{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:47:21Z","timestamp":1784134041014,"version":"3.55.0"},"reference-count":121,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2022,7,29]],"date-time":"2022-07-29T00:00:00Z","timestamp":1659052800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Ministry of Education Malaysia, Fundamental Research","award":["015MA0-047"],"award-info":[{"award-number":["015MA0-047"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Software-defined networking (SDN) is a new networking paradigm that provides centralized control, programmability, and a global view of topology in the controller. SDN is becoming more popular due to its high audibility, which also raises security and privacy concerns. SDN must be outfitted with the best security scheme to counter the evolving security attacks. A Distributed Denial-of-Service (DDoS) attack is a network attack that floods network links with illegitimate data using high-rate packet transmission. Illegitimate data traffic can overload network links, causing legitimate data to be dropped and network services to be unavailable. Low-rate Distributed Denial-of-Service (LDDoS) is a recent evolution of DDoS attack that has been emerged as one of the most serious vulnerabilities for the Internet, cloud computing platforms, the Internet of Things (IoT), and large data centers. Moreover, LDDoS attacks are more challenging to detect because this attack sends a large amount of illegitimate data that are disguised as legitimate traffic. Thus, traditional security mechanisms such as symmetric\/asymmetric detection schemes that have been proposed to protect SDN from DDoS attacks may not be suitable or inefficient for detecting LDDoS attacks. Therefore, more research studies are needed in this domain. There are several survey papers addressing the detection mechanisms of DDoS attacks in SDN, but these studies have focused mainly on high-rate DDoS attacks. Alternatively, in this paper, we present an extensive survey of different detection mechanisms proposed to protect the SDN from LDDoS attacks using machine learning approaches. Our survey describes vulnerability issues in all layers of the SDN architecture that LDDoS attacks can exploit. Current challenges and future directions are also discussed. The survey can be used by researchers to explore and develop innovative and efficient techniques to enhance SDN\u2019s protection against LDDoS attacks.<\/jats:p>","DOI":"10.3390\/sym14081563","type":"journal-article","created":{"date-parts":[[2022,8,1]],"date-time":"2022-08-01T23:49:27Z","timestamp":1659397767000},"page":"1563","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":68,"title":["A Survey of Low Rate DDoS Detection Techniques Based on Machine Learning in Software-Defined Networks"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5594-3415","authenticated-orcid":false,"given":"Abdussalam Ahmed","family":"Alashhab","sequence":"first","affiliation":[{"name":"Department of Computer and Information Science, Universiti Teknologi Petronas, Seri Iskandar 32610, Malaysia"},{"name":"Faculty of Information Technology, Alasmarya Islamic University, Zliten, Libya"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5042-5793","authenticated-orcid":false,"given":"Mohd Soperi Mohd","family":"Zahid","sequence":"additional","affiliation":[{"name":"Department of Computer and Information Science, Universiti Teknologi Petronas, Seri Iskandar 32610, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7593-3591","authenticated-orcid":false,"given":"Mohamed A.","family":"Azim","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Prince Mugrin, Medina 40202, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Muhammad Yunis","family":"Daha","sequence":"additional","affiliation":[{"name":"Department of Computer and Information Science, Universiti Teknologi Petronas, Seri Iskandar 32610, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3820-3378","authenticated-orcid":false,"given":"Babangida","family":"Isyaku","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Sule Lamido University, Kafin Hausa P.M.B.048, Jigawa State, Nigeria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0561-5031","authenticated-orcid":false,"given":"Shimhaz","family":"Ali","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, University Sains Islam Malaysia, Nilai 71800, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,7,29]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"188","DOI":"10.1109\/MNET.2019.1900138","article-title":"An ICN\/SDN-based network architecture and efficient content retrieval for future satellite-terrestrial integrated networks","volume":"34","author":"Li","year":"2019","journal-title":"IEEE Netw."