{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T20:18:57Z","timestamp":1784146737159,"version":"3.55.0"},"reference-count":57,"publisher":"MDPI AG","issue":"15","license":[{"start":{"date-parts":[[2024,8,3]],"date-time":"2024-08-03T00:00:00Z","timestamp":1722643200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The number of connected devices or Internet of Things (IoT) devices has rapidly increased. According to the latest available statistics, in 2023, there were approximately 17.2 billion connected IoT devices; this is expected to reach 25.4 billion IoT devices by 2030 and grow year over year for the foreseeable future. IoT devices share, collect, and exchange data via the internet, wireless networks, or other networks with one another. IoT interconnection technology improves and facilitates people\u2019s lives but, at the same time, poses a real threat to their security. Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks are considered the most common and threatening attacks that strike IoT devices\u2019 security. These are considered to be an increasing trend, and it will be a major challenge to reduce risk, especially in the future. In this context, this paper presents an improved framework (SDN-ML-IoT) that works as an Intrusion and Prevention Detection System (IDPS) that could help to detect DDoS attacks with more efficiency and mitigate them in real time. This SDN-ML-IoT uses a Machine Learning (ML) method in a Software-Defined Networking (SDN) environment in order to protect smart home IoT devices from DDoS attacks. We employed an ML method based on Random Forest (RF), Logistic Regression (LR), k-Nearest Neighbors (kNN), and Naive Bayes (NB) with a One-versus-Rest (OvR) strategy and then compared our work to other related works. Based on the performance metrics, such as confusion matrix, training time, prediction time, accuracy, and Area Under the Receiver Operating Characteristic curve (AUC-ROC), it was established that SDN-ML-IoT, when applied to RF, outperforms other ML algorithms, as well as similar approaches related to our work. It had an impressive accuracy of 99.99%, and it could mitigate DDoS attacks in less than 3 s. We conducted a comparative analysis of various models and algorithms used in the related works. The results indicated that our proposed approach outperforms others, showcasing its effectiveness in both detecting and mitigating DDoS attacks within SDNs. Based on these promising results, we have opted to deploy SDN-ML-IoT within the SDN. This implementation ensures the safeguarding of IoT devices in smart homes against DDoS attacks within the network traffic.<\/jats:p>","DOI":"10.3390\/s24155022","type":"journal-article","created":{"date-parts":[[2024,8,5]],"date-time":"2024-08-05T13:57:28Z","timestamp":1722866248000},"page":"5022","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":23,"title":["Software-Defined-Networking-Based One-versus-Rest Strategy for Detecting and Mitigating Distributed Denial-of-Service Attacks in Smart Home Internet of Things Devices"],"prefix":"10.3390","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-8239-0087","authenticated-orcid":false,"given":"Neder","family":"Karmous","sequence":"first","affiliation":[{"name":"Innov\u2019COM Laboratory, Higher School of Communication of Tunis (SUPCOM), Technopark Elghazala, Raoued, Ariana 2083, Tunisia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6653-9621","authenticated-orcid":false,"given":"Mohamed Ould-Elhassen","family":"Aoueileyine","sequence":"additional","affiliation":[{"name":"Innov\u2019COM Laboratory, Higher School of Communication of Tunis (SUPCOM), Technopark Elghazala, Raoued, Ariana 2083, Tunisia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Manel","family":"Abdelkader","sequence":"additional","affiliation":[{"name":"Computer Science Department, Tunis Business School, University Tunis Elmanar, Tunis 1068, Tunisia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0041-0216","authenticated-orcid":false,"given":"Lamia","family":"Romdhani","sequence":"additional","affiliation":[{"name":"Core Curriculum Program, Deanship of General Studies, University of Qatar, Doha P.O. Box 2713, Qatar"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7211-511X","authenticated-orcid":false,"given":"Neji","family":"Youssef","sequence":"additional","affiliation":[{"name":"Innov\u2019COM Laboratory, Higher School of Communication of Tunis (SUPCOM), Technopark Elghazala, Raoued, Ariana 2083, Tunisia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,8,3]]},"reference":[{"key":"ref_1","unstructured":"Jackisch, T. (2022). Assignment 2: SDN vs. Traditional Network, Glyndwr University."},{"key":"ref_2","first-page":"607","article-title":"A comprehensive review on sdn architecture, applications and major benifits of SDN","volume":"28","author":"Thirupathi","year":"2019","journal-title":"Int. J. Adv. Sci. Technol."