{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T20:18:58Z","timestamp":1784146738198,"version":"3.55.0"},"reference-count":37,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Network"],"abstract":"<jats:p>In the contemporary landscape, Distributed Denial of Service (DDoS) attacks have emerged as an exceedingly pernicious threat, particularly in the context of network management centered around technologies like Software-Defined Networking (SDN). With the increasing intricacy and sophistication of DDoS attacks, the need for effective countermeasures has led to the adoption of Machine Learning (ML) techniques. Nevertheless, despite substantial advancements in this field, challenges persist, adversely affecting the accuracy of ML-based DDoS-detection systems. This article introduces a model designed to detect DDoS attacks. This model leverages a combination of Multilayer Perceptron (MLP) and Convolutional Neural Network (CNN) to enhance the performance of ML-based DDoS-detection systems within SDN environments. We propose utilizing the SHapley Additive exPlanations (SHAP) feature-selection technique and employing a Bayesian optimizer for hyperparameter tuning to optimize our model. To further solidify the relevance of our approach within SDN environments, we evaluate our model by using an open-source SDN dataset known as InSDN. Furthermore, we apply our model to the CICDDoS-2019 dataset. Our experimental results highlight a remarkable overall accuracy of 99.95% with CICDDoS-2019 and an impressive 99.98% accuracy with the InSDN dataset. These outcomes underscore the effectiveness of our proposed DDoS-detection model within SDN environments compared to existing techniques.<\/jats:p>","DOI":"10.3390\/network3040024","type":"journal-article","created":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T08:36:59Z","timestamp":1701419819000},"page":"538-562","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":40,"title":["Optimized MLP-CNN Model to Enhance Detecting DDoS Attacks in SDN Environment"],"prefix":"10.3390","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9406-5136","authenticated-orcid":false,"given":"Mohamed Ali","family":"Setitra","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering (Cyberspace Security), University of Electronic Science and Technology of China (UESTC), No. 2006, Xiyuan Ave., West Hi-Tech. Zone, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4784-6578","authenticated-orcid":false,"given":"Mingyu","family":"Fan","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (Cyberspace Security), University of Electronic Science and Technology of China (UESTC), No. 2006, Xiyuan Ave., West Hi-Tech. Zone, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3480-1936","authenticated-orcid":false,"given":"Bless Lord Y.","family":"Agbley","sequence":"additional","affiliation":[{"name":"School of Information and Communication Engineering, University of Electronic Science and Technology of China (UESTC), No. 2006, Xiyuan Ave., West Hi-Tech. Zone, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4437-7876","authenticated-orcid":false,"given":"Zine El Abidine","family":"Bensalem","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (Cyberspace Security), University of Electronic Science and Technology of China (UESTC), No. 2006, Xiyuan Ave., West Hi-Tech. Zone, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,12,1]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Ali, T.E., Chong, Y.W., and Manickam, S. (2023). Machine Learning Techniques to Detect a DDoS Attack in SDN: A Systematic Review. Appl. Sci., 13.","DOI":"10.3390\/app13053183"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Karnani, S., Agrawal, N., and Kumar, R. (2023). A comprehensive survey on low-rate and high-rate DDoS defense approaches in SDN: Taxonomy, research challenges, and opportunities. Multimed. Tools Appl., 1\u201354.","DOI":"10.1007\/s11042-023-16781-0"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Setitra, M.A., Benkhaddra, I., Bensalem, Z.E.A., and Fan, M. (2022, January 16\u201318). Feature Modeling and Dimensionality Reduction to Improve ML-Based DDoS Detection Systems in SDN Environment. Proceedings of the 2022 19th International Computer Conference on Wavelet Active Media Technology and Information Processing (ICCWAMTIP), Chengdu, China.","DOI":"10.1109\/ICCWAMTIP56608.2022.10016507"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"e4827","DOI":"10.1002\/ett.4827","article-title":"An efficient approach to detect distributed denial of service attacks for software defined internet of things combining autoencoder and extreme gradient boosting with feature selection and hyperparameter tuning optimization","volume":"34","author":"Setitra","year":"2023","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"e4729","DOI":"10.1002\/ett.4729","article-title":"Prevention