},{"key":"ref_2","first-page":"3","article-title":"Traffic engineering in software defined networks: A survey","volume":"4","author":"Abbasi","year":"2016","journal-title":"J. Telecommun. Inf. Technol."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1016\/j.comnet.2014.07.004","article-title":"Software defined networking: State of the art and research challenges","volume":"72","author":"Jammal","year":"2014","journal-title":"Comput. Netw."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/JPROC.2014.2371999","article-title":"Software-defined networking: A comprehensive survey","volume":"103","author":"Kreutz","year":"2014","journal-title":"Proc. IEEE"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"327","DOI":"10.1007\/s12008-017-0391-2","article-title":"Emerging technologies and research challenges for intelligent transportation systems: 5G, HetNets, and SDN","volume":"12","author":"Camacho","year":"2018","journal-title":"Int. J. Interact. Des. Manuf. (IJIDeM)"},{"key":"ref_6","first-page":"1","article-title":"PFQDN: SDN-and DNS-Assisted Transparent Communications among Behind-NAT Networks","volume":"1","author":"Jia","year":"2022","journal-title":"IEEE Syst. J."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Dangi, R., Jadhav, A., Choudhary, G., Dragoni, N., Mishra, M.K., and Lalwani, P. (2022). ML-Based 5G Network Slicing Security: A Comprehensive Survey. Future Internet, 14.","DOI":"10.3390\/fi14040116"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Waseem, Q., Alshamrani, S.S., Nisar, K., Wan Din, W.I.S., and Alghamdi, A.S. (2021). Future Technology: Software-Defined Network (SDN) Forensic. Symmetry, 13.","DOI":"10.3390\/sym13050767"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Alashhab, A.A., Zahid, M.S.M., Barka, A.A., and Albaboh, A.M. (2021, January 25\u201327). Experimenting and evaluating the impact of DoS attacks on different SDN controllers. Proceedings of the 2021 IEEE 1st International Maghreb Meeting of the Conference on Sciences and Techniques of Automatic Control and Computer Engineering MI-STA, Tripoli, Libya.","DOI":"10.1109\/MI-STA52233.2021.9464469"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"175","DOI":"10.1109\/MCOM.2017.1600970","article-title":"Defense mechanisms against DDoS attacks in SDN environment","volume":"55","author":"Kalkan","year":"2017","journal-title":"IEEE Commun. Mag."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Lei, G., Ji, L., Ji, R., Cao, Y., Shao, X., and Huang, X. (2021). Extracting low-rate DDoS attack characteristics: The case of multipath TCP-based communication networks. Wirel. Commun. Mobile Comput., 2021.","DOI":"10.1155\/2021\/2264187"},{"key":"ref_12","unstructured":"Shalunov, S., and Teitelbaum, B. (2001, January 1\u20132). TCP use and performance on Internet2. Proceedings of the ACM SIGCOMM Internet Measurement Workshop, San Francisco, CA, USA."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Cambiaso, E., Papaleo, G., Chiola, G., and Aiello, M. (2016). Mobile Executions of Slow DoS Attacks, Oxford Academic.","DOI":"10.1093\/jigpal\/jzv043"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Cambiaso, E., Papaleo, G., Chiola, G., and Aiello, M. (2015, January 15\u201317). Designing and modeling the slow next DoS attack. Proceedings of the Computational Intelligence in Security for Information Systems Conference, Burgos, Spain.","DOI":"10.1007\/978-3-319-19713-5_22"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Cui, Y., Qian, Q., Guo, C., Shen, G., Tian, Y., Xing, H., and Yan, L. (2021). Towards DDoS detection mechanisms in software-defined networking. J. Netw. Comput. Appl., 190.","DOI":"10.1016\/j.jnca.2021.103156"},{"key":"ref_16","first-page":"210","article-title":"Research on low-rate DDoS attack of SDN network in cloud environment","volume":"40","author":"Xingshu","year":"2019","journal-title":"J. Commun."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"155859","DOI":"10.1109\/ACCESS.2020.3019330","article-title":"A flexible SDN-based architecture for identifying and mitigating low-rate DDoS attacks using machine learning","volume":"8","author":"Valdovinos","year":"2020","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"193","DOI":"10.3163\/1536-5050.98.2.021","article-title":"Mendeley","volume":"98","author":"Reiswig","year":"2010","journal-title":"J. Med. Libr. Assoc. JMLA"},{"key":"ref_19","first-page":"101065","article-title":"A survey on DoS\/DDoS attacks mathematical modelling for traditional, SDN and virtual networks","volume":"31","author":"Balarezo","year":"2021","journal-title":"Eng. Sci. Technol. Int. J."