📖 ABSTRACT/OVERVIEW
Software-defined networking introduces a centralised control plane that, while enabling programmable network management, creates a high-value target for denial-of-service and control plane saturation attacks, and the performance of machine learning-based intrusion detection systems adapted for SDN-specific attack patterns requires empirical characterisation. This study empirically evaluated seven machine learning algorithms for intrusion detection in SDN environments, addressing a gap in comparative evaluation using SDN-specific attack datasets. Random Forest, XGBoost, Support Vector Machine, K-Nearest Neighbour, Decision Tree, Naive Bayes, and a deep neural network were trained and evaluated on the InSDN dataset, a benchmark containing normal SDN traffic and six SDN-specific attack categories. Feature selection was performed using SHAP values to identify the 15 most discriminative features from 83 available network flow features. The Random Forest classifier achieved the highest overall detection accuracy at 98.7 percent, followed by XGBoost at 98.2 percent. The deep neural network achieved 97.4 percent accuracy but with a training time 14 times longer than Random Forest. Naive Bayes performed worst at 84.3 percent. False positive rate was lowest for XGBoost at 0.9 percent. Cross-validation F1-scores were stable within plus or minus 0.3 percent across five folds, confirming generalisation. Model inference latency on a commodity server reached 1,200 predictions per second for Random Forest, suitable for real-time integration with OpenDaylight SDN controllers. The study fills an empirical gap by providing a comparative benchmark directly applicable to SDN deployments at Nigerian universities.
Keywords: intrusion detection, software-defined networking, machine learning, Random Forest, SDN security
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