QOS-PRESERVING MULTI-ALGORITHM INTRUSION DETECTION AND MITIGATION FOR SOFTWARE DEFINED NETWORKS
DOI:
https://doi.org/10.51483/IJAIML.6.11s.2026.1754-1767Keywords:
Intrusion Detection Systems (IDS), Software Defined Networks (SDN),Machine Learning for Network Security,XGBoost and CatBoost Ensemble Methods,Quality of Service (QoS) Preservation, Real-Time Threat Mitigation, NetworkFlow Classification, Controller-Side Anomaly DetectionAbstract
Software Defined Networks (SDNs) increase programmability at the cost of expanding the attack surface and challenging traditional intrusion detection with dynamic traffic patterns and strict real-time demands. This paper compares six classification models Naïve Bayes, Decision Tree, Random Forest, XGBoost, and CatBoost models, with the InSDN dataset, which is based on SDN traffic on an emulated Mininet setup. Experimental protocol uses feature engineering at the flow level, traditional pre-processing methods, stratified sampling to maintain balance of classes and various repeat trials, which increases the resiliency and reliability of the overall evaluation structure. XGBoost is the overall leading classifier with 100% DDoS detection and 98.46% DoS detection, with the ability to perfectly distinguish Normal traffic; the minority (BFA, Web Attack, U2R) classes still report low performance as these are partially imbalanced. In addition to classification accuracy and inference latency, this work combines a controller-side QoS enforcement loop that translates alerts into one of selective flow actions of drop, redirect, rate-limit, and high-priority queueing based on composite severity and application priority scores. This QoS-aware mitigation maintains the performance of applications that require low latency and mitigates threats. Contributions of this research are: (i) exhaustive SDN-specific multi-algorithm benchmarking; (ii) a specific analysis of errors per class; (iii) a QoS-preserving alert-to-policy mechanism that enables this to be implemented in operational deployments; and (iv) a highly reproducible evaluation platform. The results are used to inform the choices of ML-driven IDS and to provide inspiration that imbalance mitigation, online learning and controller-integrated service-aware defences are further areas to be explored.





