{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T03:21:51Z","timestamp":1781925711015,"version":"3.54.5"},"reference-count":32,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2023,8,14]],"date-time":"2023-08-14T00:00:00Z","timestamp":1691971200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Software defined networking (SDN) improves the flexibility and programmability of the network by separating the control plane and the data plane and effectively realizes the global control of the network infrastructure. However, the centralized structure design of SDN exposes the controller to potential threats. Attackers have used the active flow table delivery mode to launch distributed denial of service (DDoS) attacks on the SDN controller, resulting in the controller failure and seriously affecting the network performance. To overcome this problem, this paper proposes a defense framework called CC-Guard. The framework consists of four modules: attack detection triggering, switch migration, anomaly detection, and mitigation. Among them, the attack detection trigger module improves the system\u2019s timely response to DDoS attacks. The switch migration module effectively unclogs the controller congestion problem and provides convenience for network flow transmission. The anomaly detection module uses a coarse-grained method for two-stage detection, which improves the detection accuracy. The mitigation module uses the idea of cross-domain cooperation of the controller to clear the abnormal flow in the blacklist. Experimental results show that our proposed CC-Guard has real-time DDoS attack defense capability and high detection accuracy, as well as efficient network resource utilization.<\/jats:p>","DOI":"10.3390\/e25081210","type":"journal-article","created":{"date-parts":[[2023,8,14]],"date-time":"2023-08-14T10:13:57Z","timestamp":1692008037000},"page":"1210","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers"],"prefix":"10.3390","volume":"25","author":[{"given":"Jin","family":"Wang","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University of Technology, Hangzhou 310023, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Liping","family":"Wang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University of Technology, Hangzhou 310023, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruiqing","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Mathematics, Zhengzhou University of Aeronautics, Zhengzhou 450046, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,8,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1567","DOI":"10.1109\/COMST.2017.2690823","article-title":"SDN\/NFV-Based Mobile Packet Core Network Architectures: A Survey","volume":"19","author":"Nguyen","year":"2017","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"897","DOI":"10.1109\/TIFS.2018.2868220","article-title":"A Policy-Based Security Architecture for Software Defined Networks","volume":"14","author":"Varadharajan","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Bera, P., Saha, A., and Setua, S. (2016, January 10\u201311). Denial of Service Attack in Software Defined Network. Proceedings of the 5th International Conference on Computer Science and Network Technology (ICSNT), Changchun, China.","DOI":"10.1109\/ICCSNT.2016.8070208"},{"key":"ref_4","unstructured":"(2022, September 11). OpenFlow Switch Specifification V1.4.0. Available online: https:\/\/www.opennetworking.org\/wp-content\/uploads\/2014\/10\/openflow-spec-v1.4.0.pdf."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"107398","DOI":"10.1016\/j.ymssp.2020.107398","article-title":"1D convolutional neural networks and applications: A survey","volume":"151","author":"Kiranyaz","year":"2021","journal-title":"Mech. Syst. Signal Process."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"102942","DOI":"10.1016\/j.jnca.2020.102942","article-title":"A GRU deep learning system against attacks in software defined networks","volume":"177","author":"Assis","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"3855","DOI":"10.1109\/TDSC.2021.3108782","article-title":"Detdcting and Mitigating DDoS Attacks in SDN Using Spatial-Temporal Graph Convolutional Network","volume":"19","author":"Cao","year":"2022","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Agha, S., and Rehman, O. (2020, January 20\u201321). Improving Discrimination Accuracy Rate of DDoS Attacks and Flash Events. Proceedings of the 2020 International Conference on Cyber Warfare and Security (ICCWS), Islamabad, Pakistan.","DOI":"10.1109\/ICCWS48432.2020.9292377"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Nam, T., Phong, P., and Khoa, T. (2018, January 10\u201312). Self-organizing map-based approaches in DDoS flooding detection using SDN. Proceedings of the 32nd International Conference on Information Networking (ICOIN), Chiang Mai, Thailand.","DOI":"10.1109\/ICOIN.2018.8343119"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Deepa, V., Sudar, K., and Deepalakshmi, P. (2019, January 30\u201331). Design of Ensemble Learning Methods for DDoS Detection in SDN Environment. Proceedings of the 2019 International Conference on Vision Towards Emerging Trends in Communication and Networking (Vi-TECoN), Vellore, India.","DOI":"10.1109\/ViTECoN.2019.8899682"},{"key":"ref_11","first-page":"176","article-title":"DDoS attack detection and defense based on hybrid deep learning model in SDN","volume":"39","author":"Li","year":"2018","journal-title":"J. Commun."