{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T15:37:56Z","timestamp":1774021076535,"version":"3.50.1"},"reference-count":42,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2025,3,19]],"date-time":"2025-03-19T00:00:00Z","timestamp":1742342400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"University Grants Commission (UGC), Nepal","award":["CRG-078\/79-Engg-01"],"award-info":[{"award-number":["CRG-078\/79-Engg-01"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The increasing complexity and scale of modern software-defined networking demands advanced solutions to address security challenges, particularly distributed denial-of-service (DDoS) attacks in multi-controller environments. Traditional single-controller implementations are struggling to effectively counter sophisticated cyber threats, necessitating a faster and scalable solution. This study introduces a novel approach for attack detection and mitigation with optimized multi-controller software-defined networking (SDN) using machine learning (ML). The study focuses on the design, implementation, and assessment of the optimal placement of multi-controllers using K-means++ and OPTICS in real topologies and an intrusion detection system (IDS) using the XGBoost classification algorithm to detect and mitigate attacks efficiently with accuracy, precision, and recall of 98.5%, 97.0%, and 97.0%, respectively. Additionally, the IDS decouples from the controllers, preserves controller resources, and allows for efficient near-real-time attack detection and mitigation. The proposed solution outperforms well by autonomously identifying anomalous behaviors in networks through successfully combining the controller placement problem (CPP) and DDoS security.<\/jats:p>","DOI":"10.3390\/jcp5010010","type":"journal-article","created":{"date-parts":[[2025,3,19]],"date-time":"2025-03-19T06:10:53Z","timestamp":1742364653000},"page":"10","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Machine Learning-Based Attack Detection and Mitigation with Multi-Controller Placement Optimization over SDN Environment"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9418-0092","authenticated-orcid":false,"given":"Binod","family":"Sapkota","sequence":"first","affiliation":[{"name":"Department of Electronics and Computer Engineering, Pulchowk Campus, Institute of Engineering, Tribhuvan University, Kirtipur 44613, Nepal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Arjun","family":"Ray","sequence":"additional","affiliation":[{"name":"Department of Electronics and Computer Engineering, Pulchowk Campus, Institute of Engineering, Tribhuvan University, Kirtipur 44613, Nepal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-9730-2778","authenticated-orcid":false,"given":"Manish Kumar","family":"Yadav","sequence":"additional","affiliation":[{"name":"Department of Electronics and Computer Engineering, Pulchowk Campus, Institute of Engineering, Tribhuvan University, Kirtipur 44613, Nepal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6449-399X","authenticated-orcid":false,"given":"Babu R.","family":"Dawadi","sequence":"additional","affiliation":[{"name":"Department of Electronics and Computer Engineering, Pulchowk Campus, Institute of Engineering, Tribhuvan University, Kirtipur 44613, Nepal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shashidhar R.","family":"Joshi","sequence":"additional","affiliation":[{"name":"Department of Electronics and Computer Engineering, Pulchowk Campus, Institute of Engineering, Tribhuvan University, Kirtipur 44613, Nepal"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,3,19]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Wang, T., Feng, Y., and Sakurai, K. (2021, January 4\u20136). Improving the two-stage detection of cyberattacks in SDN environment using dynamic thresholding. Proceedings of the 2021 15th International Conference on Ubiquitous Information Management and Communication (IMCOM), Seoul, Republic of Korea.","DOI":"10.1109\/IMCOM51814.2021.9377395"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Rasol, K.A., and Domingo-Pascual, J. (2020). Multi-level Hierarchical Controller Placement in Software Defined Networking. Selected Papers from the 12th International Networking Conference: INC 2020, Springer.","DOI":"10.1007\/978-3-030-64758-2_10"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"106883","DOI":"10.1016\/j.comnet.2019.106883","article-title":"Controller placement in software defined networks: A comprehensive survey","volume":"163","author":"Killi","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Gadze, J.D., Bamfo-Asante, A.A., Agyemang, J.O., Nunoo-Mensah, H., and Opare, K.A.B. (2021). An investigation into the application of deep learning in the detection and mitigation of DDOS attack on SDN controllers. Technologies, 9.","DOI":"10.3390\/technologies9010014"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"102856","DOI":"10.1016\/j.jnca.2020.102856","article-title":"A comprehensive survey of load balancing techniques in software-defined network","volume":"174","author":"Hamdan","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1007\/s40860-022-00171-8","article-title":"A comprehensive survey on SDN security: Threats, mitigations, and future directions","volume":"9","author":"Maleh","year":"2023","journal-title":"J. Reliab. Intell. Environ."