{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T05:20:38Z","timestamp":1780636838099,"version":"3.54.1"},"reference-count":31,"publisher":"Engineering and Technology Publishing","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["jcm"],"published-print":{"date-parts":[[2021]]},"abstract":"<jats:p>This paper proposes a hybrid technique for distributed denial-of-service (DDoS) attack detection that combines statistical analysis and machine learning, with software defined networking (SDN) security. Data sets are analyzed in an iterative approach and compared to a dynamic threshold. Sixteen features are extracted, and machine learning is used to examine correlation measures between the features. A dynamically configured SDN is employed with software defined security (SDS), to provide a robust policy framework to protect the availability and integrity, and to maintain privacy of all the networks with quick response remediation. Machine learning is further employed to increase the precision of detection. This increases the accuracy from 87\/88% to 99.86%, with reduced false positive ratio (FPR). The results obtained based on experimental data-sets outperformed existing techniques.<\/jats:p>","DOI":"10.12720\/jcm.16.7.267-275","type":"journal-article","created":{"date-parts":[[2021,10,20]],"date-time":"2021-10-20T07:51:00Z","timestamp":1634716260000},"page":"267-275","source":"Crossref","is-referenced-by-count":13,"title":["SDN Enabled DDoS Attack Detection and Mitigation for 5G Networks"],"prefix":"10.12720","author":[{"name":"Macquarie University, Sydney, Australia","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bhulok","family":"Aryal","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Robert","family":"Abbas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Iain B.","family":"Collings","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"4977","published-online":{"date-parts":[[2021]]},"reference":[{"key":"ref0","doi-asserted-by":"publisher","unstructured":"[1] F. Bensalah, N. Elkamoun, and Y. Baddi, \"SDNStat-Sec: A statistical defense mechanism against DDoS attacks in SDN-based VANET,\" in Advances on Smart and Soft Computing, Springer, pp. 527-540.","DOI":"10.1007\/978-981-15-6048-4_46"},{"key":"ref1","doi-asserted-by":"publisher","unstructured":"[2] H. Li and L. Wang, \"Online orchestration of cooperative defense against DDoS attacks for 5G MEC,\" in Proc. IEEE Wireless Communications and Networking Conference, 2018.","DOI":"10.1109\/WCNC.2018.8377309"},{"key":"ref2","doi-asserted-by":"publisher","unstructured":"[3] A. S. Mamolar, Z. Pervez, J. M. A. Calero, and A. M. Khattak, \"Towards the transversal detection of DDoS network attacks in 5G multi-tenant overlay networks,\" Computers & Security, vol. 79, pp. 132-147, 2018.","DOI":"10.1016\/j.cose.2018.07.017"},{"key":"ref3","doi-asserted-by":"publisher","unstructured":"[4] B. Hussain, Q. Du, B. Sun, and Z. Han, \"Deep learning-based DDoS-Attack detection for cyber-physical system over 5G network,\" IEEE Transactions on Industrial Informatics, 2020.","DOI":"10.1109\/TII.2020.2974520"},{"key":"ref4","doi-asserted-by":"publisher","unstructured":"[5] M. K. Forland, K. Kralevska, M. Garau, and D. Gligoroski, \"Preventing DDoS with SDN in 5G,\" in Proc. IEEE Globecom Workshops (GC Wkshps), 2019.","DOI":"10.1109\/GCWkshps45667.2019.9024497"},{"key":"ref5","doi-asserted-by":"publisher","unstructured":"[6] G. C. Hong, C. N. Lee, and M. F. Lee, \"Dynamic threshold for DDoS mitigation in SDN environment,\" in Proc. Asia-Pacific Signal and Information Processing Association