{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T21:31:39Z","timestamp":1784842299693,"version":"3.55.0"},"reference-count":58,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2022,6,8]],"date-time":"2022-06-08T00:00:00Z","timestamp":1654646400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Defense Science and Technology Academic Collaborative Research Project"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Recent developments have made software-defined networking (SDN) a popular technology for solving the inherent problems of conventional distributed networks. The key benefit of SDN is the decoupling between the control plane and the data plane, which makes the network more flexible and easier to manage. SDN is a new generation network architecture; however, its configuration settings are centralized, making it vulnerable to hackers. Our study investigated the feasibility of applying artificial intelligence technology to detect abnormal attacks in an SDN environment based on the current unit network architecture; therefore, the concept of symmetry includes the sustainability of SDN applications and robust performance of machine learning (ML) models in the case of various malicious attacks. In this study, we focus on the early detection of abnormal attacks in an SDN environment. On detection of malicious traffic in SDN topology, the AI module in the topology is applied to detect and act against the attack source through machine learning algorithms, making the network architecture more flexible. Under multiple abnormal attacks, we propose a hierarchical multi-class (HMC) architecture to effectively address the imbalanced dataset problem and improve the performance of minority classes. The experimental results show that the decision tree, random forest, bagging, AdaBoost, and deep learning models exhibit the best performance for distributed denial-of-service (DDoS) attacks. In addition, for the imbalanced dataset problem of multiclass classification, our proposed HMC architecture performs better than previous single classifiers. We also simulated the SDN topology and scenario verification. In summary, we concatenated the AI module to enhance the security and effectiveness of SDN networks in a practical manner.<\/jats:p>","DOI":"10.3390\/sym14061178","type":"journal-article","created":{"date-parts":[[2022,6,13]],"date-time":"2022-06-13T02:01:44Z","timestamp":1655085704000},"page":"1178","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":23,"title":["Early Detection of Abnormal Attacks in Software-Defined Networking Using Machine Learning Approaches"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1646-5190","authenticated-orcid":false,"given":"Hsiu-Min","family":"Chuang","sequence":"first","affiliation":[{"name":"Department of Computer Science and Information Engineering, Chung Cheng Institute of Technology, National Defense University, Taoyuan City 335, Taiwan"},{"name":"System Engineering and Technology Program, National Yang Ming Chiao Tung University, Hsinchu City 30010, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0662-1620","authenticated-orcid":false,"given":"Fanpyn","family":"Liu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Information Engineering, Chung Cheng Institute of Technology, National Defense University, Taoyuan City 335, Taiwan"},{"name":"System Engineering and Technology Program, National Yang Ming Chiao Tung University, Hsinchu City 30010, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5510-9685","authenticated-orcid":false,"given":"Chung-Hsien","family":"Tsai","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Information Engineering, Chung Cheng Institute of Technology, National Defense University, Taoyuan City 335, Taiwan"},{"name":"System Engineering and Technology Program, National Yang Ming Chiao Tung University, Hsinchu City 30010, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,6,8]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"721","DOI":"10.1007\/s10922-020-09517-0","article-title":"Network Management 2030: Operations and Control of Network 2030 Services","volume":"28","author":"Clemm","year":"2020","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"165263","DOI":"10.1109\/ACCESS.2020.3022633","article-title":"InSDN: A Novel SDN Intrusion Dataset","volume":"8","author":"Elsayed","year":"2020","journal-title":"IEEE Access."