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"80813","DOI":"10.1109\/ACCESS.2019.2922196","article-title":"A survey on distributed denial of service (DDoS) attacks in SDN and cloud computing environments","volume":"7","author":"Dong","year":"2019","journal-title":"IEEE Access"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"143985","DOI":"10.1109\/ACCESS.2020.3013998","article-title":"Detection techniques of distributed denial of service attacks on software-defined networking controlle\u2014A review","volume":"8","author":"Aladaileh","year":"2020","journal-title":"IEEE Access"},{"key":"ref_22","first-page":"3","article-title":"DDoS attack in software defined networks: A survey","volume":"15","author":"Xu","year":"2017","journal-title":"ZTE Commun."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"ur Rasool, R., Wang, H., Ashraf, U., Ahmed, K., Anwar, Z., and Rafique, W. (2020). A survey of link flooding attacks in software defined network ecosystems. J. Netw. Comput. Appl., 172.","DOI":"10.1016\/j.jnca.2020.102803"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1016\/j.ins.2019.08.047","article-title":"Data-driven software defined network attack detection: State-of-the-art and perspectives","volume":"513","author":"Wang","year":"2020","journal-title":"Inform. Sci."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Singh, J., and Behal, S. (2020). Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions. Comput. Sci. Rev., 37.","DOI":"10.1016\/j.cosrev.2020.100279"},{"key":"ref_26","first-page":"11","article-title":"Does machine learning really work?","volume":"18","author":"Mitchell","year":"1997","journal-title":"AI Mag."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Swana, E., and Doorsamy, W. (2021). An Unsupervised Learning Approach to Condition Assessment on a Wound-Rotor Induction Generator. Energies, 14.","DOI":"10.3390\/en14030602"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s42979-021-00592-x","article-title":"Machine learning: Algorithms, real-world applications and research directions","volume":"2","author":"Sarker","year":"2021","journal-title":"SN Comput. Sci."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"420","DOI":"10.1007\/s42979-021-00815-1","article-title":"Deep learning: A comprehensive overview on techniques, taxonomy, applications and research directions","volume":"2","author":"Sarker","year":"2021","journal-title":"SN Comput. Sci."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1016\/0920-5489(94)90017-5","article-title":"Advanced supervised learning in multi-layer perceptrons\u2014From backpropagation to adaptive learning algorithms","volume":"16","author":"Riedmiller","year":"1994","journal-title":"Comput. Stand. Interfaces"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"315","DOI":"10.1016\/S0893-6080(96)00074-3","article-title":"Supervised learning extensions to the clam network","volume":"10","author":"Thacker","year":"1997","journal-title":"Neural Netw."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"197","DOI":"10.1007\/s11749-016-0481-7","article-title":"A random forest guided tour","volume":"25","author":"Biau","year":"2016","journal-title":"Test"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Sch\u00f6lkopf, B., Smola, A.J., and Bach, F. (2002). Learning with Kernels: Support Vector Machines, Regularization, Optimization, and Beyond, MIT Press.","DOI":"10.7551\/mitpress\/4175.001.0001"},{"key":"ref_34","unstructured":"Dietterich, T.G., and Kong, E.B. (1995). Machine Learning Bias, Statistical Bias, and Statistical Variance of Decision Tree Algorithms, Citeseer. Report."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"352","DOI":"10.1016\/S1532-0464(03)00034-0","article-title":"Logistic regression and artificial neural network classification models: A methodology review","volume":"35","author":"Dreiseitl","year":"2002","journal-title":"J. Biomed. Inform."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1111\/j.1540-5915.1993.tb00462.x","article-title":"Application of the back propagation neural network algorithm with monotonicity constraints for two-group classification problems","volume":"24","author":"Archer","year":"1993","journal-title":"Decis. Sci."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"1883","DOI":"10.4249\/scholarpedia.1883","article-title":"K-nearest neighbor","volume":"4","author":"Peterson","year":"2009","journal-title":"Scholarpedia"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1016\/S0950-7051(01)00154-X","article-title":"Clustered linear regression","volume":"15","author":"Ari","year":"2002","journal-title":"Knowl.