Improved K-means-based solution for detecting DDoS attacks in SDN

Haizhong Qian,Lili Cai
DOI: https://doi.org/10.1016/j.phycom.2024.102318
IF: 2.379
2024-02-19
Physical Communication
Abstract:Software Defined Networking (SDN) is a change to the traditional network, which can better face the complex network scenarios and meet the future network development needs. However, SDN faces many network security problems in the process of development, among which distributed denial-of-service (DDoS) attacks on SDN cause the most serious problem of communication paralysis. For the problem of unstable detection accuracy based on K-means algorithm detection scheme, a detection scheme based on density selection and mutual information improvement K-means algorithm (MIK-means) is proposed, which can well improve the stability and accuracy of the detection effect. Through a large number of experimental results show that the detection scheme maintains an average accuracy of more than 96% under different attack types and rates, while the detection scheme also maintains 5 6s from response to completion of mitigation, which well reduces the computational overhead.
telecommunications,engineering, electrical & electronic
What problem does this paper attempt to address?