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Jahromi, H.Z., and Delaney, D.T. (2018, January 6\u20139). An Application Awareness Framework based on SDN and Machine Learning: Defining the Roadmap and Challenges. Proceedings of the 10th International Conference on Communication Software and Networks (ICCSN), Chengdu, China.","DOI":"10.1109\/ICCSN.2018.8488328"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Ahmed, M.R., Islam, S., Shatabda, S., Muzahidul Islam, A.K.M., and Robin, M.T.I. (2021). Intrusion Detection System in Software-Defined Networks Using Machine Learning and Deep Learning Techniques\u2014A Comprehensive Survey. TechRxiv Preprint.","DOI":"10.36227\/techrxiv.17153213.v1"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Thakur, N., and Han, C.Y. (2021). A Study of Fall Detection in Assisted Living: Identifying and Improving the Optimal Machine Learning Method. J. Sens. Actuator Netw., 10.","DOI":"10.3390\/jsan10030039"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Lee, C., Hong, J., Heo, D., and Choi, H. (2021, January 20\u201322). Sequential Deep Learning Architectures for Anomaly Detection in Virtual Network Function Chains. Proceedings of the 2021 International Conference on Information and Communication Technology Convergence (ICTC), Jeju Island, Korea.","DOI":"10.1109\/ICTC52510.2021.9621043"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Fan, C., Kaliyamurthy, N.M., Chen, S., Jiang, H., Zhou, Y., and Campbell, C. (2022). Detection of DDoS Attacks in Software Defined Networking Using Entropy. Appl. Sci., 12.","DOI":"10.3390\/app12010370"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Aslam, M., Ye, D., Tariq, A., Asad, M., Hanif, M., Ndzi, D., Chelloug, S.A., Elaziz, M.A., Al-Qaness, M.A.A., and Jilani, S.F. (2022). Adaptive Machine Learning Based Distributed Denial-of-Services Attacks Detection and Mitigation System for SDN-Enabled IoT. Sensors, 22.","DOI":"10.3390\/s22072697"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"104412","DOI":"10.1016\/j.micpro.2021.104412","article-title":"An Optimized Weighted Voting Based Ensemble Model for DDoS Attack Detection and Mitigation in SDN Environment","volume":"89","author":"Maheshwari","year":"2022","journal-title":"Microprocess. Microsyst."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1016\/j.future.2021.11.009","article-title":"Software-Defined DDoS Detection with Information Entropy Analysis and Optimized Deep Learning","volume":"129","author":"Liu","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_11","unstructured":"Jemili, I., and Mosbah, M. (2022). A Survey of Machine Learning Methods for DDoS Threats Detection Against SDN. Distributed Computing for Emerging Smart Networks (DiCES-N), Springer. Communications in Computer and Information Science."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Sudar, K.M., Beulah, M., Deepalakshmi, P., Nagaraj, P., and Chinnasamy, P. (2021, January 21). Detection of Distributed Denial of Service Attacks in SDN using Machine learning techniques. Proceedings of the 2021 International Conference on Computer Communication and Informatics (ICCCI), Coimbatore, India.","DOI":"10.1109\/ICCCI50826.2021.9402517"},{"key":"ref_13","unstructured":"(2021, May 25). KDD Cup 1999. Available online: http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A Detailed Analysis of the KDD CUP 99 Data Set. Proceedings of the IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_15","unstructured":"Ahuja, N., Singal, G., and Mukhopadhyay, D. (2020). DDOS attack SDN Dataset. Mendeley Data."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"5803","DOI":"10.1002\/sec.1737","article-title":"Software-Defined Networking (SDN): A Survey","volume":"9","author":"Benzekki","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Bedhief, I., Kassar, M., Aguili, T., and Foschini, L. (2019, January 24\u201328). Self-Adaptive Management of SDN Distributed Controllers for Highly Dynamic IoT Networks. Proceedings of the 15th International Wireless Communications & Mobile Computing Conference (IWCMC), Tangier, Morocco.","DOI":"10.1109\/IWCMC.2019.8766349"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"23471","DOI":"10.1109\/ACCESS.2019.2899653","article-title":"eTDP: Enhanced Topology Discovery Protocol for Software-Defined Networks","volume":"7","year":"2019","journal-title":"IEEE Access"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Gyllstrom, D., Braga, N., and Kurose, J. (2014, January 3\u20136). Recovery from Link Failures in a Smart Grid Communication Network Using Openflow. Proceedings of the 2014 IEEE International Conference on Smart Grid Communications (SmartGridComm), Venice, Italy.","DOI":"10.1109\/SmartGridComm.2014.7007655"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Naous, J., Erickson, D., Covington, G.A., Appenzeller, G., and McKeown, N. (2008, January 1\u20139). Implementing an OpenFlow Switch on the NetFPGA Platform. Proceedings of the 4th ACM\/IEEE Symposium on Architectures for Networking and Communications Systems (ANCS \u201908), New York, NY, USA.","DOI":"10.1145\/1477942.1477944"},{"key":"ref_21","unstructured":"Tandon, R. (2020). A Survey of Distributed Denial of Service Attacks and Defenses. arXiv."},{"key":"ref_22","unstructured":"Foster, N., and Sherwood, R. (2013, January 16). Attacking Software-Defined Networks: A First Feasibility Study. Proceedings of the second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking (HotSDN), New York, NY, USA."},{"key":"ref_23","unstructured":"Sadeghi, A.-R. (2013, January 4\u20138). Avant-guard: Scalable and Vigilant Switch Flow Management in Software-Defined Networks. Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security (CCS\u201913), Berlin, Germany."