{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,23]],"date-time":"2026-08-23T16:39:12Z","timestamp":1787503152293,"version":"build-2736575974"},"reference-count":38,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2022,8,12]],"date-time":"2022-08-12T00:00:00Z","timestamp":1660262400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Software-defined networking (SDN) is an innovative network paradigm, offering substantial control of network operation through a network\u2019s architecture. SDN is an ideal platform for implementing projects involving distributed applications, security solutions, and decentralized network administration in a multitenant data center environment due to its programmability. As its usage rapidly expands, network security threats are becoming more frequent, leading SDN security to be of significant concern. Machine-learning (ML) techniques for intrusion detection of DDoS attacks in SDN networks utilize standard datasets and fail to cover all classification aspects, resulting in under-coverage of attack diversity. This paper proposes a hybrid technique to recognize denial-of-service (DDoS) attacks that combine deep learning and feedforward neural networks as autoencoders. Two datasets were analyzed for the training and testing model, first statically and then iteratively. The auto-encoding model is constructed by stacking the input layer and hidden layer of self-encoding models\u2019 layer by layer, with each self-encoding model using a hidden layer. To evaluate our model, we use a three-part data split (train, test, and validate) rather than the common two-part split (train and test). The resulting proposed model achieved a higher accuracy for the static dataset, where for ISCX-IDS-2012 dataset, accuracy reached a high of 99.35% in training, 99.3% in validation and 99.99% in precision, recall, and F1-score. for the UNSW2018 dataset, the accuracy reached a high of 99.95% in training, 0.99.94% in validation, and 99.99% in precision, recall, and F1-score. In addition, the model achieved great results with a dynamic dataset (using an emulator), reaching a high of 97.68% in accuracy.<\/jats:p>","DOI":"10.3390\/fi14080240","type":"journal-article","created":{"date-parts":[[2022,8,15]],"date-time":"2022-08-15T01:47:21Z","timestamp":1660528041000},"page":"240","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":39,"title":["Improved DDoS Detection Utilizing Deep Neural Networks and Feedforward Neural Networks as Autoencoder"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9866-2883","authenticated-orcid":false,"given":"Ahmed Latif","family":"Yaser","sequence":"first","affiliation":[{"name":"Computer Science Department, Faculty of Computers and Information, Menoufia University, Shebin Elkom 32511, Egypt"},{"name":"Department of Information Systems, College of Administration and Economics, University of Baghdad, Baghdad P.O. Box 10071, Iraq"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hamdy M.","family":"Mousa","sequence":"additional","affiliation":[{"name":"Computer Science Department, Faculty of Computers and Information, Menoufia University, Shebin Elkom 32511, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3742-7548","authenticated-orcid":false,"given":"Mahmoud","family":"Hussein","sequence":"additional","affiliation":[{"name":"Computer Science Department, Faculty of Computers and Information, Menoufia University, Shebin Elkom 32511, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,8,12]]},"reference":[{"key":"ref_1","first-page":"56","article-title":"A Security Architecture for Software Defined Networks (SDN)","volume":"13","author":"Adekunle","year":"2015","journal-title":"Int. J. Comput. Sci. Inf. Secur."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/JPROC.2014.2371999","article-title":"Software-defined networking: A comprehensive survey","volume":"103","author":"Kreutz","year":"2014","journal-title":"Proc. IEEE"},{"key":"ref_3","unstructured":"Makori, D.O. (2018). Machine Learning Based Ddos Attack Detection for Software-Defined Networks: Yaz\u0131l\u0131m Tan\u0131ml\u0131 A\u011flar I\u00e7in Makine \u00d6\u011frenme Esasl\u0131 Ddos Attack Alg\u0131lama. [M.Sc. Thesis, Akarya \u00dcniversitesi]."},{"key":"ref_4","unstructured":"Weekes, J. (2019). Towards Smarter SDN Switches: Revisiting the Balance of Intelligence in SDN Networks, Lancaster University (United Kingdom)."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"469","DOI":"10.1016\/j.compeleceng.2018.01.015","article-title":"Cyber-security in smart grid: Survey and challenges","volume":"67","author":"Kaabouch","year":"2018","journal-title":"Comput. Electr. Eng."