-Based Syst."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Hastie, T., Tibshirani, R., and Friedman, J. (2009). Unsupervised learning. The Elements of Statistical Learning, Springer.","DOI":"10.1007\/978-0-387-84858-7"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"El Naqa, I., and Murphy, M.J. (2015). What is machine learning?. Machine Learning in Radiation Oncology, Springer.","DOI":"10.1007\/978-3-319-18305-3"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"1147","DOI":"10.1016\/0167-8655(95)00075-R","article-title":"A conceptual version of the k-means algorithm","volume":"16","author":"Ralambondrainy","year":"1995","journal-title":"Pattern Recognit. Lett."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"208","DOI":"10.1016\/j.datak.2006.01.013","article-title":"ST-DBSCAN: An algorithm for clustering spatial\u2013temporal data","volume":"60","author":"Birant","year":"2007","journal-title":"Data Knowl. Eng."},{"key":"ref_43","unstructured":"Wang, K., Zhang, J., Li, D., Zhang, X., and Guo, T. (2008). Adaptive affinity propagation clustering. arXiv."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Comaniciu, D., and Meer, P. (1999, January 20\u201327). Mean shift analysis and applications. Proceedings of the 7th IEEE International Conference on Computer Vision, Kerkyra, Greece.","DOI":"10.1109\/ICCV.1999.790416"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"542","DOI":"10.1109\/TNN.2009.2015974","article-title":"Semi-supervised learning (Chapelle, o. et al., eds.; 2006) [book reviews]","volume":"20","author":"Chapelle","year":"2009","journal-title":"IEEE Trans. Neural Netw."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1016\/j.optlaseng.2019.01.011","article-title":"Surface defect classification of steels with a new semi-supervised learning method","volume":"117","author":"Di","year":"2019","journal-title":"Opt. Lasers Eng."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Shinan, K., Alsubhi, K., Alzahrani, A., and Ashraf, M.U. (2021). Machine learning-based botnet detection in software-defined network: A systematic review. Symmetry, 13.","DOI":"10.3390\/sym13050866"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Fazakis, N., Kanas, V.G., Aridas, C.K., Karlos, S., and Kotsiantis, S. (2019). Combination of active learning and semi-supervised learning under a self-training scheme. Entropy, 21.","DOI":"10.3390\/e21100988"},{"key":"ref_49","first-page":"1","article-title":"Graph-based semi-supervised learning","volume":"8","author":"Subramanya","year":"2014","journal-title":"Synth. Lect. Artif. Intell. Mach. Learn."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Chapelle, O., and Zien, A. (2005, January 6\u20138). Semi-supervised classification by low density separation. Proceedings of the International Workshop on Artificial Intelligence and Statistics (PMLR), Bridgetown, Barbados.","DOI":"10.7551\/mitpress\/9780262033589.001.0001"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"1241","DOI":"10.1016\/j.drudis.2018.01.039","article-title":"The rise of deep learning in drug discovery","volume":"23","author":"Chen","year":"2018","journal-title":"Drug Discov. Today"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Albawi, S., Mohammed, T.A., and Al-Zawi, S. (2017, January 21\u201323). Understanding of a convolutional neural network. Proceedings of the 2017 International Conference on Engineering and Technology (ICET), Antalya, Turkey.","DOI":"10.1109\/ICEngTechnol.2017.8308186"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Lorencin, I., An\u0111eli\u0107, N., Mrzljak, V., and Car, Z. (2019). Genetic algorithm approach to design of multi-layer perceptron for combined cycle power plant electrical power output estimation. Energies, 12.","DOI":"10.3390\/en12224352"},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"2673","DOI":"10.1109\/78.650093","article-title":"Bidirectional recurrent neural networks","volume":"45","author":"Schuster","year":"1997","journal-title":"IEEE Trans. Sign. Process."},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Wang, W., Huang, Y., Wang, Y., and Wang, L. (2014, January 23\u201328). Generalized autoencoder: A neural network framework for dimensionality reduction. