Related Experiment Video
Updated: Jun 21, 2025

07:13
Early Detection of Cyanobacterial Blooms and Associated Cyanotoxins using Fast Detection Strategy
Published on: February 25, 2021
3.8K
Detection and mitigation of DDoS attacks based on multi-dimensional characteristics in SDN.
Kun Wang1,2, Yu Fu3, Xueyuan Duan4,5
1Department of Information Security, Naval University of Engineering, Wuhan, 430033, China.
Scientific Reports
|July 16, 2024
Summary
This study introduces a two-stage method for detecting and mitigating Distributed Denial of Service (DDoS) attacks in Software-Defined Networking (SDN). The approach enhances detection accuracy and network security by analyzing multi-dimensional traffic characteristics.
Area of Science:
- Computer Science
- Cybersecurity
- Network Engineering
Background:
- Traditional Distributed Denial of Service (DDoS) detection and mitigation in Software-Defined Networking (SDN) suffer from high computational overhead, feature underutilization, and excessive bandwidth consumption.
- Existing methods often lack the efficiency and accuracy required for real-time threat management in dynamic SDN environments.
Purpose of the Study:
- To propose and evaluate a novel two-stage detection and mitigation method for DDoS attacks in SDN environments.
- To address the limitations of traditional methods by leveraging multi-dimensional traffic characteristics for improved accuracy and efficiency.
Main Methods:
- A two-stage approach involving coarse-grained detection via traffic statistics analysis and fine-grained detection using a Multi-Dimensional Deep Convolutional Classifier (MDDCC).
- The MDDCC employs wavelet decomposition and convolutional neural networks to extract multi-dimensional features from traffic data.
- Attack source tracing and isolation are achieved by integrating graph theory with restrictive strategies.
Main Results:
- The proposed method achieves quick and accurate DDoS attack detection in SDN networks using minimal statistical information.
- Experimental results demonstrate superior accuracy and generalization capabilities compared to traditional methods on both simulated and public datasets.
- Effective mitigation is achieved by isolating affected nodes, ensuring the continued transmission of legitimate traffic during attacks.
Conclusions:
- The developed method significantly enhances DDoS attack detection and mitigation capabilities in SDN environments.
- It offers a robust mechanism for containing cyber threats and safeguarding network integrity and performance.
- The approach provides a more efficient and accurate alternative to conventional DDoS defense strategies in SDN.

