{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:48:01Z","timestamp":1784134081638,"version":"3.55.0"},"reference-count":51,"publisher":"MDPI AG","issue":"21","license":[{"start":{"date-parts":[[2022,10,28]],"date-time":"2022-10-28T00:00:00Z","timestamp":1666915200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Natural Science Foundation of Zhejiang Province","award":["LQ20F020014"],"award-info":[{"award-number":["LQ20F020014"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>With the development of Software Defined Networking (SDN), its security is becoming increasingly important. Since SDN has the characteristics of centralized management and programmable, attackers can easily take advantage of the security vulnerabilities of SDN to carry out distributed denial of service (DDoS) attacks, which will cause the memory of controllers and switches to be occupied, network bandwidth and server resources to be exhausted, affecting the use of normal users. To solve this problem, this paper designs and implements an online attack detection and mitigation SDN defense system. The SDN defense system consists of two modules: anomaly detection module and mitigation module. The anomaly detection model uses a lightweight hybrid deep learning method\u2014Convolutional Neural Network and Extreme Learning Machine (CNN-ELM) for anomaly detection of traffic. The mitigation model uses IP traceback to locate the attacker and effectively filters out abnormal traffic by sending flow rule commands from the controller. Finally, we evaluate the SDN defense system. The experimental results show that the SDN defense system can accurately identify and effectively mitigate DDoS attack flows in real-time.<\/jats:p>","DOI":"10.3390\/s22218287","type":"journal-article","created":{"date-parts":[[2022,10,30]],"date-time":"2022-10-30T10:47:57Z","timestamp":1667126877000},"page":"8287","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":53,"title":["SDN-Defend: A Lightweight Online Attack Detection and Mitigation System for DDoS Attacks in SDN"],"prefix":"10.3390","volume":"22","author":[{"given":"Jin","family":"Wang","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University of Technology, Hangzhou 310023, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Liping","family":"Wang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University of Technology, Hangzhou 310023, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,10,28]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1007\/978-3-319-97643-3_3","article-title":"Distributed Denial of Service Attacks and Defense Mechanisms: Current Landscape and Future Directions","volume":"Volume 72","author":"Bhatia","year":"2018","journal-title":"Versatile Cybersecurity"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"18701","DOI":"10.1109\/ACCESS.2019.2896783","article-title":"Efficient Distributed Denial-of-Service Attack Defense in SDN-Based Cloud","volume":"7","author":"Phan","year":"2019","journal-title":"IEEE Access"},{"key":"ref_3","unstructured":"RADWARE (2018). 2017\u20132018 Global Application & Network Security Report, RADWARE."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1145\/2377677.2377735","article-title":"Scalable software defined network controllers","volume":"42","author":"Voellmy","year":"2012","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"2593","DOI":"10.1007\/s11277-020-07812-2","article-title":"Systematic Review of Quality of Services(QoS) in Software Defined Networking(SDN)","volume":"116","author":"Keshari","year":"2021","journal-title":"Wirel. Pers. Commun."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1145\/1355734.1355746","article-title":"OpenFlow: Enabling innovation in campus networks","volume":"38","author":"McKeown","year":"2008","journal-title":"Comput. Commun. Rev."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1016\/j.comcom.2021.02.013","article-title":"Sieve: A flow scheduling framework in SDN based data center networks","volume":"171","author":"Zaher","year":"2021","journal-title":"Comput. Commun."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"675","DOI":"10.1109\/TCC.2019.2944823","article-title":"SDN-Based Traffic Matrix Estimation in Data Center Network through Large Size Flow Identification","volume":"10","author":"Liu","year":"2022","journal-title":"IEEE Trans. Cloud Comput."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"103387","DOI":"10.1016\/j.jnca.2022.103387","article-title":"Software-Defined Networking in wireless ad hoc scenarios:Objectives and control architectures","volume":"203","author":"Fogli","year":"2022","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"7746","DOI":"10.1109\/JIOT.2021.3114270","article-title":"Centralized and Distributed Instrusion Detection for Resource-Constrained Wireless SDN Networks","volume":"9","author":"Segura","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1007\/s10922-020-09580-7","article-title":"An SDN-Assisted Defense Mechduanism for the Shrew DDoS Attack in a Cloud Computing Environment","volume":"29","author":"Agrawal","year":"2021","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"198","DOI":"10.1016\/j.comcom.2021.11.008","article-title":"Mitigating TCP SYN flooding based EDOS attack in cloud computing environment binomial distribution in SDN","volume":"182","author":"Shah","year":"2022","journal-title":"Comput. Commun."