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Kandoi, R., and Antikainen, M. (2015, January 11\u201315). Denial-Of-Service Attacks in OpenFlow SDN Networks. Proceedings of the 2015 IFIP\/IEEE International Symposium on Integrated Network Management (IM), Ottawa, ON, Canada.","DOI":"10.1109\/INM.2015.7140489"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1109\/MCOM.2015.7081073","article-title":"Securing Software Defined Networks: Taxonomy, Requirements, and Open Issues","volume":"53","author":"Akhunzada","year":"2015","journal-title":"IEEE Commun. Mag."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1109\/MNET.2016.1600109NM","article-title":"On Denial of Service Attacks in Software Defined Networks","volume":"30","author":"Zhang","year":"2016","journal-title":"IEEE Netw."},{"key":"ref_27","unstructured":"Dover, J.M. (2013). A Denial of Service Attack against the Open Floodlight SDN Controller, Dover Networks LLC."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"100279","DOI":"10.1016\/j.cosrev.2020.100279","article-title":"Detection and Mitigation of DDoS Attacks in SDN: A Comprehensive Review, Research Challenges and Future Directions","volume":"37","author":"Singh","year":"2020","journal-title":"Comput. Sci. Rev."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"76024","DOI":"10.1109\/ACCESS.2021.3081629","article-title":"Detection and Classification of Conflict Flows in SDN Using Machine Learning Algorithms","volume":"9","author":"Khairi","year":"2021","journal-title":"IEEE Access"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"72585","DOI":"10.1109\/ACCESS.2020.2987977","article-title":"Flow-aware Elephant Flow Detection for Software-Defined Networks","volume":"8","author":"Hamdan","year":"2020","journal-title":"IEEE Access"},{"key":"ref_31","unstructured":"Boumerdassi, S., Renault, \u00c9., and M\u00fchlethaler, P. (2019, January 3\u20135). Network Traffic Classification Using Machine Learning for Software Defined Networks. Proceedings of the International Conference on Maching Learning for Netwwork (MLN), Paris, France."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Khamaiseh, S., Serra, E., Li, Z., and Xu, D. (2019, January 10\u201312). Detecting Saturation Attacks in SDN via Machine Learning. Proceedings of the 2019 4th International Conference on Computing, Communications and Security (ICCCS), Rome, Italy.","DOI":"10.1109\/CCCS.2019.8888049"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"1022","DOI":"10.1109\/TCC.2019.2901669","article-title":"Elephant Flow Detection and Differentiated Scheduling with Efficient Sampling and Classification","volume":"9","author":"Tang","year":"2021","journal-title":"IEEE Trans. Cloud Comput."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1049\/iet-net.2018.5082","article-title":"Artificial Intelligence Enabled Software-Defined Networking: A Comprehensive Overview","volume":"8","author":"Latah","year":"2019","journal-title":"IET Netw."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Comaneci, D., and Dobre, C. (2018, January 29\u201331). Securing Networks Using SDN and Machine Learning. Proceedings of the IEEE International Conference on Computational Science and Engineering (CSE), Bucharest, Romania.","DOI":"10.1109\/CSE.2018.00034"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"55380","DOI":"10.1109\/ACCESS.2018.2872430","article-title":"DataNet: Deep Learning based Encrypted Network Traffic Classification in SDN Home Gateway","volume":"6","author":"Wang","year":"2018","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"1","DOI":"10.17485\/ijst\/2016\/v9i44\/89812","article-title":"Application of Artificial Intelligence to Software Defined Networking: A Survey","volume":"9","author":"Latah","year":"2016","journal-title":"Indian J. Sci. Technol."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"215","DOI":"10.1016\/j.comcom.2019.09.014","article-title":"Varman: Multi-plane Security Framework for Software Defined Networks","volume":"148","author":"Krishnan","year":"2019","journal-title":"Comput. Commun."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"266","DOI":"10.1109\/TCCN.2018.2790974","article-title":"Intelligent Software-Defined Mesh Networks with Link-Failure Adaptive Traffic Balancing","volume":"4","author":"Bao","year":"2018","journal-title":"IEEE Trans. Cognit. Commun. Netw."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Amaral, P., Dinis, J., Pinto, P., Bernardo, L., Tavares, J., and Mamede, H.S. (2016, January 11\u201316). Machine Learning in Software Defined Networks: Data Collection and Traffic Classification. Proceedings of the 2016 IEEE 24th International Conference on Network Protocols (ICNP), Singapore.","DOI":"10.1109\/ICNP.2016.7785327"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1109\/TSC.2016.2602861","article-title":"Defending Against Flow Table Overloading Attack in Software-Defined Networks","volume":"12","author":"Yuan","year":"2019","journal-title":"IEEE Trans. Serv. Comput."