Comparative Analysis of Machine Learning Algorithms for DDoS Detection in SDN Topology

Authors

  • Marwa Alsayed Rshad
  • Mahmoud Mohammed Alzalabani
  • El Said Ahmed Marzouk
  • Haitham Mahmoud Abdelghany

Keywords:

Software-Defined Networking (SDN), Random Forest, Flow-Level Feature Analysis, DDoS Attack Mitigation, Tree Topology.

Abstract

Software-Defined Networking (SDN) is network control centralized, rendering the controller susceptible to a number of attacks. The Distributed Denial of Service (DDoS) attack is one of the most critical risks and it overwhelms the target with false traffic denying any real user the right to use the services. A number of techniques, such as traffic filtering, anomaly-based systems, and machine learning (ML) algorithms are used to identify and prevent such attacks. This paper has gathered a network traffic data to perform training and testing of four machine learning algorithms: Support Vector Machine, Naive Bayes, Decision Tree, and Random Forest. Five constructed features were used: Speed of Flow Entry (SFE), Speed of Source IP (SSIP), Ratio of Flow Pair (RFIP), and the standard deviations of flow packets/bytes (SDFP/SDFB), across five different data split ratios (90:10, 80:20, 70:30, 60:40, and 50:50). The algorithms were evaluated using cross-validation, Accuracy, Precision, Recall/Detection Rate (DR), F1, False Detection Rate (FDR), and AUC metrics. The results demonstrated that all ML algorithms effectively detected DDoS attacks with high accuracy; however, the Random Forest algorithm achieved the best performance, reaching 99.99% accuracy at the 80:20 split ratio.

Downloads

Published

2026-06-14

How to Cite

Rshad, M. A., Alzalabani, M. M., Marzouk, E. S. A., & Abdelghany, H. M. (2026). Comparative Analysis of Machine Learning Algorithms for DDoS Detection in SDN Topology . International Journal of Artificial Intelligence and Machine Learning, 6(5s), 956–986. Retrieved from https://svedbergopen.com/index.php/ijaiml/article/view/658