},{"key":"ref_13","first-page":"15","article-title":"DDoS detection and mitigation Framework inSDN","volume":"6","author":"Jia","year":"2021","journal-title":"J. Cyber Secur."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Bera, P., Saha, A., and Setua, S.K. (2016, January 10\u201311). Denial of Service Attack in Software Defined Network. Proceedings of the 2016 5th International Conference on Computer Science and Network Technology(ICSNT), Changchun, China.","DOI":"10.1109\/ICCSNT.2016.8070208"},{"key":"ref_15","unstructured":"Cao, J., Li, Q., and Xie, R. (2019, January 14\u201316). The Crosspath attacks:disrupting the SDN control channel via shared links. Proceedings of the 28th USENIX Scurity Symposium, Santa Clara, CA, USA."},{"key":"ref_16","unstructured":"Soylu, M., Cuillen, L., and Lzumi, S. (2, January June). NFV-GUARD: Mitigating Flow Table-Overflow Attacks in SDN Using NFV. Proceedings of the IEEE 7th International Conference on Network Softwarization, Tokyo Japan."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"109140","DOI":"10.1016\/j.comnet.2022.109140","article-title":"A DDoS atatck detection and countermeasure scheme based on DWT and auto-encoder neural network for SDN","volume":"214","author":"Fouladi","year":"2022","journal-title":"Comput. Networks"},{"key":"ref_18","first-page":"103017","article-title":"ADVICE: Towards adaptive scheduling for data collection and DDoS detection in SDN","volume":"63","author":"Peng","year":"2021","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"116748","DOI":"10.1016\/j.eswa.2022.116748","article-title":"A norvel approach for accurate detection of the DDoS attacks in SDN-based SCADA systems based on deep recurrent neural networks","volume":"197","author":"Polat","year":"2022","journal-title":"Expert Syst.Appl."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"100279","DOI":"10.1016\/j.cosrev.2020.100279","article-title":"Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions","volume":"37","author":"Singh","year":"2020","journal-title":"Comput. Sci. Rev."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Wang, R., Jia, Z.P., and Ju, L. (2015, January 20\u201322). An Entropy-Based Distributed DDoS Detection Mechanism in Software-Defined Networking. Proceedings of the 2015 IEEE Trustcom\/BigDataSE\/ISPA, Washington, DC, USA.","DOI":"10.1109\/Trustcom.2015.389"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1002\/cpe.5402","article-title":"Machine learning algorithm to detect DDoS attacks in SDN","volume":"32","author":"Santos","year":"2020","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"e3543","DOI":"10.1002\/dac.3543","article-title":"FMD: A DoS mitigation scheme based on flow migration in software-defined networking","volume":"31","author":"Wu","year":"2018","journal-title":"Int. J. Commun. Syst."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TDSC.2021.3108782","article-title":"Detecting and Mitigating DDoS Attacks in SDN Using Spatial-Temporal Graph Convolutional Network","volume":"19","author":"Cao","year":"2022","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1471","DOI":"10.1109\/TIFS.2018.2879616","article-title":"Statistical Application Fingerprinting for DDoS Attack Mitigation","volume":"14","author":"Ahmed","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_26","unstructured":"Carvalho, R.N., Bordim, J.L., and Alchieri, E.A.P. (2019, January 20\u201324). Entropy-Based DoS Attack Identification in SDN. Proceedings of the IEEE International Parallel and Distributed Processing Symposium Workshops, Rio de Janeiro, Brazil."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Mousavi, S.M., and St-Hilaire, M. (2015, January 16\u201319). Early detection of DDoS attacks against SDN controllers. Proceedings of the International Conference on Computing, Networking and Communications, Anaheim, CA, USA.","DOI":"10.1109\/ICCNC.2015.7069319"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"2358","DOI":"10.1109\/JSAC.2018.2869997","article-title":"JESS: Joint entropy-based DDoS defense scheme in SDN","volume":"36","author":"Kalkan","year":"2018","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Salaria, S., Arora, S., and Goyal, N. (2020, January 30\u201331). Implementation and Analysis of an Improved PCA technique for DDoS Detection. Proceedings of the IEEE 5th International Conference on Computing Communication and Automation, Greater Noida, India.","DOI":"10.1109\/ICCCA49541.2020.9250912"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1109\/TNNLS.2019.2900091","article-title":"The Forbidden Region Self-Organizing Map Neural Network","volume":"31","author":"Ramos","year":"2020","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"609","DOI":"10.1109\/TPWRD.2015.2479941","article-title":"Hierarchical K-means method for clustering large-scale advanced metering infrastructure data","volume":"32","author":"Xu","year":"2017","journal-title":"IEEE Trans. Power Deliv."