Annual Summit and Conference, 2019.","DOI":"10.1109\/APSIPAASC47483.2019.9023229"},{"key":"ref6","doi-asserted-by":"publisher","unstructured":"[7] A. S. Mamolar, P. Salv\u00e1-Garc\u0131\u0301a, E. Chirivella-Perez, Z. Pervez, J. M. A. Calero, and Q. Wang, \"Autonomic protection of multi-tenant 5G mobile networks against UDP flooding DDoS attacks,\" Journal of Network and Computer Applications, vol. 145, p. 102416, 2019.","DOI":"10.1016\/j.jnca.2019.102416"},{"key":"ref7","doi-asserted-by":"publisher","unstructured":"[8] M. Monshizadeh, V. Khatri, and R. Kantola, \"Detection as a service: an SDN application,\" in Proc. 19th International Conference on Advanced Communication Technology, 2017.","DOI":"10.23919\/ICACT.2017.7890099"},{"key":"ref8","doi-asserted-by":"publisher","unstructured":"[9] K. Cabaj, M. Gregorczyk, W. Mazurczyk, P. Nowakowski, and P. \u017b\u00f3rawski, \"Sdn-based mitigation of scanning attacks for the 5g internet of radio light system,\" in Proc. 13th International Conference on Availability, Reliability and Security, 2018.","DOI":"10.1145\/3230833.3233248"},{"key":"ref9","unstructured":"[10] M. Tiloca, A. Stagkopoulou, and G. Dini, \"Performance and security evaluation of SDN networks in OMNeT++\/INET,\" arXiv preprint arXiv:1609.04554, 2016."},{"key":"ref10","unstructured":"[11] J. Lam and R. Abbas, \"Machine learning based anomaly detection for 5G networks,\" arXiv preprint arXiv:2003.03474, 2020."},{"key":"ref11","doi-asserted-by":"publisher","unstructured":"[12] Q. Yan, Q. Gong, and F. R. Yu, \"Effective software-defined networking controller scheduling method to mitigate DDoS attacks,\" Electronics Letters, vol. 53, p. 469-471, 2017.","DOI":"10.1049\/el.2016.2234"},{"key":"ref12","doi-asserted-by":"publisher","unstructured":"[13] S. S. Dhaliwal, A. A. Nahid, and R. Abbas, \"Effective intrusion detection system using XGBoost,\" Information, vol. 9, p. 149, 2018.","DOI":"10.3390\/info9070149"},{"key":"ref13","doi-asserted-by":"publisher","unstructured":"[14] H. Polat, O. Polat, and A. Cetin, \"Detecting DDoS attacks in software-defined networks through feature selection methods and machine learning models,\" Sustainability, vol. 12, p. 1035, 2020.","DOI":"10.3390\/su12031035"},{"key":"ref14","doi-asserted-by":"publisher","unstructured":"[15] S. Smys, A. Basar, and H. Wang, \"Hybrid intrusion detection system for Internet of Things (IoT),\" Journal of ISMAC, vol. 2, pp. 190-199, 2020.","DOI":"10.36548\/jismac.2020.4.002"},{"key":"ref15","doi-asserted-by":"publisher","unstructured":"[16] C. S. Rajpoot, A. K. Bairwa, and V. K. Sharma, \"Mitigating the impact of DDoS attack on upsurge network performance in MANET,\" in Proc. International Conference on Communication and Computational Technologies, 2020.","DOI":"10.1007\/978-981-15-5077-5_14"},{"key":"ref16","doi-asserted-by":"publisher","unstructured":"[17] Y. Cui, L. Yan, S. Li, H. Xing, W. Pan, J. Zhu, and X. Zheng, \"SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks,\" Journal of Network and Computer Applications, vol. 68, pp. 65-79, 2016.","DOI":"10.1016\/j.jnca.2016.04.005"},{"key":"ref17","doi-asserted-by":"publisher","unstructured":"[18] O. Yavanoglu and M. Aydos, \"A review on cyber security datasets for machine learning algorithms,\" in Proc. IEEE International Conference on Big Data, 2017.","DOI":"10.1109\/BigData.2017.8258167"},{"key":"ref18","doi-asserted-by":"publisher","unstructured":"[19] H. H. Jazi, H. Gonzalez, N. Stakhanova, and A. A. Ghorbani, \"Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling,\" Computer Networks, vol. 121, pp. 25-36, 2017.","DOI":"10.1016\/j.comnet.2017.03.018"},{"key":"ref19","doi-asserted-by":"publisher","unstructured":"[20] D. Bhamare, T. Salman, M. Samaka, A. Erbad, and R. Jain, \"Feasibility of supervised machine learning for cloud security,\" in Proc. International Conference on Information Science and Security, 2016.","DOI":"10.1109\/ICISSEC.2016.7885853"},{"key":"ref20","unstructured":"[21] W. Koehrson, \"Beyond accuracy: Precision and recall,\" Towards Data Science, 2018."