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops, Columbus, OH, USA.","DOI":"10.1109\/CVPRW.2014.79"},{"key":"ref_56","first-page":"1","article-title":"Convolutional deep belief networks on cifar-10","volume":"40","author":"Krizhevsky","year":"2010","journal-title":"Computers"},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"1464","DOI":"10.1109\/5.58325","article-title":"The self-organizing map","volume":"78","author":"Kohonen","year":"1990","journal-title":"Proc. IEEE"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Liao, Z., Chen, C., Ju, Y., He, C., Jiang, J., and Pei, Q. (2022). Multi-Controller Deployment in SDN-Enabled 6G Space\u2013Air\u2013Ground Integrated Network. Remote Sens., 14.","DOI":"10.3390\/rs14051076"},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1145\/2500468.2500473","article-title":"Software-defined networking","volume":"56","author":"Kirkpatrick","year":"2013","journal-title":"Commun. ACM"},{"key":"ref_60","doi-asserted-by":"crossref","first-page":"3542","DOI":"10.1109\/COMST.2018.2839348","article-title":"Comparative analysis of control plane security of SDN and conventional networks","volume":"20","author":"Abdou","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_61","unstructured":"O.N. Fundation (2022). Open Networking, O.N. Foundation."},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1145\/1355734.1355746","article-title":"OpenFlow: Enabling innovation in campus networks","volume":"38","author":"McKeown","year":"2008","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Kaur, K., Kaur, S., and Gupta, V. (2016, January 21\u201324). Flow statistics based load balancing in OpenFlow. Proceedings of the 2016 International Conference on Advances in Computing, Communications and Informatics (ICACCI), Jaipur, India.","DOI":"10.1109\/ICACCI.2016.7732075"},{"key":"ref_64","doi-asserted-by":"crossref","unstructured":"Cheema, A., Tariq, M., Hafiz, A., Khan, M.M., Ahmad, F., and Anwar, M. (2022). Prevention Techniques against Distributed Denial of Service Attacks in Heterogeneous Networks: A Systematic Review. Secur. Commun. Netw., 2022.","DOI":"10.1155\/2022\/8379532"},{"key":"ref_65","doi-asserted-by":"crossref","unstructured":"Huraj, L., Horak, T., Strelec, P., and Tanuska, P. (2021). Mitigation against DDoS Attacks on an IoT-Based Production Line Using Machine Learning. Appl. Sci., 11.","DOI":"10.3390\/app11041847"},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Wang, S., Gomez, K., Sithamparanathan, K., Asghar, M.R., Russello, G., and Zanna, P. (2021). Mitigating DDoS Attacks in SDN-Based IoT Networks Leveraging Secure Control and Data Plane Algorithm. Appl. Sci., 11.","DOI":"10.3390\/app11030929"},{"key":"ref_67","doi-asserted-by":"crossref","first-page":"11237","DOI":"10.1016\/j.ifacol.2020.12.354","article-title":"The vulnerability of securing IoT production lines and their network components in the Industry 4.0 concept","volume":"53","author":"Horak","year":"2020","journal-title":"IFAC-Pap. Online"},{"key":"ref_68","doi-asserted-by":"crossref","unstructured":"\u0160imon, M., Huraj, L., and Hor\u00e1k, T. (2018, January 12\u201314). DDoS reflection attack based on IoT: A case study. Proceedings of the Computer Science Online Conference, Las Vegas, NV, USA.","DOI":"10.1007\/978-3-319-91192-2_5"},{"key":"ref_69","doi-asserted-by":"crossref","first-page":"425","DOI":"10.1007\/s13369-017-2414-5","article-title":"DDoS attack detection and mitigation using SDN: Methods, practices, and solutions","volume":"42","author":"Bawany","year":"2017","journal-title":"Arab. J. Sci. Eng."},{"key":"ref_70","doi-asserted-by":"crossref","unstructured":"Wang, B., and Su, J. (2018). FlexMonitor: A flexible monitoring framework in SDN. Symmetry, 10.","DOI":"10.3390\/sym10120713"},{"key":"ref_71","doi-asserted-by":"crossref","unstructured":"Yang, Y.S., Lee, S.H., Chen, W.C., Yang, C.S., Huang, Y.M., and Hou, T.W. (2022). Securing SCADA Energy Management System under DDos attacks using token verification approach. Appl. Sci., 12.","DOI":"10.3390\/app12010530"},{"key":"ref_72","doi-asserted-by":"crossref","first-page":"2046","DOI":"10.1109\/SURV.2013.031413.00127","article-title":"A survey of defense mechanisms against distributed denial of service (DDoS) flooding attacks","volume":"15","author":"Zargar","year":"2013","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_73","doi-asserted-by":"crossref","first-page":"426","DOI":"10.1109\/TIFS.2011.2107320","article-title":"Low-rate DDoS attacks detection and traceback by using new information metrics","volume":"6","author":"Xiang","year":"2011","journal-title":"IEEE Trans. Inform. Forens. Secur."