{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T12:54:20Z","timestamp":1784120060029,"version":"3.55.0"},"reference-count":47,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2022,3,31]],"date-time":"2022-03-31T00:00:00Z","timestamp":1648684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The development of smart network infrastructure of the Internet of Things (IoT) faces the immense threat of sophisticated Distributed Denial-of-Services (DDoS) security attacks. The existing network security solutions of enterprise networks are significantly expensive and unscalable for IoT. The integration of recently developed Software Defined Networking (SDN) reduces a significant amount of computational overhead for IoT network devices and enables additional security measurements. At the prelude stage of SDN-enabled IoT network infrastructure, the sampling based security approach currently results in low accuracy and low DDoS attack detection. In this paper, we propose an Adaptive Machine Learning based SDN-enabled Distributed Denial-of-Services attacks Detection and Mitigation (AMLSDM) framework. The proposed AMLSDM framework develops an SDN-enabled security mechanism for IoT devices with the support of an adaptive machine learning classification model to achieve the successful detection and mitigation of DDoS attacks. The proposed framework utilizes machine learning algorithms in an adaptive multilayered feed-forwarding scheme to successfully detect the DDoS attacks by examining the static features of the inspected network traffic. In the proposed adaptive multilayered feed-forwarding framework, the first layer utilizes Support Vector Machine (SVM), Naive Bayes (NB), Random Forest (RF), k-Nearest Neighbor (kNN), and Logistic Regression (LR) classifiers to build a model for detecting DDoS attacks from the training and testing environment-specific datasets. The output of the first layer passes to an Ensemble Voting (EV) algorithm, which accumulates the performance of the first layer classifiers. In the third layer, the adaptive frameworks measures the real-time live network traffic to detect the DDoS attacks in the network traffic. The proposed framework utilizes a remote SDN controller to mitigate the detected DDoS attacks over Open Flow (OF) switches and reconfigures the network resources for legitimate network hosts. The experimental results show the better performance of the proposed framework as compared to existing state-of-the art solutions in terms of higher accuracy of DDoS detection and low false alarm rate.<\/jats:p>","DOI":"10.3390\/s22072697","type":"journal-article","created":{"date-parts":[[2022,3,31]],"date-time":"2022-03-31T21:34:29Z","timestamp":1648762469000},"page":"2697","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":132,"title":["Adaptive Machine Learning Based Distributed Denial-of-Services Attacks Detection and Mitigation System for SDN-Enabled IoT"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9697-6766","authenticated-orcid":false,"given":"Muhammad","family":"Aslam","sequence":"first","affiliation":[{"name":"School of Computing, Engineering and Physical Sciences, University of the West of Scotland, Glasgow G72 0LH, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2510-9523","authenticated-orcid":false,"given":"Dengpan","family":"Ye","sequence":"additional","affiliation":[{"name":"School of Cyber Sceince and Engineering, Wuhan University, Wuhan 430079, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1196-1248","authenticated-orcid":false,"given":"Aqil","family":"Tariq","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Engineering in Surveying, Mapping and Remote Sensing (LIESMARS), Wuhan University, Wuhan 430079, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0036-1714","authenticated-orcid":false,"given":"Muhammad","family":"Asad","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Nagoya Institute of Technology, Nagoya 466-8555, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8312-0996","authenticated-orcid":false,"given":"Muhammad","family":"Hanif","sequence":"additional","affiliation":[{"name":"Department of Computer Science, COMSATS University of Islamabad, Wah Cantt 45550, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1125-1978","authenticated-orcid":false,"given":"David","family":"Ndzi","sequence":"additional","affiliation":[{"name":"School of Computing, Engineering and Physical Sciences, University of the West of Scotland, Glasgow G72 0LH, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9711-0235","authenticated-orcid":false,"given":"Samia Allaoua","family":"Chelloug","sequence":"additional","affiliation":[{"name":"Department