},{"key":"ref21","unstructured":"[22] Z. Tan, A. Jamdagni, X. He, P. Nanda, R. P. Liu, and J. Hu, \"Detection of denial-of-service attacks based on computer vision techniques,\" 2018."},{"key":"ref22","unstructured":"[23] W. Yassin, N. I. Udzir, Z. Muda, M. N. Sulaiman, and others, \"Anomaly-based intrusion detection through k-means clustering and naives bayes classification,\" 2017."},{"key":"ref23","doi-asserted-by":"publisher","unstructured":"[24] N. Fallahi, A. Sami, and M. Tajbakhsh, \"Automated flow-based rule generation for network intrusion detection systems,\" in Proc. 24th Iranian Conference on Electrical Engineering, 2016.","DOI":"10.1109\/IranianCEE.2016.7585840"},{"key":"ref24","unstructured":"[25] C. Catania and C. G. Garino, \"Towards reducing human effort in network intrusion detection,\" in Proc. IEEE 7th International Conference on Intelligent Data Acquisition and Advanced Computing Systems, 2019."},{"key":"ref25","doi-asserted-by":"publisher","unstructured":"[26] A. Saied, R. E. Overill, and T. Radzik, \"Detection of known and unknown DDoS attacks using artificial neural networks,\" Neurocomputing, vol. 172, pp. 385-393, 2016.","DOI":"10.1016\/j.neucom.2015.04.101"},{"key":"ref26","doi-asserted-by":"publisher","unstructured":"[27] B. Wang, Y. Zheng, W. Lou, and Y. T. Hou, \"DDoS attack protection in the era of cloud computing and software-defined networking,\" Computer Networks, vol. 81, pp. 308-319, 2018.","DOI":"10.1016\/j.comnet.2015.02.026"},{"key":"ref27","unstructured":"[28] P. Kalaivani and M. Vijaya, \"Mining based detection of botnet traffic in network flow,\" International Journal of Computer Science and Information Technology & Security, 2016."},{"key":"ref28","doi-asserted-by":"publisher","unstructured":"[29] A. Bansal and S. Mahapatra, \"A comparative analysis of machine learning techniques for botnet detection,\" in Proc. 10th International Conference on Security of Information and Networks, 2017.","DOI":"10.1145\/3136825.3136874"},{"key":"ref29","doi-asserted-by":"publisher","unstructured":"[30] R. Chen, W. Niu, X. Zhang, Z. Zhuo, and F. Lv, \"An effective conversation-based botnet detection method,\" Mathematical Problems in Engineering, vol. 2017, 2017.","DOI":"10.1155\/2017\/4934082"},{"key":"ref30","unstructured":"[31] S. Oshima, T. Nakashima, and T. Sueyosh, \"Detection technique using statistical analysis to generate quick response time,\" in Proc. International Conference on Broadband, Wireless Computing, Communication and Applications, 2017."}],"container-title":["Journal of Communications"],"original-title":[],"link":[{"URL":"http:\/\/www.jocm.us\/uploadfile\/2021\/0618\/20210618052054569.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,25]],"date-time":"2021-11-25T06:17:04Z","timestamp":1637821024000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.jocm.us\/show-257-1668-1.html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":31,"URL":"https:\/\/doi.org\/10.12720\/jcm.16.7.267-275","relation":{},"ISSN":["2374-4367"],"issn-type":[{"value":"2374-4367","type":"print"}],"subject":[],"published":{"date-parts":[[2021]]}}}