Design and Implementation of a Novel Machine Learning Framework for DDoS Attack Detection and Mitigation in SDNs for IoT Environments
DOI:
https://doi.org/10.51483/IJAIML.6.8s.2026.1146-1156Keywords:
Distributed denial-of-service; Internet of Things; Software-defined networking; Machine learning; Anomaly detection; OpenFlow; Adaptive mitigationAbstract
With the emergence of applications of Internet of Things (IoT) that are based on Software-Defined Networking (SDN), there is a flexible but insecure environment for distributed denial-of-service attacks that can saturate links, switches, controllers, or services. A recently proposed machine-learning framework enables the real-time IoT traffic monitoring, flow-level preprocessing and feature engineering, hybrid threat detection, and adaptive SDN mitigation, and the application of security/privacy controls to detect and mitigate hybrid threats in IoT-enabled SDN. The two-algorithm implementation examines Random Forest and XGBoost, while the framework retains an anomaly component for uncharacterized behaviors. Besides, the paper employs OpenFlow statistics for light-weight monitoring and the controller translates the model decisions into graduated actions, such as rate limiting, flow dropping, rerouting, and isolation of devices, and a reproducible Mininet-based evaluation protocol is defined based on the accuracy, precision, recall, F1-score, ROC-AUC, false-positive rate, detection latency, controller overhead, and network recovery indicators. In the controlled prototype implementation, Random Forest and XGBoost achieved 95.40% and 95.38% accuracy, respectively, with ROC-AUC values of 98.22% and 98.20%. These classifier-level measurements support the two-algorithm implementation, while complete controller and network-level validation remains to be carried out in Mininet/SDN. The design satisfies all objectives in the doctoral synopsis and can be used as a basis for implementation.





