Related Experiment Video
Updated: Aug 30, 2025

Automated Deployment of an Internet Protocol Telephony Service on Unmanned Aerial Vehicles Using Network Functions Virtualization
Published on: November 26, 2019
A variable-trust threshold-based approach for DDOS attack mitigation in software defined networks
Fatty M Salem1, Hoda Youssef2, Ihab Ali1
1Department of Electronics and Communications Engineering, Faculty of Engineering, Helwan University, Cairo, Egypt.
This study introduces a novel two-phase algorithm to detect Distributed Denial of Service (DDoS) attacks in Software-Defined Networks (SDN). The method dynamically assesses user trust to effectively mitigate network threats and improve performance.
Area of Science:
- Computer Science
- Network Security
- Cybersecurity
Background:
- Software-Defined Networks (SDN) offer advanced features but are vulnerable to attacks, particularly Distributed Denial of Service (DDoS).
- The centralized nature of SDN controllers makes them a critical target for DDoS attacks, potentially crippling the entire network.
- Existing DDoS mitigation schemes struggle with accurately distinguishing legitimate from malicious traffic.
Purpose of the Study:
- To propose and evaluate a novel two-phase algorithm for mitigating DDoS attacks targeting SDN controllers.
- To enhance the security and reliability of SDN by effectively detecting and mitigating malicious traffic.
- To address the challenge of dynamically determining thresholds for differentiating legitimate and malicious user requests.
Main Methods:
- A two-phase algorithm is introduced for DDoS attack detection in SDN.
- Phase 1 involves extracting relevant header fields from network traffic.
- Phase 2 calculates a dynamic trust value for each user based on header information, enabling adaptive threat detection.
Main Results:
- The proposed approach demonstrates superior performance compared to existing DDoS detection schemes.
- Achieved high accuracy, detection rate, and a low false-positive rate in identifying malicious traffic.
- The system's accuracy reached up to 98.83%, significantly outperforming traditional methods.
Conclusions:
- The developed two-phase algorithm effectively mitigates DDoS attacks in SDN environments.
- Dynamic trust value calculation provides a more robust method for distinguishing malicious from legitimate requests.
- The findings highlight a significant advancement in securing SDN infrastructure against sophisticated cyber threats.
Related Concept Videos
Zones of Protection
Protective zones are defined by closed dashed lines, containing one or more components. A key characteristic of these zones is the strategic placement of...
Distributed Loads: Problem Solving
Distribution Reliability and Automation
Network Function of a Circuit
Multimachine Stability
In analyzing the system, the nodal equations represent the relationship between bus voltages, machine voltages, and machine currents. The nodal equation is given by:
Line Protection with Impedance Relays
Under normal conditions, low load currents keep the measured...