},{"key":"ref_74","doi-asserted-by":"crossref","first-page":"43920","DOI":"10.1109\/ACCESS.2020.2976609","article-title":"Low-rate DoS attacks, detection, defense, and challenges: A survey","volume":"8","author":"Zhijun","year":"2020","journal-title":"IEEE Access"},{"key":"ref_75","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.patrec.2014.07.019","article-title":"An empirical evaluation of information metrics for low-rate and high-rate DDoS attack detection","volume":"51","author":"Bhuyan","year":"2015","journal-title":"Pattern Recogn. Lett."},{"key":"ref_76","doi-asserted-by":"crossref","unstructured":"Phan, T.V., Gias, T.R., Islam, S.T., Huong, T.T., Thanh, N.H., and Bauschert, T. (2019, January 9\u201313). Q-MIND: Defeating stealthy DoS attacks in SDN with a machine-learning based defense framework. Proceedings of the 2019 IEEE Global Communications Conference (GLOBECOM), Waikoloa, HI, USA.","DOI":"10.1109\/GLOBECOM38437.2019.9013585"},{"key":"ref_77","first-page":"423","article-title":"Low rate DDoS Attack Identification and Defense using SDN based on Machine Learning Method","volume":"8","author":"Khamkar","year":"2021","journal-title":"Int. Res. J. Eng. Technol. (IRJET)"},{"key":"ref_78","doi-asserted-by":"crossref","first-page":"56","DOI":"10.1504\/IJSNET.2020.109720","article-title":"Machine learning based low-rate DDoS attack detection for SDN enabled IoT networks","volume":"34","author":"Cheng","year":"2020","journal-title":"Int. J. Sens. Netw."},{"key":"ref_79","doi-asserted-by":"crossref","unstructured":"Yin, W., Cui, Y., Qian, Q., Shen, G., Guo, C., and Li, S. (2021). DIAMOND: A Structured Coevolution Feature Optimization Method for LDDoS Detection in SDN-IoT. Wirel. Commun. Mob. Comput., 2021.","DOI":"10.1155\/2021\/9530274"},{"key":"ref_80","doi-asserted-by":"crossref","unstructured":"Sudar, K.M., and Deepalakshmi, P. (2022). Flow-Based Detection and Mitigation of Low-Rate DDOS Attack in SDN Environment Using Machine Learning Techniques. IoT and Analytics for Sensor Networks, Springer.","DOI":"10.1007\/978-981-16-2919-8_18"},{"key":"ref_81","doi-asserted-by":"crossref","first-page":"17404","DOI":"10.1109\/ACCESS.2020.2967478","article-title":"Low-rate DDoS attack detection based on factorization machine in software defined network","volume":"8","author":"Zhijun","year":"2020","journal-title":"IEEE Access"},{"key":"ref_82","doi-asserted-by":"crossref","unstructured":"Nugraha, B., and Murthy, R.N. (2020, January 10\u201312). Deep learning-based slow DDoS attack detection in SDN-based networks. Proceedings of the 2020 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), Madrid, Spain.","DOI":"10.1109\/NFV-SDN50289.2020.9289894"},{"key":"ref_83","doi-asserted-by":"crossref","first-page":"428","DOI":"10.1109\/JSAC.2021.3126053","article-title":"Performance and features: Mitigating the low-rate TCP-targeted DoS attack via SDN","volume":"40","author":"Tang","year":"2021","journal-title":"IEEE J. Select.Areas Commun."},{"key":"ref_84","doi-asserted-by":"crossref","unstructured":"Sun, W., Guan, S., Wang, P., and Wu, Q. (2022). A hybrid deep learning model based low-rate DoS attack detection method for software defined network. Trans. Emerg. Telecommun. Technol., 33.","DOI":"10.1002\/ett.4443"},{"key":"ref_85","doi-asserted-by":"crossref","unstructured":"Apostolovic, T., Stankovic, N., Milenkovic, K., and Stanisavljevic, Z. (2018, January 30\u201331). DDoSSim-System for Visual Representation of the Selected Distributed Denial of Service Attacks. Proceedings of the 2018 Zooming Innovation in Consumer Technologies Conference (ZINC), Novi Sad, Serbia.","DOI":"10.1109\/ZINC.2018.8448570"},{"key":"ref_86","unstructured":"(2022, February 17). jseidl.GoldenEye. Available online: https:\/\/www.kali.org\/tools\/goldeneye\/."},{"key":"ref_87","unstructured":"(2022, February 17). HULK. Mr4FX. Available online: https:\/\/allabouttesting.org\/hulk-ddos-tool-complete-installation-usage-with-examples\/."},{"key":"ref_88","unstructured":"Cloudflare (2021). Slowloris DDoS Attack, Cloudflare."},{"key":"ref_89","unstructured":"(2022, February 17). Cloudflare. Available online: https:\/\/www.cloudflare.com\/learning\/ddos\/ddos-low-and-slow-attack\/."},{"key":"ref_90","doi-asserted-by":"crossref","first-page":"1985","DOI":"10.1007\/s12652-018-0800-9","article-title":"Distributed denial of service (DDoS) attack mitigation in software defined network (SDN)-based cloud computing environment","volume":"10","author":"Bhushan","year":"2019","journal-title":"J. Ambient Intell. Human. Comput."