of Information Technology, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University, P.O. Box 84428, Riyadh 11671, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7682-6269","authenticated-orcid":false,"given":"Mohamed Abd","family":"Elaziz","sequence":"additional","affiliation":[{"name":"Department of Mathematics, Faculty of Science, Zagazig University, Zagazig 44519, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6956-7641","authenticated-orcid":false,"given":"Mohammed A. A.","family":"Al-Qaness","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Engineering in Surveying, Mapping and Remote Sensing (LIESMARS), Wuhan University, Wuhan 430079, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4751-8574","authenticated-orcid":false,"given":"Syeda Fizzah","family":"Jilani","sequence":"additional","affiliation":[{"name":"Department of Physics, Aberystwyth University, Aberystwyth SY23 3FL, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,3,31]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1016\/j.comnet.2019.01.023","article-title":"Internet of Things: A Survey on Machine Learning-based Intrusion Detection Approaches","volume":"151","author":"Papa","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_2","first-page":"732","article-title":"5G-enabled devices and smart-spaces in social-IoT: An overview","volume":"92","year":"2017","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"11413","DOI":"10.1109\/ACCESS.2017.2716344","article-title":"An Autonomous Wireless Body Area Network Implementation Towards IoT Connected Healthcare Applications","volume":"5","author":"Wu","year":"2017","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"167","DOI":"10.1016\/j.jnca.2019.06.019","article-title":"BlockSecIoTNet: Blockchain-based decentralized security architecture for IoT network","volume":"143","author":"Rathore","year":"2019","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_5","unstructured":"Dao, N.N., Phan, T.V., Ad, U.S., Kim, J., Bauschert, T., and Cho, S. (2021). Securing Heterogeneous IoT with Intelligent DDoS Attack Behavior Learning. IEEE Syst. Journal, 1\u201310."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.jnca.2019.01.006","article-title":"Efficient DDoS attacks mitigation for stateful forwarding in Internet of Things","volume":"130","author":"Liu","year":"2019","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1016\/j.future.2013.08.002","article-title":"Detection and defense of application-layer DDoS attacks in backbone web traffic","volume":"38","author":"Zhou","year":"2014","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"2242","DOI":"10.1109\/COMST.2015.2457491","article-title":"Botnet in DDoS Attacks: Trends and Challenges","volume":"17","author":"Hoque","year":"2015","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"879","DOI":"10.1109\/TNSM.2018.2828938","article-title":"An Inter-domain Collaboration Scheme to Remedy DDoS Attacks in Computer Networks","volume":"15","author":"Simpson","year":"2018","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_10","first-page":"225","article-title":"Generation of DDoS Attack Dataset for Effective IDS Development and Evaluation","volume":"9","author":"Alzahrani","year":"2018","journal-title":"J. Inf. Secur."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"698","DOI":"10.1016\/j.asoc.2012.08.028","article-title":"Detection of malicious and non-malicious website visitors using unsupervised neural network learning","volume":"13","author":"Stevanovic","year":"2013","journal-title":"Appl. Soft Comput."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Bhunia, S.S., and Gurusamy, M. (2017, January 22\u201324). Dynamic attack detection and mitigation in IoT using SDN. Proceedings of the 2017 27th International Telecommunication Networks and Applications Conference (ITNAC), Melbourne, VIC, Australia.","DOI":"10.1109\/ATNAC.2017.8215418"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"317","DOI":"10.1016\/j.asoc.2016.07.014","article-title":"Optimal allocation of FACTS devices for static security enhancement in power systems via imperialistic competitive algorithm (ICA)","volume":"48","author":"Jordehi","year":"2016","journal-title":"Appl. Soft Comput."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"541","DOI":"10.1109\/SURV.2011.072210.00075","article-title":"A Survey on the Application of FPGAs for Network Infrastructure Security","volume":"13","author":"Chen","year":"2011","journal-title":"Commun. Surv. Tutor. IEEE"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"252","DOI":"10.1109\/TSC.2019.2949801","article-title":"Groupchain: Towards a Scalable Public Blockchain in Fog Computing of IoT Services Computing","volume":"13","author":"Lei","year":"2020","journal-title":"IEEE Trans. Serv. Comput."