of DDoS attacks using an optimized deep learning approach in blockchain technology","volume":"34","author":"Benkhaddra","year":"2023","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"158","DOI":"10.3390\/network3010008","article-title":"A Federated Learning-Based Approach for Improving Intrusion Detection in Industrial Internet of Things Networks","volume":"3","author":"Rashid","year":"2023","journal-title":"Network"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"628","DOI":"10.3390\/network2040036","article-title":"Detection of Malicious Network Flows with Low Preprocessing Overhead","volume":"2","author":"Fox","year":"2022","journal-title":"Network"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Shieh, C.S., Nguyen, T.T., and Horng, M.F. (2023). Detection of Unknown DDoS Attack Using Convolutional Neural Networks Featuring Geometrical Metric. Mathematics, 11.","DOI":"10.3390\/math11092145"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"353","DOI":"10.1016\/j.inffus.2022.09.026","article-title":"Fusion of statistical importance for feature selection in Deep Neural Network-based Intrusion Detection System","volume":"90","author":"Thakkar","year":"2023","journal-title":"Inf. Fusion"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Saha, S., Priyoti, A.T., Sharma, A., and Haque, A. (2022). Towards an Optimized Ensemble Feature Selection for DDoS Detection Using Both Supervised and Unsupervised Method. Sensors, 22.","DOI":"10.3390\/s22239144"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"117500","DOI":"10.1016\/j.eswa.2022.117500","article-title":"Recognition of DDoS Attacks on SD-VANET Based on Combination of Hyperparameter Optimization and Feature Selection","volume":"203","author":"Polat","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"e7299","DOI":"10.1002\/cpe.7299","article-title":"Performance evaluation of machine learning models for distributed denial of service attack detection using improved feature selection and hyper-parameter optimization techniques","volume":"34","author":"Habib","year":"2022","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"104571","DOI":"10.1016\/j.micpro.2022.104571","article-title":"On Improving the Performance of DDoS attack detection system","volume":"93","author":"Batchu","year":"2022","journal-title":"Microprocess. Microsyst."},{"key":"ref_14","first-page":"101176","article-title":"Detecting flooding DDoS attacks in software defined networks using supervised learning techniques","volume":"35","author":"Wang","year":"2022","journal-title":"Eng. Sci. Technol. Int. J."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"109269","DOI":"10.1016\/j.comnet.2022.109269","article-title":"An integrated approach explaining the detection of distributed denial of service attacks","volume":"216","author":"Batchu","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"e6919","DOI":"10.1002\/cpe.6919","article-title":"An ensemble method for feature selection and an integrated approach for mitigation of distributed denial of service attacks","volume":"34","author":"Chanu","year":"2022","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"393","DOI":"10.1007\/s12652-021-02907-5","article-title":"A feature reduction based reflected and exploited DDoS attacks detection system","volume":"1-13","author":"Kshirsagar","year":"2022","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1862","DOI":"10.1109\/TCCN.2022.3186331","article-title":"A Flow-Based Anomaly Detection Approach With Feature Selection Method Against DDoS Attacks in SDNs","volume":"8","author":"Azer","year":"2022","journal-title":"IEEE Trans. Cogn. Commun. Netw."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"102748","DOI":"10.1016\/j.cose.2022.102748","article-title":"A new DDoS attacks intrusion detection model based on deep learning for cybersecurity","volume":"118","author":"Akgun","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1016\/j.future.2022.02.006","article-title":"A feature selection-based method for DDoS attack flow classification","volume":"132","author":"Zhou","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Saha, S., Priyoti, A.T., Sharma, A., and Haque, A. (2022, January 8\u201311). Towards an Optimal Feature Selection Method for AI-Based DDoS Detection System. Proceedings of the 2022 IEEE 19th Annual Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA.","DOI":"10.1109\/CCNC49033.2022.9700569"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Fenil, E., and Kumar, P.M. (2022, January 28\u201329). Towards a secure Software Defined Network with Adaptive Mitigation of DDoS attacks by Machine Learning Approaches. Proceedings of the 2022 IEEE International Conference on Advances in Computing, Communication and Applied