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Pathak, Y., Prashanth, P.V.N., and Tiwari, A. (2023). AI Meets SDN: A Survey of Artificial Intelligent Techniques Applied to Software-Defined Networks. 6G Enabled Fog Computing in IoT: Applications and Opportunities, Springer Nature.","DOI":"10.1007\/978-3-031-30101-8_16"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"312","DOI":"10.1007\/s44230-023-00025-3","article-title":"A Comprehensive Survey on Machine Learning using in Software Defined Networks (SDN)","volume":"3","author":"Faezi","year":"2023","journal-title":"Hum. Centric Intell. Syst."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Karmous, N., Aoueileyine, M.O.E., Abdelkader, M., and Youssef, N. (2023, January 29\u201331). Enhanced Machine Learning-Based SDN Controller Framework for Securing IoT Networks. Proceedings of the International Conference on Advanced Information Networking and Applications, Juiz de Fora, Brazil.","DOI":"10.1007\/978-3-031-28694-0_6"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3556973","article-title":"Advancing sdn from openflow to p4: A survey","volume":"55","author":"Liatifis","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Ku\u017aniar, M., Pere\u0161\u00edni, P., and Kosti\u0107, D. (2015, January 19\u201320). What you need to know about SDN flow tables. Proceedings of the Passive and Active Measurement: 16th International Conference, PAM 2015, New York, NY, USA. Proceedings 16.","DOI":"10.1007\/978-3-319-15509-8_26"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"110015","DOI":"10.1016\/j.comnet.2023.110015","article-title":"DDoS attacks in Industrial IoT: A survey","volume":"236","author":"Chaudhary","year":"2023","journal-title":"Comput. Netw."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"103096","DOI":"10.1016\/j.cose.2023.103096","article-title":"A comprehensive study of DDoS attacks over IoT network and their countermeasures","volume":"127","author":"Kumari","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"AlMasri, T., Snober, M.A., and Al-Haija, Q.A. (2022, January 23\u201324). IDPS-SDN-ML: An Intrusion Detection and Prevention System Using Software-Defined Networks and Machine Learning. Proceedings of the 2022 1st International Conference on Smart Technology, Applied Informatics, and Engineering (APICS), Surakarta, Indonesia.","DOI":"10.1109\/APICS56469.2022.9918804"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Karmous, N., Aoueileyine, M.O.E., Abdelkader, M., and Youssef, N. (2022, January 29\u201331). A proposed intrusion detection method based on machine learning used for internet of things systems. Proceedings of the International Conference on Advanced Information Networking and Applications, Juiz de Fora, Brazil.","DOI":"10.1007\/978-3-030-99619-2_4"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Hu, J., and Szymczak, S. (2023). A review on longitudinal data analysis with random forest. Brief. Bioinform., 24.","DOI":"10.1093\/bib\/bbad002"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"2395","DOI":"10.1161\/CIRCULATIONAHA.106.682658","article-title":"Logistic regression","volume":"117","author":"LaValley","year":"2008","journal-title":"Circulation"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"106933","DOI":"10.1016\/j.knosys.2021.106933","article-title":"Ensemble of ML-KNN for classification algorithm recommendation","volume":"221","author":"Zhu","year":"2021","journal-title":"Knowl. Based Syst."},{"key":"ref_15","first-page":"713","article-title":"Na\u00efve Bayes","volume":"15","author":"Webb","year":"2010","journal-title":"Encycl. Mach. Learn."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"95","DOI":"10.3390\/iot4020006","article-title":"A DDoS Attack Detection Method Using Conditional Entropy Based on SDN Traffic","volume":"4","author":"Tian","year":"2023","journal-title":"IoT"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1017\/S0252921100072559","article-title":"Conditional entropy: A tool to explore the phase space","volume":"Volume 172","author":"Cincotta","year":"1999","journal-title":"Proceedings of the International Astronomical Union Colloquium"},{"key":"ref_18","unstructured":"Mart\u00ednez Gim\u00e9nez, M. (2023). Cybersecurity and attacks with Python\/Scapy. [Ph.D. Dissertation, Universitat Polit\u00e8cnica de Val\u00e8ncia]."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"102211","DOI":"10.1016\/j.asej.2023.102211","article-title":"Securing IoT and SDN systems using deep-learning based automatic intrusion detection","volume":"14","author":"Elsayed","year":"2023","journal-title":"Ain Shams Eng. J."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"5929","DOI":"10.1007\/s10462-020-09838-1","article-title":"A review on the long short-term memory model","volume":"53","author":"Mosquera","year":"2020","journal-title":"Artif. Intell. Rev."