a structural overlap between host injection and normal traffic attributable to their shared ARP protocol.

Read PDF

Similar papers

Conference Aug 2026

Real-Time DDoS Detection Using Centralized SDN Controller and MLP

Distributed Denial-of-Service (DDoS) attacks pose a significant threat to the availability and reliability of modern network infrastructures. Traditional detection mechanisms often lack scalability, adaptability, and real-time responsiveness, making them ineffective against evolving attack patterns. This paper proposes...

Maragani Venkata Naga Jagadeesh, K. S. S. Prasad, Raya Venkata Karthik Reddy et al. · 0 citations
Open access 2026

Observability-Driven, Sniffer-Free Intrusion Detection for RPL: Closing the Detection Ceiling With On-Mote Control-Plane Features

A sniffer-free detection pipeline that operates exclusively on the integer counters each mote already maintains for normal operation of RPL, indicating that detection in constrained IoT networks is bounded by what the mote reports, not by classifier sophistication.

E. Pacheco, C. Pedroso · 0 citations
Open access Aug 2026

Lightweight Rescaled Range R/S-Based Real-Time DDoS Detection for Software-Defined Networks

A lightweight Rescaled Range (R/S)-based scheme for effective real-time DDoS attack detection in SDN that efficiently captures changes in self-similarity and detects TCP/UDP DDoS attacks in real time is proposed.

M. Awad, Ghazal Alsholi, Haniah Altabaa et al. · 0 citations
Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...

Kamal Singh, Brijesh Kumar · 0 citations
Preprint Aug 2026

Cross-Domain Joint DDoS Detection in Multi-Controller SDN via Confidence-Based Entropy Fusion

A cross-domain confidence-fusion framework that leverages lightweight edge-side messages to calibrate aggregation-controller decisions without sharing raw traffic data is proposed that is non-intrusive, communication-efficient, and incrementally deployable.

Zhaoyang Zhang, Shen Wang, Xiao-Feng Tao · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.