Informatics (ACCAI), Chennai, India.","DOI":"10.1109\/ACCAI53970.2022.9752607"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Golchin, P., Kundel, R., Steuer, T., Hark, R., and Steinmetz, R. (2022, January 25\u201329). Improving DDoS Attack Detection Leveraging a Multi-aspect Ensemble Feature Selection. Proceedings of the NOMS 2022-2022 IEEE\/IFIP Network Operations and Management Symposium, Budapest, Hungary.","DOI":"10.1109\/NOMS54207.2022.9789763"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"108498","DOI":"10.1016\/j.comnet.2021.108498","article-title":"A generalized machine learning model for DDoS attacks detection using hybrid feature selection and hyperparameter tuning","volume":"200","author":"Batchu","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_25","first-page":"250","article-title":"Evaluating the impact of feature selection methods on the performance of the machine learning models in detecting DDoS attacks","volume":"23","author":"Bindra","year":"2020","journal-title":"Rom. J. Inf. Sci. Technol."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Polat, H., Polat, O., and Cetin, A. (2020). Detecting DDoS attacks in software-defined networks through feature selection methods and machine learning models. Sustainability, 12.","DOI":"10.3390\/su12031035"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"166011","DOI":"10.1109\/ACCESS.2019.2953565","article-title":"FWFS: Selecting robust features towards reliable and stable traffic classifier in SDN","volume":"7","author":"Zaki","year":"2019","journal-title":"IEEE Access"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1016\/j.inffus.2018.11.010","article-title":"Short-long term anomaly detection in wireless sensor networks based on machine learning and multi-parameterized edit distance","volume":"52","author":"Cauteruccio","year":"2019","journal-title":"Inf. Fusion"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2695","DOI":"10.1016\/j.procs.2020.09.292","article-title":"Walking cycle and walking phases extraction from videos using transfer learning","volume":"176","author":"Setitra","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Gonz\u00e1lez-N\u00f3voa, J.A., Busto, L., Campanioni, S., Fari\u00f1a, J., Rodr\u00edguez-Andina, J.J., Vila, D., and Veiga, C. (2023). Two-step approach for occupancy estimation in intensive care units based on Bayesian optimization techniques. Sensors, 23.","DOI":"10.3390\/s23031162"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"16591","DOI":"10.1007\/s11042-022-13820-0","article-title":"The effect of choosing optimizer algorithms to improve computer vision tasks: A comparative study","volume":"82","author":"Hassan","year":"2023","journal-title":"Multimed. Tools Appl."},{"key":"ref_32","unstructured":"Taud, H., and Mas, J.F. (2018). Geomatic Approaches for Modeling Land Change Scenarios, Springer."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.ceh.2020.11.002","article-title":"An anatomization on breast cancer detection and diagnosis employing multi-layer perceptron neural network (MLP) and Convolutional neural network (CNN)","volume":"4","author":"Desai","year":"2021","journal-title":"Clin. eHealth"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"6999","DOI":"10.1109\/TNNLS.2021.3084827","article-title":"A survey of convolutional neural networks: Analysis, applications, and prospects","volume":"33","author":"Li","year":"2021","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1549","DOI":"10.1007\/s11277-023-10344-0","article-title":"Design and Development of Consensus Activation Function Enabled Neural Network-Based Smart Healthcare Using BIoT","volume":"130","author":"Benkhaddra","year":"2023","journal-title":"Wirel. Pers. Commun."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"165263","DOI":"10.1109\/ACCESS.2020.3022633","article-title":"InSDN: A novel SDN intrusion dataset","volume":"8","author":"Elsayed","year":"2020","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Hakak, S., and Ghorbani, A.A. (2019, January 1\u20133). Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy. Proceedings of the 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India.","DOI":"10.1109\/CCST.2019.8888419"}],"container-title":["Network"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2673-8732\/3\/4\/24\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:36:15Z","timestamp":1760132175000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2673-8732\/3\/4\/24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,1]]},"references-count":37,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["network3040024"],"URL":"https:\/\/doi.org\/10.3390\/network3040024","relation":{},"ISSN":["2673-8732"],"issn-type":[{"value":"2673-8732","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,1]]}}}