},{"key":"ref_21","unstructured":"Cheepborisuttikul, T., and Teng-Amuang, Y. (2019). Using Low Orbit Ion Cannon for Denial of Service Attack Based on CVE. Int. J. Adv. Comput. Netw. Its Secur., 145\u2013149."},{"key":"ref_22","unstructured":"Moustafa, N. (2024, January 15). ToN_IoT datasets. IEEE Dataport 2019. Available online: https:\/\/ieee-dataport.org\/documents\/toniot-datasets."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"165263","DOI":"10.1109\/ACCESS.2020.3022633","article-title":"InSDN: A Novel SDN Intrusion Dataset","volume":"8","author":"Elsayed","year":"2020","journal-title":"IEEE Access"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Singh, C., and Jain, A.K. (2023). Detection and Mitigation of DDoS Attacks on SDN Controller in IoT Network using Gini Impurity, Preprint.","DOI":"10.21203\/rs.3.rs-2991752\/v1"},{"key":"ref_25","first-page":"612","article-title":"Evaluating the impact of GINI index and information gain on classification using decision tree classifier algorithm","volume":"11","author":"Tangirala","year":"2020","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_26","unstructured":"Habibi Lashkari, A. (2024, January 15). CICFlowmeter-V4.0 (Formerly Known as ISCXFlowMeter) Is a Network Traffic Bi-Flow Generator and Analyser for Anomaly Detection. Available online: https:\/\/github.com\/ISCX\/CICFlowMeter."},{"key":"ref_27","unstructured":"Zhao, R. (2024, January 26). NSL-KDD. IEEE Dataport 2022. Available online: https:\/\/ieee-dataport.org\/documents\/nsl-kdd-0."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Taud, H., and Mas, J.F. (2018). Multilayer perceptron (MLP). Geomatic Approaches for Modeling Land Change Scenarios, Springer.","DOI":"10.1007\/978-3-319-60801-3_27"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"4765","DOI":"10.1007\/s10462-022-10275-5","article-title":"Recent advances in decision trees: An updated survey","volume":"56","author":"Costa","year":"2023","journal-title":"Artif. Intell. Rev."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Liu, Z., Wang, Y., Feng, F., Liu, Y., Li, Z., and Shan, Y. (2023). A DDoS Detection Method Based on Feature Engineering and Machine Learning in Software-Defined Networks. Sensors, 23.","DOI":"10.3390\/s23136176"},{"key":"ref_31","unstructured":"Canadian Institute for Cybersecurity (2024, January 15). A Realistic Cyber Defense Dataset (CSE-CIC-IDS2018). Available online: https:\/\/www.unb.ca\/cic\/datasets\/ids-2018.html."},{"key":"ref_32","first-page":"323","article-title":"A comprehensive survey on grey wolf optimization","volume":"15","author":"Sharma","year":"2022","journal-title":"Recent Adv. Comput. Sci. Commun."},{"key":"ref_33","first-page":"82","article-title":"Support vector machine-a survey","volume":"2","author":"Pradhan","year":"2012","journal-title":"Int. J. Emerg. Technol. Adv. Eng."},{"key":"ref_34","first-page":"25","article-title":"A Survey of Xgboost system","volume":"8","author":"Gohiya","year":"2018","journal-title":"Int. J. Adv. Technol. Eng. Res."},{"key":"ref_35","first-page":"233","article-title":"Performance evaluation of SDN DDoS attack detection and mitigation based random forest and K-nearest neighbors machine learning algorithms","volume":"36","author":"Mohsin","year":"2022","journal-title":"Rev. D\u2019Intelligence Artif."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"1797","DOI":"10.11591\/eei.v12i3.5232","article-title":"Simulation of SDN in mininet and detection of DDoS attack using machine learning","volume":"12","author":"Karthika","year":"2023","journal-title":"Bull. Electr. Eng. Inform."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"28934","DOI":"10.1109\/ACCESS.2023.3260256","article-title":"FMDADM: A Multi-Layer DDoS Attack Detection and Mitigation Framework Using Machine Learning for Stateful SDN-Based IoT Networks","volume":"11","author":"Khedr","year":"2023","journal-title":"IEEE Access"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Elubeyd, H., and Yiltas-Kaplan, D. (2023). Hybrid Deep Learning Approach for Automatic DoS\/DDoS Attacks Detection in Software-Defined Networks. Appl. Sci., 13.","DOI":"10.3390\/app13063828"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1016\/j.jnca.2017.08.017","article-title":"A review of smart home applications based on Internet of Things","volume":"97","author":"Alaa","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Malche, T., and Maheshwary, P. (2017, January 10\u201311). Internet of Things (IoT) for building smart home system. Proceedings of the 2017 International conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud), I-SMAC, Palladam, India.","DOI":"10.1109\/I-SMAC.2017.8058258"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"1399","DOI":"10.1016\/j.procs.2020.04.150","article-title":"A Novel MQTT Security framework in Generic IoT Model","volume":"171","author":"Patel","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"2931","DOI":"10.1007\/s11042-020-09750-4","article-title":"MQTT protocol employing IOT based home safety system with ABE encryption","volume":"80","author":"Gupta","year":"2021","journal-title":"Multimed. Tools Appl."