},{"key":"ref_32","first-page":"82","article-title":"Incremental GHSOM algorithm for DDoS attack detection","volume":"40","author":"Liu","year":"2020","journal-title":"J. Nanjing Univ. Posts Telecommun. Nat. Sci. Ed."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"1774","DOI":"10.1109\/TNNLS.2017.2673241","article-title":"Efficient KNN classification with different numbers of nearest neighbors","volume":"29","author":"Zhang","year":"2018","journal-title":"IEEE Trans. Neural Netw. Learn."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"3057","DOI":"10.1109\/TIFS.2019.2913798","article-title":"A synergistic concealed information test with novel approach for EEG channel selection and SVM parameter optimization","volume":"14","author":"Bablani","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_35","first-page":"73","article-title":"Detection of Application Layer DDoS Based on BP Neural Network","volume":"55","author":"Jing","year":"2019","journal-title":"Comput. Eng. Appl."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"34699","DOI":"10.1109\/ACCESS.2019.2895092","article-title":"SGS: Safe-Guard Scheme for Protecting Control Plane Against DDoS Attacks in Software-Defined Networking","volume":"7","author":"Wang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Lin, W.H., Lin, H.C., and Wang, P. (2018, January 13\u201317). Using convolutional neural networks to network intrusion detection for cyber threats. Proceedings of the 4th IEEE International Conference on Applied System Innovation, Tokyo, Japan.","DOI":"10.1109\/ICASI.2018.8394474"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"102604","DOI":"10.1016\/j.cose.2022.102604","article-title":"A hybrid method of entropy and SSAE-SVM based DDoS detection and mitigation mechanism in SDN","volume":"115","author":"Zhang","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_39","first-page":"176","article-title":"DDoS attack detection and defense based on hybrid deep learning model in SDN","volume":"39","author":"Li","year":"2018","journal-title":"J. Commun."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Yuan, X.Y., Li, C.H., and Li, X.L. (2017, January 29\u201331). DeepDefense: Identifying DDoS attack via deep learning. Proceedings of the IEEE International Conference on Smart Computing, Hong Kong, China.","DOI":"10.1109\/SMARTCOMP.2017.7946998"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"103160","DOI":"10.1016\/j.jnca.2021.103160","article-title":"A novel hybrid model for intrusion detection systems in SDNs based on CNN and a new regularization technique","volume":"191","author":"Elsayed","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_42","first-page":"2018243","article-title":"Research on tracing method of IP spoofing data packet network in SDN","volume":"39","author":"Wei","year":"2018","journal-title":"J. Commun."},{"key":"ref_43","first-page":"1","article-title":"Extreme learning machines: New trends and applications","volume":"58","author":"Deng","year":"2015","journal-title":"Chin. Sci. Inf. Sci."},{"key":"ref_44","unstructured":"(2022, September 11). Keras: The Python Deep Learning API. Available online: https:\/\/keras.io."},{"key":"ref_45","unstructured":"(2022, September 11). Mininet: An Instant Virtual Network on Your Laptop(or Other PC)-Mininet. Available online: https\/\/mininet.org."},{"key":"ref_46","unstructured":"(2022, September 11). Open vSwitch. Available online: https:\/\/www.openvswitch.org."},{"key":"ref_47","unstructured":"(2022, September 11). Ryu SDN Framework. Available online: https:\/\/ryu-sdn.org."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Sharadaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Towards Generating a New Instrusion Detection Dataset and Instrusion Traffic Characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy, Funchal, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"165263","DOI":"10.1109\/ACCESS.2020.3022633","article-title":"InSDN: A Novel SDN Intrusion Dataset","volume":"8","author":"Elsayed","year":"2020","journal-title":"IEEE Access"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"215","DOI":"10.1016\/j.comcom.2019.09.014","article-title":"VARMAN: Multi-plane security framework for software defined networks","volume":"148","author":"Krishnan","year":"2019","journal-title":"Comput. Commun."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1109\/TNNLS.2020.2978386","article-title":"A Comprehensive Survey on Graph Neural Networks","volume":"32","author":"Wu","year":"2021","journal-title":"IEEE Trans. Neural Networks Learn. Syst."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/21\/8287\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:05:23Z","timestamp":1760144723000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/21\/8287"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,28]]},"references-count":51,"journal-issue":{"issue":"21","published-online":{"date-parts":[[2022,11]]}},"alternative-id":["s22218287"],"URL":"https:\/\/doi.org\/10.3390\/s22218287","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10,28]]}}}