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"838","DOI":"10.1109\/LCOMM.2019.2901486","article-title":"Improving the Routing Security in Software-Defined Networks","volume":"23","author":"Ai","year":"2019","journal-title":"IEEE Commun. Lett."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1016\/j.jnca.2018.03.024","article-title":"D-FACE: An anomaly based distributed approach for early detection of DDoS attacks and flash events","volume":"111","author":"Behal","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Braga, R., Mota, E., and Passito, A. (2010, January 10\u201314). Lightweight DDoS flooding attack detection using NOX\/OpenFlow. Proceedings of the IEEE Local Computer Network Conference, Denver, CO, USA.","DOI":"10.1109\/LCN.2010.5735752"},{"key":"ref_19","unstructured":"Choi, Y. (2010, January 9\u201310). Implementation of content-oriented networking architecture (CONA): A focus on DDoS countermeasure. Proceedings of the European NetFPGA Developers Workshop, Cambridge, UK."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1016\/j.jnca.2016.04.005","article-title":"SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks","volume":"68","author":"Cui","year":"2016","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1109\/MNET.2016.7389832","article-title":"When big data meets software-defined networking: SDN for big data and big data for SDN","volume":"30","author":"Cui","year":"2016","journal-title":"IEEE Netw."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"436","DOI":"10.1109\/TCC.2014.2355227","article-title":"Byzantine-resilient secure software-defined networks with multiple controllers","volume":"2","author":"Li","year":"2015","journal-title":"IEEE Trans. Cloud Comput."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"325","DOI":"10.1109\/COMST.2016.2618874","article-title":"Software Defined Networking Architecture, Security and Energy Efficiency: A Survey","volume":"19","author":"Rawat","year":"2017","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Xu, Y., and Liu, Y. (2016, January 10\u201314). DDoS attack detection under SDN context. Proceedings of the IEEE INFOCOM 2016\u2014The 35th Annual IEEE International Conference on Computer Communications, San Francisco, CA, USA.","DOI":"10.1109\/INFOCOM.2016.7524500"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"2099","DOI":"10.1109\/TETC.2019.2963091","article-title":"Edge Cloud Server Deployment with Transmission Power Control through Machine Learning for 6G Internet of Things","volume":"9","author":"Rodrigues","year":"2019","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"key":"ref_26","first-page":"1956","article-title":"Application of Behavior Analysis Technology based on Machine Learning in the Next Generation Intelligent Network Security System","volume":"51","author":"Chen","year":"2018","journal-title":"Commun. Technol."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"138","DOI":"10.1016\/j.cose.2019.04.018","article-title":"A cost analysis of machine learning using dynamic runtime opcodes for malware detection","volume":"85","author":"Carlin","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"493","DOI":"10.1007\/s12083-017-0630-0","article-title":"Survey on SDN based network intrusion detection system using machine learning approaches","volume":"12","author":"Sultana","year":"2018","journal-title":"Peer-to-Peer Netw. Appl."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1016\/j.comnet.2019.04.027","article-title":"The hybrid technique for DDoS detection with supervised learning algorithms","volume":"158","author":"Hosseini","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Aslam, M., Ye, D., Hanif, M., and Asad, M. (2020, January 8\u201310). Machine learning based SDN-enabled distributed denial-of-services attacks detection and mitigation system for Internet of Things. Proceedings of the International Conference on Machine Learning for Cyber Security, Guangzhou, China.","DOI":"10.1007\/978-3-030-62223-7_16"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"e4327","DOI":"10.1002\/dac.4327","article-title":"A lightweight portable intrusion detection communication system for auditing applications","volume":"33","author":"Nykvist","year":"2020","journal-title":"Int. J. Commun. Syst."