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Karmous, N., Aoueileyine, M.O.-E., Abdelkader, M., and Youssef, N. (2022, January 1\u20134). IoT Real-Time Attacks Classification Framework Using Machine Learning. Proceedings of the 2022 IEEE Ninth International Conference on Communications and Networking (ComNet), Hammamet, Tunisia.","DOI":"10.1109\/ComNet55492.2022.9998441"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Ahmed, M.R., Shatabda, S., Islam, A.M., and Robin, M.T.I. (2021). Intrusion Detection System in Software-Defined Networks Using Machine Learning and Deep Learning Techniques\u2014A Comprehensive Survey. TechRxiv, preprint.","DOI":"10.36227\/techrxiv.17153213.v1"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Ashraf, E., Areed, N.F., Salem, H., Abdelhady, E.H., and Farouk, A. (2022). IoT Based Intrusion Detection Systems from the Perspective of Machine and Deep Learning: A Survey and Comparative Study. Delta Univ. Sci. J., 5.","DOI":"10.21608\/dusj.2022.275552"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Singh, M., and Baranwal, G. (2018, January 23\u201324). Quality of service (qos) in internet of things. Proceedings of the 2018 3rd International Conference On Internet of Things: Smart Innovation and Usages (IoT-SIU), Bhimtal, India.","DOI":"10.1109\/IoT-SIU.2018.8519862"},{"key":"ref_47","first-page":"103629","article-title":"The evolution of Mirai botnet scans over a six-year period","volume":"79","author":"Affinito","year":"2023","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Shukla, P., Krishna, C.R., and Patil, N.V. (2023). Iot traffic-based DDoS attacks detection mechanisms: A comprehensive review. J. Supercomput., 1\u201358.","DOI":"10.1007\/s11227-023-05843-7"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Mathews, J., Chatterjee, P., and Banik, S. (2022, January 14\u201316). CoAP-DoS: An IoT Network Intrusion Data Set. Proceedings of the 2022 6th International Conference on Cryptography, Security and Privacy (CSP), Tianjin, China.","DOI":"10.1109\/CSP55486.2022.00025"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Almeghlef, S.M., AL-Ghamdi, A.A.M., Ramzan, M.S., and Ragab, M. (2023). Application Layer-Based Denial-of-Service Attacks Detection against IoT-CoAP. Electronics, 12.","DOI":"10.20944\/preprints202305.0070.v1"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"16","DOI":"10.53608\/estudambilisim.1297052","article-title":"Attacks on Availability of IoT Middleware Protocols: A Case Study on MQTT","volume":"4","author":"Mustafa","year":"2023","journal-title":"Eski\u015fehir T\u00fcrk D\u00fcnyas\u0131 Uygulama Ara\u015ft\u0131rma Merkezi Bili\u015fim Dergisi"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Alahmadi, A.A., Aljabri, M., Alhaidari, F., Alharthi, D.J., Rayani, G.E., Marghalani, L.A., Alotaibi, O.B., and Bajandouh, S.A. (2023). DDoS Attack Detection in IoT-Based Networks Using Machine Learning Models: A Survey and Research Directions. Electronics, 12.","DOI":"10.3390\/electronics12143103"},{"key":"ref_53","first-page":"659","article-title":"Improving the classification accuracy using recursive feature elimination with cross-validation","volume":"11","author":"Misra","year":"2020","journal-title":"Int. J. Emerg. Technol."},{"key":"ref_54","first-page":"31","article-title":"A comparative analysis of undersampling techniques for network intrusion detection systems design","volume":"36","author":"Silva","year":"2021","journal-title":"J. Commun. Inf. Syst."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","article-title":"SMOTE: Synthetic minority over-sampling technique","volume":"16","author":"Chawla","year":"2002","journal-title":"J. Artif. Intell. Res."},{"key":"ref_56","unstructured":"Odnan, S., Repetto, M., Carrega, A., and Bolla, R. (July, January 28). Evaluating ML-based DDoS detection with grid search hyperparameter optimization. Proceedings of the 2021 IEEE 7th International Conference on Network Softwarization (NetSoft), Tokyo, Japan."},{"key":"ref_57","first-page":"61","article-title":"Performance of machine learning algorithms with different K values in K-fold cross-validation","volume":"6","author":"Nti","year":"2021","journal-title":"J. Inf. Technol. Comput. Sci."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/15\/5022\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T15:29:22Z","timestamp":1760110162000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/15\/5022"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,3]]},"references-count":57,"journal-issue":{"issue":"15","published-online":{"date-parts":[[2024,8]]}},"alternative-id":["s24155022"],"URL":"https:\/\/doi.org\/10.3390\/s24155022","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8,3]]}}}