},{"key":"ref_91","doi-asserted-by":"crossref","unstructured":"Ubale, T., and Jain, A.K. (2020). Survey on DDoS attack techniques and solutions in software-defined network. Handbook of Computer Networks and Cyber Security, Springer.","DOI":"10.1007\/978-3-030-22277-2_15"},{"key":"ref_92","doi-asserted-by":"crossref","first-page":"509","DOI":"10.1016\/j.comcom.2020.02.085","article-title":"New-flow based DDoS attacks in SDN: Taxonomy, rationales, and research challenges","volume":"154","author":"Singh","year":"2020","journal-title":"Comput. Commun."},{"key":"ref_93","doi-asserted-by":"crossref","unstructured":"Pashkov, V., Shalimov, A., and Smeliansky, R. (2014, January 28\u201329). Controller failover for SDN enterprise networks. Proceedings of the 2014 International Science and Technology Conference (Modern Networking Technologies)(MoNeTeC), Moscow, Russia.","DOI":"10.1109\/MoNeTeC.2014.6995594"},{"key":"ref_94","doi-asserted-by":"crossref","first-page":"55","DOI":"10.3233\/JHS-200630","article-title":"A two level security mechanism to detect a DDoS flooding attack in software-defined networks using entropy-based and C4. 5 technique","volume":"26","author":"Deepalakshmi","year":"2020","journal-title":"J. High Speed Netw."},{"key":"ref_95","doi-asserted-by":"crossref","unstructured":"Daha, M.Y., Zahid, M.S.M., Husain, K., and Ousta, F. (2021, January 19\u201320). Performance Evaluation of Software Defined Networks with Single and Multiple Link Failure Scenario under Floodlight Controller. Proceedings of the 2021 International Conference on Computing, Communication, and Intelligent Systems (ICCCIS), Greater Noida, India.","DOI":"10.1109\/ICCCIS51004.2021.9397125"},{"key":"ref_96","first-page":"11","article-title":"CDRA: A Community Detection based Routing Algorithm for Link Failure Recovery in Software Defined Networks","volume":"12","author":"Daha","year":"2021","journal-title":"(IJACSA) Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_97","doi-asserted-by":"crossref","unstructured":"Chen, K.Y., Junuthula, A.R., Siddhrau, I.K., Xu, Y., and Chao, H.J. (2016, January 17\u201319). SDNShield: Towards more comprehensive defense against DDoS attacks on SDN control plane. Proceedings of the 2016 IEEE Conference on Communications and Network Security (CNS), Philadelphia, PA, USA.","DOI":"10.1109\/CNS.2016.7860467"},{"key":"ref_98","doi-asserted-by":"crossref","first-page":"162","DOI":"10.1016\/j.compeleceng.2016.09.012","article-title":"An East-West interface for distributed SDN control plane: Implementation and evaluation","volume":"57","author":"Benamrane","year":"2017","journal-title":"Comput. Electr. Eng."},{"key":"ref_99","first-page":"8708","article-title":"Preemptive modelling towards classifying vulnerability of DDoS attack in SDN environment","volume":"10","author":"BN","year":"2020","journal-title":"Int. Electr. Comput. Eng."},{"key":"ref_100","doi-asserted-by":"crossref","unstructured":"He, C.H., Chang, B.Y., Chakraborty, S., Chen, C., and Wang, L.C. (2018, January 28\u201329). A zero flow entry expiration timeout p4 switch. Proceedings of the Symposium on SDN Research, Los Angeles, CA, USA.","DOI":"10.1145\/3185467.3190785"},{"key":"ref_101","doi-asserted-by":"crossref","unstructured":"Kandoi, R., and Antikainen, M. (2015, January 11\u201315). Denial-of-service attacks in OpenFlow SDN networks. Proceedings of the 2015 IFIP\/IEEE International Symposium on Integrated Network Management (IM), Ottawa, ON, Canada.","DOI":"10.1109\/INM.2015.7140489"},{"key":"ref_102","doi-asserted-by":"crossref","unstructured":"Isyaku, B., Mohd Zahid, M.S., Bte Kamat, M., Abu Bakar, K., and Ghaleb, F.A. (2020). Software Defined Networking Flow Table Management of OpenFlow Switches Performance and Security Challenges: A Survey. Future Internet, 12.","DOI":"10.3390\/fi12090147"},{"key":"ref_103","doi-asserted-by":"crossref","unstructured":"You, X., Feng, Y., and Sakurai, K. (2017, January 19\u201322). Packet in message based DDoS attack detection in SDN network using OpenFlow. Proceedings of the 2017 Fifth International Symposium on Computing and Networking (CANDAR), Aomori, Japan.","DOI":"10.1109\/CANDAR.2017.93"},{"key":"ref_104","doi-asserted-by":"crossref","unstructured":"Pascoal, T.A., Dantas, Y.G., Fonseca, I.E., and Nigam, V. (2017, January 29\u201331). Slow TCAM exhaustion DDoS attack. Proceedings of the IFIP International Conference on ICT Systems Security and Privacy Protection, Rome, Italy.","DOI":"10.1007\/978-3-319-58469-0_2"},{"key":"ref_105","doi-asserted-by":"crossref","first-page":"2383","DOI":"10.1007\/s11227-020-03323-w","article-title":"The DDoS attacks detection through machine learning and statistical methods in SDN","volume":"77","author":"Dehkordi","year":"2021","journal-title":"J. Supercomput."