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"e4062","DOI":"10.1002\/ett.4062","article-title":"Intelligent intrusion detection system in smart grid using computational intelligence and machine learning","volume":"32","author":"Khan","year":"2020","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Khan, S., Thorn, J., Wahlgren, A., and Gurtov, A. (2021, January 3\u20137). Intrusion Detection in Automatic Dependent Surveillance-Broadcast (ADS-B) with Machine Learning. Proceedings of the 2021 IEEE\/AIAA 40th Digital Avionics Systems Conference (DASC), San Antonio, TX, USA.","DOI":"10.1109\/DASC52595.2021.9594431"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"3559","DOI":"10.1109\/JIOT.2020.2973176","article-title":"Learning-driven detection and mitigation of DDoS attack in IoT via SDN-cloud architecture","volume":"7","author":"Ravi","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"24694","DOI":"10.1109\/ACCESS.2018.2831284","article-title":"A DDoS Attack Detection and Mitigation With Software-Defined Internet of Things Framework","volume":"6","author":"Yin","year":"2018","journal-title":"IEEE Access"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"4829","DOI":"10.1109\/JIOT.2018.2846040","article-title":"Securing the internet of things in the age of machine learning and software-defined networking","volume":"5","author":"Restuccia","year":"2018","journal-title":"IEEE Internet Things J."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Kanagavelu, R., and Aung, K.M.M. (2018, January 5\u20136). A survey on sdn based security in internet of things. Proceedings of the Future of Information and Communication Conference, Singapore.","DOI":"10.1007\/978-3-030-03405-4_39"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"671","DOI":"10.1109\/TNN.2006.873281","article-title":"A geometric approach to support vector machine (SVM) classification","volume":"17","author":"Mavroforakis","year":"2006","journal-title":"IEEE Trans. Neural Netw."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Yusof, A.R., Udzir, N.I., and Selamat, A. (2016, January 2\u20134). An evaluation on KNN-SVM algorithm for detection and prediction of DDoS attack. Proceedings of the International Conference on Industrial, Engineering and Other Applications of Applied Intelligent Systems, Morioka, Japan.","DOI":"10.1007\/978-3-319-42007-3_9"},{"key":"ref_40","first-page":"60","article-title":"Naive bayes classifiers","volume":"18","author":"Murphy","year":"2006","journal-title":"Univ. Br. Columbia"},{"key":"ref_41","first-page":"177","article-title":"DDoS classification using neural network and na\u00efve bayes methods for network forensics","volume":"9","author":"Yudhana","year":"2018","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Hosmer, D.W., Lemeshow, S., and Sturdivant, R.X. (2013). Applied Logistic Regression, John Wiley & Sons.","DOI":"10.1002\/9781118548387"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1016\/j.eswa.2018.03.027","article-title":"An ecosystem for anomaly detection and mitigation in software-defined networking","volume":"104","author":"Carvalho","year":"2018","journal-title":"Expert Syst. Appl."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"160536","DOI":"10.1109\/ACCESS.2019.2950945","article-title":"Efficient DDoS Detection Based on K-FKNN in Software Defined Networks","volume":"7","author":"Xu","year":"2019","journal-title":"IEEE Access"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Alam, M.S., and Vuong, S.T. (2013, January 20\u201323). Random forest classification for detecting android malware. Proceedings of the 2013 IEEE International Conference on Green Computing and Communications and IEEE Internet of Things and IEEE Cyber, Physical and Social Computing, Beijing, China.","DOI":"10.1109\/GreenCom-iThings-CPSCom.2013.122"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"107049","DOI":"10.1016\/j.comnet.2019.107049","article-title":"HELAD: A novel network anomaly detection model based on heterogeneous ensemble learning","volume":"169","author":"Zhong","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"9804061","DOI":"10.1155\/2018\/9804061","article-title":"A DDoS attack detection method based on SVM in software defined network","volume":"2018","author":"Ye","year":"2018","journal-title":"Secur. Commun. Netw."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/7\/2697\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:47:40Z","timestamp":1760136460000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/7\/2697"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,31]]},"references-count":47,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2022,4]]}},"alternative-id":["s22072697"],"URL":"https:\/\/doi.org\/10.3390\/s22072697","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,31]]}}}