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1016\/j.jnca.2016.04.005","article-title":"SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks","volume":"68","author":"Cui","year":"2016","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Yang, X., Han, B., and Sun, Z. (2017, January 4\u20138). SDN-Based DDoS Attack Detection with Cross-Plane Collaboration and Lightweight Flow Monitoring. Proceedings of the IEEE Global Telecommunications Conference (Globecom), Singapore.","DOI":"10.1109\/GLOCOM.2017.8254079"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Cui, J., He, J.T., and Xu, Y. (2018, January 11\u201313). TDDAD: Time-based detection and defense scheme against DDoS attack on SDN controller. Proceedings of the 23rd Australasian Conference on Information Security and Privacy (ACISP), Wollongong, Australia.","DOI":"10.1007\/978-3-319-93638-3_37"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"102604","DOI":"10.1016\/j.cose.2022.102604","article-title":"A hybrid method of entropy and SSAE-SVM based DDoS detection and mitigation mechanism in SDN","volume":"115","author":"Zhang","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Shin, S., Yegneswaran, V., and Porras, P. (2013, January 4\u20138). AVANT-GUARD: Scalable and vigilant switch flow management in software-defined networks. Proceedings of the2013 ACM SIGSAC Conference on Computer and Communication Security, Berlin, Germany.","DOI":"10.1145\/2508859.2516684"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Wang, H., Lei, X., and Gu, G. (2015, January 22\u201325). FloodGuard: A DoS Attack Prevention Extension in Software-Defined Networks. Proceedings of the45th Annual IEEE\/IFIP International Conference on Dependable Systems & Networks, Rio de Janeiro, Brazil.","DOI":"10.1109\/DSN.2015.27"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1419","DOI":"10.1109\/TNET.2020.2983976","article-title":"Detection and Mitigation of DoS Attacks in Software Defined Networks","volume":"28","author":"Gao","year":"2020","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Macedo, R., Castro, R., and Santos, A. (2016, January 4\u20138). Self-Organized SDN Controller Cluster Conformations Against DDoS Attacks Effects. Proceedings of the 2016 IEEE Global Communications Conference (GLOBECOM), Washington, DC, USA.","DOI":"10.1109\/GLOCOM.2016.7842259"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"34699","DOI":"10.1109\/ACCESS.2019.2895092","article-title":"SGS: Safe-Guard Scheme for Protecting Control Plane Against DDoS Attacks in Software-Defined Networking","volume":"7","author":"Wang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"e3543","DOI":"10.1002\/dac.3543","article-title":"FMD: A DoS mitigation scheme based on flow migration in software-defined networking","volume":"31","author":"Wu","year":"2018","journal-title":"Int. J. Commun. Syst."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1608689","DOI":"10.1155\/2022\/1608689","article-title":"BSD-Guard: A Collaborative Blockchain-Based Approach for Detection and Mitigation of SDN-Targeted DDoS Attacks","volume":"2022","author":"Jiang","year":"2022","journal-title":"Secur. Commun. Netw."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"109361","DOI":"10.1016\/j.comnet.2022.109361","article-title":"DOCUS-DDoS detection in SDN using modified CUSUM with flash traffic discrimination and mitigation","volume":"217","author":"Shalini","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"10032","DOI":"10.1109\/ACCESS.2023.3240467","article-title":"An Improved Genetic Algorithm for Constrained Optimization Problems","volume":"11","author":"Wang","year":"2023","journal-title":"IEEE Access"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1016\/j.future.2021.11.009","article-title":"Software-defined DDoS detection with information entropy analysis and optimized deep learning","volume":"129","author":"Liu","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"103160","DOI":"10.1016\/j.jnca.2021.103160","article-title":"A novel hybrid model for intrusion detection systems in SDNs based on CNN and a new regularization technique","volume":"191","author":"Elsayed","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1186\/s40537-021-00544-5","article-title":"IDS-attention: An efficient algorithm for intrusion detection systems using attention mechanism","volume":"8","author":"Laghrissi","year":"2021","journal-title":"J. Big Data"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Erel, M., Teoman, E., and Ozcevik, Y. (2015, January 18\u201321). Scalability analysis and flow admission control in mininet-based SDN environment. Proceedings of the2015 IEEE Conference on Network Function Virtualization and Software-Defined Networks (NFV-SDN), San Franciso, CA, USA.","DOI":"10.1109\/NFV-SDN.2015.7387396"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"1","DOI":"10.53829\/ntr201408fa4","article-title":"Ryu SDN framework-open-source SDN platform software","volume":"12","author":"Kubo","year":"2014","journal-title":"NTT Tech. Rev."},{"key":"ref_30","unstructured":"Jawaharan, R., Mohan, P., and Das, T. (August, January 30). Empirical Evaluation of SDN Controllers Using Mininet\/Wireshark and Comparison with Cbench. Proceedings of the 27th International Conference on Computer Communication and Network (ICCCN), Hangzhou, China."},{"key":"ref_31","first-page":"1482","article-title":"Switch Dynamic Migration Strategy Based on Efficiency Optimization in SDN","volume":"47","author":"Yao","year":"2019","journal-title":"Acta Electron. Sinica"},{"key":"ref_32","first-page":"2316","article-title":"Controller Load Balancing Mechanism Based on Distributed Policy in SDN","volume":"46","author":"Hu","year":"2018","journal-title":"Acta Electron. Sinica"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/25\/8\/1210\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T20:33:32Z","timestamp":1760128412000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/25\/8\/1210"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,14]]},"references-count":32,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2023,8]]}},"alternative-id":["e25081210"],"URL":"https:\/\/doi.org\/10.3390\/e25081210","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,8,14]]}}}