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"34885","DOI":"10.1109\/ACCESS.2019.2904236","article-title":"Cyberpulse: A Machine Learning based Link Flooding Attack Mitigation System for Software Defined Networks","volume":"7","author":"Rasool","year":"2019","journal-title":"IEEE Access"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Tseng, C.-W., Wu, L.-F., Hsu, S.-C., and Yu, S.-W. (2020, January 22\u201325). IPv6 DoS Attacks Detection Using Machine Learning Enhanced IDS in SDN\/NFV Environment. Proceedings of the 2020 21st Asia-Pacific Network Operations and Management Symposium (APNOMS), Daegu, Korea.","DOI":"10.23919\/APNOMS50412.2020.9237056"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Tonkal, \u00d6., Polat, H., Ba\u015faran, E., C\u00f6mert, Z., and Kocao\u011flu, R. (2021). Machine Learning Approach Equipped with Neighbourhood Component Analysis for DDoS Attack Detection in Software-Defined Networking. Electronics, 10.","DOI":"10.3390\/electronics10111227"},{"key":"ref_45","unstructured":"Khoshgoftaar, T.M. (2019, January 16\u201319). An Intrusion Detection System for Multi-class Classification Based on Deep Neural Networks. Proceedings of the 18th IEEE International Conference On Machine Learning and Applications (ICMLA), Boca Raton, FL, USA."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"44570","DOI":"10.1109\/ACCESS.2018.2854567","article-title":"An Efficient SDN-based DDoS Attack Detection and Rapid Response Platform in Vehicular Networks","volume":"6","author":"Yu","year":"2018","journal-title":"IEEE Access"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Huseyin, P., Polat, O., and Aydin, C. (2020). Detecting DDoS Attacks in Software-Defined Networks Through Feature Selection Methods and Machine Learning Models. Sustainability, 12.","DOI":"10.3390\/su12031035"},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"307","DOI":"10.11591\/ijeecs.v22.i1.pp307-314","article-title":"Generation and Collection of Data for Normal and Conflicting Flows in Software Defined Network Flow Table","volume":"22","author":"Khairi","year":"2021","journal-title":"Indonesian J. Electr. Eng. Comput. Sci."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Dey, S.K., and Rahman, M.M. (2020). Effects of Machine Learning Approach in Flow-Based Anomaly Detection on Software-Defined Networking. Symmetry, 12.","DOI":"10.3390\/sym12010007"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Shinan, K., Alsubhi, K., Alzahrani, A., and Ashraf, M.U. (2021). Machine Learning-Based Botnet Detection in Software-Defined Network: A Systematic Review. Symmetry, 13.","DOI":"10.3390\/sym13050866"},{"key":"ref_51","unstructured":"Pendlebury, F., Pierazzi, F., Jordaney, R., Kinder, J., and Cavallaro, L. (2019, January 14\u201316). TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and Time. Proceedings of the 28th USENIX Conference on Security Symposium (SEC\u201919), Santa Clara, CA, USA."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1109\/TETCI.2017.2699220","article-title":"Context-Aware, Adaptive, and Scalable Android Malware Detection through Online Learning","volume":"1","author":"Narayanan","year":"2017","journal-title":"IEEE Trans. Emerg. Top. Comput. Intellig."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Xu, K., Li, Y., Deng, R., Chen, K., and Xu, J. (2019, January 17\u201319). Droidevolver: Self-Evolving Android Malware Detection System. Proceedings of the IEEE European Symposium on Security and Privacy (EuroS&P), Stockholm, Sweden.","DOI":"10.1109\/EuroSP.2019.00014"},{"key":"ref_54","unstructured":"Jordaney, R., Sharad, K., Dash, S.K., Wang, Z., Papini, D., and Cavallaro, L. (2017, January 16\u201318). Transcend: Detecting Concept Drift in Malware Classification Models. Proceedings of the 26th USENIX Conference on Security Symposium, Vancouver, BC, Canada."},{"key":"ref_55","unstructured":"Barbero, F., Pendlebury, F., Pierazzi, F., and Cavallaro, L. (2020). Transcending Transcend: Revisiting Malware Classification in the Presence of Concept Drift. arXiv."},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1145\/3371924","article-title":"Assessing and Improving Malware Detection Sustainability through App Evolution Studies","volume":"29","author":"Cai","year":"2020","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","article-title":"Smote: Synthetic Minority Over-Sampling Technique","volume":"16","author":"Chawla","year":"2002","journal-title":"J. Artif. Intell. Res."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"110","DOI":"10.1109\/MCOM.2013.6588659","article-title":"EstiNet Openflow Network Simulator and Emulator","volume":"51","author":"Wang","year":"2013","journal-title":"IEEE Commun. Mag."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/14\/6\/1178\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:25:51Z","timestamp":1760138751000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/14\/6\/1178"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,8]]},"references-count":58,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2022,6]]}},"alternative-id":["sym14061178"],"URL":"https:\/\/doi.org\/10.3390\/sym14061178","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,8]]}}}