},{"key":"ref_106","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1080\/10824669.2018.1523734","article-title":"Receiver operating characteristic (ROC) area under the curve (AUC): A diagnostic measure for evaluating the accuracy of predictors of education outcomes","volume":"24","author":"Bowers","year":"2019","journal-title":"J. Educ. Stud. Placed Risk (JESPAR)"},{"key":"ref_107","first-page":"229","article-title":"Reinforcement Learning: An Introduction by Richard S. Sutton and Andrew G. Barto, Adaptive Computation and Machine Learning Series; MIT Press (Bradford Book), Cambridge, Mass., 1998, pp. 58\u2013322, ISBN 0-262-19398-1","volume":"17","author":"Andrew","year":"1999","journal-title":"Robotica"},{"key":"ref_108","doi-asserted-by":"crossref","unstructured":"De Oliveira, R.L.S., Schweitzer, C.M., Shinoda, A.A., and Prete, L.R. (2014, January 2\u20134). Using mininet for emulation and prototyping software-defined networks. Proceedings of the 2014 IEEE Colombian conference on communications and computing (COLCOM), Bogota, Colombia.","DOI":"10.1109\/ColComCon.2014.6860404"},{"key":"ref_109","doi-asserted-by":"crossref","unstructured":"Wette, P., Dr\u00e4xler, M., Schwabe, A., Wallaschek, F., Zahraee, M.H., and Karl, H. (2014, January 2\u20134). Maxinet: Distributed emulation of software-defined networks. Proceedings of the 2014 IFIP Networking Conference, Trondheim, Norway.","DOI":"10.1109\/IFIPNetworking.2014.6857078"},{"key":"ref_110","unstructured":"(2022, March 23). Open Network. Available online: https:\/\/opennetworking.org\/onos\/."},{"key":"ref_111","unstructured":"(2022, March 23). Shekyan. Available online: https:\/\/www.kali.org\/tools\/slowhttptest\/."},{"key":"ref_112","unstructured":"(2022, March 23). Cup. Available online: http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html."},{"key":"ref_113","first-page":"3840","article-title":"DServ-LB: Dynamic server load balancing algorithm","volume":"1","author":"Deepalakshmi","year":"2018","journal-title":"Int. J. Commun. Syst."},{"key":"ref_114","unstructured":"(2022, March 23). Scapy. Available online: https:\/\/scapy.net\/."},{"key":"ref_115","doi-asserted-by":"crossref","first-page":"1025","DOI":"10.1111\/mice.12313","article-title":"Structural damage detection with automatic feature-extraction through deep learning","volume":"32","author":"Lin","year":"2017","journal-title":"Comput.-Aided Civil Infrastruct. Eng."},{"key":"ref_116","doi-asserted-by":"crossref","unstructured":"Taud, H., and Mas, J. (2018). Multilayer perceptron (MLP). Geomatic Approaches for Modeling Land Change Scenarios, Springer.","DOI":"10.1007\/978-3-319-60801-3_27"},{"key":"ref_117","doi-asserted-by":"crossref","first-page":"1627","DOI":"10.1016\/j.jprocont.2009.07.011","article-title":"Fault detection and diagnosis in process data using one-class support vector machines","volume":"19","author":"Mahadevan","year":"2009","journal-title":"J. Process Control"},{"key":"ref_118","unstructured":"Andersson, O.O. (2022, January 15). Available online: https:\/\/github.com\/Ogglas\/Orignal-Slowloris-HTTP-DoS."},{"key":"ref_119","doi-asserted-by":"crossref","unstructured":"Roopak, M., Tian, G.Y., and Chambers, J. (2019, January 7\u20139). Deep learning models for cyber security in IoT networks. Proceedings of the 2019 IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA.","DOI":"10.1109\/CCWC.2019.8666588"},{"key":"ref_120","doi-asserted-by":"crossref","unstructured":"Khooi, X.Z., Csikor, L., Kang, M.S., and Divakaran, D.M. (2020, January 10\u201314). In-Network Defense against AR-DDoS Attacks. Proceedings of the SIGCOMM\u201920 Poster and Demo Sessions, Online.","DOI":"10.1145\/3405837.3411375"},{"key":"ref_121","doi-asserted-by":"crossref","unstructured":"Kuzmanovic, A., and Knightly, E.W. (2003, January 25\u201329). Low-rate TCP-targeted denial of service attacks: The shrew vs. the mice and elephants. Proceedings of the 2003 Conference on Applications, Technologies, Architectures, and Protocols for Computer Communications, Karlsruhe, Germany.","DOI":"10.1145\/863955.863966"}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/14\/8\/1563\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:58:51Z","timestamp":1760140731000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/14\/8\/1563"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,29]]},"references-count":121,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2022,8]]}},"alternative-id":["sym14081563"],"URL":"https:\/\/doi.org\/10.3390\/sym14081563","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,29]]}}}