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Potluri, S., and Diedrich, C. (2016, January 6\u20139). Accelerated deep neural networks for enhanced intrusion detection system. Proceedings of the 2016 IEEE 21st International Conference on Emerging Technologies and Factory Automation (ETFA), Berlin, Germany.","DOI":"10.1109\/ETFA.2016.7733515"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Nam, T.M., Phong, P.H., Khoa, T.D., Huong, T.T., Nam, P.N., Thanh, N.H., Thang, L.X., Tuan, P.A., and Loi, V.D. (2018, January 10\u201312). Self-organizing map-based approaches in DDoS flooding detection using SDN. Proceedings of the 2018 International Conference on Information Networking (ICOIN), Chiang Mai, Thailand.","DOI":"10.1109\/ICOIN.2018.8343119"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"e2050","DOI":"10.1002\/nem.2050","article-title":"A deep learning method to detect network intrusion through flow-based features","volume":"29","author":"Acarman","year":"2019","journal-title":"Int. J. Netw. Manag."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Elsayed, M.S., Le-Khac, N.-A., Soumyabrata, D., and Jurcut, A.D. (2019, January 19\u201320). Machine-Learning Techniques for detecting Attacks in SDN. Proceedings of the 2019 IEEE 7th International Conference on Computer Science and Network Technology (ICCSNT), Dalian, China.","DOI":"10.1109\/ICCSNT47585.2019.8962519"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"716","DOI":"10.37394\/23203.2020.15.72","article-title":"An enhanced deep autoencoder-based approach for DDoS attack detection","volume":"15","author":"Sindian","year":"2020","journal-title":"Wseas Trans. Syst. Control"},{"key":"ref_11","unstructured":"(2022, June 30). DDoS Evaluation Dataset (CIC-DDoS2019). Available online: https:\/\/www.unb.ca\/cic\/datasets\/ddos-2019.html."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1007\/s42797-021-00025-1","article-title":"Design of a dynamic and self-adapting system, supported with artificial intelligence, machine learning and real-time intelligence for predictive cyber risk analytics in extreme environments\u2013cyber risk in the colonisation of Mars","volume":"2","author":"Radanliev","year":"2020","journal-title":"Saf. Extrem. Environ."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Mhamdi, L., McLernon, D., El-Moussa, F., Zaidi, S.A.R., Ghogho, M., and Tang, T. (2020, January 27\u201330). A deep learning approach combining autoencoder with one-class SVM for DDoS attack detection in SDNs. Proceedings of the 2020 IEEE Eighth International Conference on Communications and Networking (ComNet), Hammamet, Tunisia.","DOI":"10.1109\/ComNet47917.2020.9306073"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1852","DOI":"10.3906\/elk-1908-87","article-title":"Distributed denial of service attack detection in cloud computing using hybridextreme learning machine","volume":"29","author":"Kushwah","year":"2021","journal-title":"Turk. J. Electr. Eng. Comput. Sci."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Gadze, J.D., Bamfo-Asante, A.A., Agyemang, J.O., Nunoo-Mensah, H., and Opare, K.A.-B. (2021). An investigation into the application of deep learning in the detection and mitigation of DDOS attack on SDN controllers. Technologies, 9.","DOI":"10.3390\/technologies9010014"},{"key":"ref_16","unstructured":"Singh, A., and Jang-Jaccard, J. (2022). Autoencoder-based Unsupervised Intrusion Detection using Multi-Scale Convolutional Recurrent Networks. arXiv."},{"key":"ref_17","unstructured":"(2022, May 26). The UNSW-NB15 Dataset. Available online: https:\/\/research.unsw.edu.au\/projects\/unsw-nb15-dataset."},{"key":"ref_18","unstructured":"(2022, June 12). NSL-KDD Dataset. Available online: https:\/\/www.unb.ca\/cic\/datasets\/nsl.html."},{"key":"ref_19","first-page":"653","article-title":"Detection of IoT based DDoS Attacks by Network Traffic Analysis using Feedforward Neural Networks","volume":"16","author":"Ivanova","year":"2022","journal-title":"Int. J. Circuits Syst. Sign. Proc."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"9965","DOI":"10.1007\/s13369-021-06484-9","article-title":"VMFCVD: An Optimized Framework to Combat Volumetric DDoS Attacks using Machine Learning","volume":"47","author":"Prasad","year":"2022","journal-title":"Arab. J. Sci. Eng."