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1007\/s11036-014-0533-8","article-title":"Software-defined and virtualized future mobile and wireless networks: A survey","volume":"20","author":"Yang","year":"2015","journal-title":"Mob. Netw. Appl."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"AlMomin, H., and Ibrahim, A.A. (2020, January 26\u201327). Detection of distributed denial of service attacks through a combination of machine learning algorithms over software defined network environment. Proceedings of the 2020 International Congress on Human-Computer Interaction, Optimization and Robotic Applications (HORA), Ankara, Turkey.","DOI":"10.1109\/HORA49412.2020.9152873"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"80813","DOI":"10.1109\/ACCESS.2019.2922196","article-title":"A survey on distributed denial of service (DDoS) attacks in SDN and cloud computing environments","volume":"7","author":"Dong","year":"2019","journal-title":"IEEE Access"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Tahirou, A.K., Konate, K., and Soidridine, M.M. (2023, January 3\u20135). Detection and mitigation of DDoS attacks in SDN using Machine Learning (ML). Proceedings of the 2023 International Conference on Digital Age & Technological Advances for Sustainable Development (ICDATA), Casablanca, Morocco.","DOI":"10.1109\/ICDATA58816.2023.00019"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Melkov, D., and Paulikas, S. (2021, January 22). Security benefits and drawbacks of software-defined networking. Proceedings of the 2021 IEEE Open Conference of Electrical, Electronic and Information Sciences (eStream), Vilnius, Lithuania.","DOI":"10.1109\/eStream53087.2021.9431466"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"143985","DOI":"10.1109\/ACCESS.2020.3013998","article-title":"Detection techniques of distributed denial of service attacks on software-defined networking controller\u2014A review","volume":"8","author":"Aladaileh","year":"2020","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"100279","DOI":"10.1016\/j.cosrev.2020.100279","article-title":"Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions","volume":"37","author":"Singh","year":"2020","journal-title":"Comput. Sci. Rev."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"104216","DOI":"10.1016\/j.engappai.2021.104216","article-title":"Supervised feature selection techniques in network intrusion detection: A critical review","volume":"101","author":"Galatro","year":"2021","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"407","DOI":"10.59670\/ml.v20iS13.6472","article-title":"Detection and Mitigation of DDOS Attack in SDN Environment Using Hybrid CNN-LSTM","volume":"20","author":"Rajan","year":"2023","journal-title":"Migr. Lett."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Bakker, J.N., Ng, B., and Seah, W.K. (August, January 30). Can machine learning techniques be effectively used in real networks against DDoS attacks?. Proceedings of the 2018 27th International Conference on Computer Communication and Networks (ICCCN), Hangzhou, China.","DOI":"10.1109\/ICCCN.2018.8487445"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"184","DOI":"10.1109\/SERVICES.2019.00051","article-title":"DDoS attacks detection and mitigation in SDN using machine learning","volume":"Volume 2642","author":"Rahman","year":"2019","journal-title":"Proceedings of the 2019 IEEE World Congress on Services (SERVICES)"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Chen, J., Yang, Y.t., Hu, K.k., Zheng, H.b., and Wang, Z. (2019, January 22\u201324). DAD-MCNN: DDoS attack detection via multi-channel CNN. Proceedings of the 2019 11th International Conference on Machine Learning and Computing, Zhuhai, China.","DOI":"10.1145\/3318299.3318329"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Morfino, V., and Rampone, S. (2020). Towards near-real-time intrusion detection for IoT devices using supervised learning and apache spark. Electronics, 9.","DOI":"10.3390\/electronics9030444"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Meti, N., Narayan, D., and Baligar, V. (2017, January 13\u201316). Detection of distributed denial of service attacks using machine learning algorithms in software defined networks. Proceedings of the 2017 International Conference on Advances in Computing, Communications and Informatics (ICACCI), Udupi, India.","DOI":"10.1109\/ICACCI.2017.8126031"},{"key":"ref_21","first-page":"233","article-title":"Performance evaluation of SDN DDoS attack detection and mitigation based random forest and K-nearest neighbors machine learning algorithms","volume":"36","author":"Mohsin","year":"2022","journal-title":"Rev. d\u2019Intell. Artif."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"101","DOI":"10.1016\/j.jnca.2017.11.015","article-title":"A survey on software defined networking with multiple controllers","volume":"103","author":"Zhang","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1016\/j.comcom.2018.04.008","article-title":"Multi-objective optimization controller placement problem in internet-oriented software defined network","volume":"123","author":"Zhang","year":"2018","journal-title":"Comput. Commun."