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"51691","DOI":"10.1109\/ACCESS.2019.2908998","article-title":"Comprehensive review of artificial intelligence and statistical approaches in distributed denial of service attack and defense methods","volume":"7","author":"Khalaf","year":"2019","journal-title":"IEEE Access"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1145\/997150.997156","article-title":"A taxonomy of DDoS attack and DDoS defense mechanisms","volume":"34","author":"Mirkovic","year":"2004","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1186\/s42400-019-0038-7","article-title":"Survey of intrusion detection systems: Techniques, datasets and challenges","volume":"2","author":"Khraisat","year":"2019","journal-title":"Cybersecurity"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Sahri, N., and Okamura, K. (2016, January 15\u201317). Protecting DNS services from IP spoofing: SDN collaborative authentication approach. Proceedings of the 11th International Conference on Future Internet Technologies, Nanjing, China.","DOI":"10.1145\/2935663.2935666"},{"key":"ref_25","first-page":"73781","article-title":"Survey of machine learning algorithms for disease diagnostic","volume":"9","author":"Fatima","year":"2017","journal-title":"J. Intell. Learn. Syst. Appl."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Gupta, C., Johri, I., Srinivasan, K., Hu, Y.-C., Qaisar, S.M., and Huang, K.-Y. (2022). A Systematic Review on Machine Learning and Deep Learning Models for Electronic Information Security in Mobile Networks. Sensors, 22.","DOI":"10.3390\/s22052017"},{"key":"ref_27","unstructured":"(2022, May 15). Intrusion Detection Evaluation Dataset (ISCXIDS2012). Available online: https:\/\/www.unb.ca\/cic\/datasets\/ids.html."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Tang, T.A., McLernon, D., Mhamdi, L., Zaidi, S.A.R., and Ghogho, M. (2019). Intrusion detection in sdn-based networks: Deep recurrent neural network approach. Deep Learning Applications for Cyber Security, Springer.","DOI":"10.1007\/978-3-030-13057-2_8"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2750","DOI":"10.1016\/j.procs.2020.04.299","article-title":"Data traffic classification in software defined networks (SDN) using supervised-learning","volume":"171","author":"Raikar","year":"2020","journal-title":"Proc. Comput. Sci."},{"key":"ref_30","unstructured":"Sugomori, Y., Kaluza, B., Soares, F.M., and Souza, A.M. (2017). Deep Learning: Practical Neural Networks with Java, Packt Publishing Ltd."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Meng, Q., Catchpoole, D., Skillicom, D., and Kennedy, P.J. (2017, January 14\u201319). Relational autoencoder for feature extraction. Proceedings of the 2017 International Joint Conference on Neural Networks (IJCNN), Anchorage, AK, USA.","DOI":"10.1109\/IJCNN.2017.7965877"},{"key":"ref_32","unstructured":"Charu, C.A. (2018). Neural Networks and Deep Learning: A Textbook, An Giang University."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Xu, Z., Wang, Y., Long, M., Wang, J., and KLiss, M. (2018, January 13\u201319). PredCNN: Predictive Learning with Cascade Convolutions. Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence, Stockholm, Sweden.","DOI":"10.24963\/ijcai.2018\/408"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Chu, W., and Cai, D. (2017, January 19\u201325). Stacked Similarity-Aware Autoencoders. Proceedings of the Twenty-Sixth International Joint Conference on Artificial Intelligence, Melbourne, Australia.","DOI":"10.24963\/ijcai.2017\/216"},{"key":"ref_35","first-page":"5105709","article-title":"A stacked autoencoder-based deep neural network for achieving gearbox fault diagnosis","volume":"2018","author":"Liu","year":"2018","journal-title":"Math. Probl. Eng."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"103160","DOI":"10.1016\/j.jnca.2021.103160","article-title":"A novel hybrid model for intrusion detection systems in SDNs based on CNN and a new regularization technique","volume":"191","author":"ElSayed","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"155859","DOI":"10.1109\/ACCESS.2020.3019330","article-title":"A flexible SDN-based architecture for identifying and mitigating low-rate DDoS attacks using machine learning","volume":"8","author":"Valdovinos","year":"2020","journal-title":"IEEE Access"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Soltanaghaei, M. (2020). A New DDoS Detection Method in Software Defined Network, Research Square.","DOI":"10.35543\/osf.io\/jnhsm"}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/8\/240\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:08:10Z","timestamp":1760141290000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/8\/240"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,12]]},"references-count":38,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2022,8]]}},"alternative-id":["fi14080240"],"URL":"https:\/\/doi.org\/10.3390\/fi14080240","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,8,12]]}}}