},{"key":"ref_24","first-page":"1","article-title":"A Fault Tolerant Multi-Controller Framework for SDN DDoS Attacks Detection","volume":"5","author":"Valizadeh","year":"2022","journal-title":"Int. J. Web Res."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"9965945","DOI":"10.1155\/2023\/9965945","article-title":"DDoS attack detection and classification using hybrid model for multicontroller SDN","volume":"2023","author":"Gebremeskel","year":"2023","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_26","first-page":"1","article-title":"Early detection of DDoS attacks in a multi-controller based SDN","volume":"13422","author":"Pandikumar","year":"2017","journal-title":"Int. J. Eng. Sci."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Gurusamy, U., K, H., and MSK, M. (2019). Detection and mitigation of UDP flooding attack in a multicontroller software defined network using secure flow management model. Concurr. Comput. Pract. Exp., 31.","DOI":"10.1002\/cpe.5326"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Sapkota, B., Dawadi, B.R., and Joshi, S.R. (2023). Controller placement problem during SDN deployment in the ISP\/Telco networks: A survey. Eng. Rep., 6.","DOI":"10.1002\/eng2.12801"},{"key":"ref_29","unstructured":"Arthur, D., and Vassilvitskii, S. (2007, January 7\u20139). k-means++: The advantages of careful seeding. Proceedings of the SODA, New Orleans, LA, USA."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1145\/304181.304187","article-title":"OPTICS: Ordering points to identify the clustering structure","volume":"28","author":"Ankerst","year":"1999","journal-title":"ACM Sigmod Rec."},{"key":"ref_31","first-page":"226","article-title":"A density-based algorithm for discovering clusters in large spatial databases with noise","volume":"Volume 96","author":"Ester","year":"1996","journal-title":"Proceedings of the Second International Conference on Knowledge Discovery and Data Mining"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Campello, R.J., Kr\u00f6ger, P., Sander, J., and Zimek, A. (2020). Density-based clustering. Wiley Interdiscip. Rev. Data Min. Knowl. Discov., 10.","DOI":"10.1002\/widm.1343"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1002\/widm.30","article-title":"Density-based clustering","volume":"1","author":"Kriegel","year":"2011","journal-title":"Wiley Interdiscip. Rev. Data Min. Knowl. Discov."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"1765","DOI":"10.1109\/JSAC.2011.111002","article-title":"The internet topology zoo","volume":"29","author":"Knight","year":"2011","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"103108","DOI":"10.1016\/j.jnca.2021.103108","article-title":"Automated DDOS attack detection in software defined networking","volume":"187","author":"Ahuja","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"8060333","DOI":"10.1155\/2022\/8060333","article-title":"Labelled dataset on distributed denial-of-service (DDoS) attacks based on internet control message protocol version 6 (ICMPv6)","volume":"2022","author":"Manickam","year":"2022","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Dawadi, B.R., Adhikari, B., and Srivastava, D.K. (2023). Deep learning technique-enabled web application firewall for the detection of web attacks. Sensors, 23.","DOI":"10.3390\/s23042073"},{"key":"ref_38","first-page":"637","article-title":"Building a personalized fitness recommendation application based on sequential information","volume":"12","author":"Abdulaziz","year":"2021","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Clinton, U.B., Hoque, N., and Robindro Singh, K. (2024). Classification of DDoS attack traffic on SDN network environment using deep learning. Cybersecurity, 7.","DOI":"10.1186\/s42400-024-00219-7"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"106733","DOI":"10.1109\/ACCESS.2023.3319214","article-title":"Optimized artificial intelligence model for DDoS detection in SDN environment","volume":"11","year":"2023","journal-title":"IEEE Access"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"166675","DOI":"10.1109\/ACCESS.2024.3486034","article-title":"Detecting DDoS Threats using Supervised Machine Learning for Traffic Classification in Software Defined Networking","volume":"12","author":"Hirsi","year":"2024","journal-title":"IEEE Access"},{"key":"ref_42","first-page":"93","article-title":"DDos detection in Software-Defined Network (Sdn) using machine learning","volume":"12","author":"Alubaidan","year":"2023","journal-title":"Int. J. Cybern. Inform."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/1\/10\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T16:56:19Z","timestamp":1760028979000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/1\/10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,19]]},"references-count":42,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,3]]}},"alternative-id":["jcp5010010"],"URL":"https:\/\/doi.org\/10.3390\/jcp5010010","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,19]]}}}