CORTEXA
← Browse
crossrefFuture Internet2026-02-19Cited by 0

A Systematic Review of Machine-Learning-Based Detection of DDoS Attacks in Software-Defined Networks

Surendren Ganeshan, R Kanesaraj Ramasamy

Software-Defined Networking (SDN) has emerged as a fundamental architecture for future Internet systems by enabling centralized control, programmability, and fine-grained traffic management. However, the logical centralization of the SDN control plane also introduces critical vulnerabilities, particularly to Distributed Denial-of-Service (DDoS) attacks that can severely disrupt network availability and performance. To address these challenges, machine-learning (ML) techniques have been increasingly adopted to enable intelligent, adaptive, and data-driven DDoS detection mechanisms within SDN environments. This study presents a PRISMA-guided systematic literature review of recent ML-based approaches for DDoS detection in SDN-based networks. A comprehensive search of IEEE Xplore, ACM Digital Library, ScienceDirect, and Google Scholar identified 38 primary studies published between 2021 and 2025. The selected studies were systematically analyzed to examine learning paradigms, experimental environments, evaluation metrics, datasets, and emerging architectural trends. The synthesis reveals that while single machine-learning classifiers remain dominant in the literature, hybrid and ensemble-based approaches are increasingly adopted to improve detection robustness under dynamic and high-volume traffic conditions. Experimental evaluations are predominantly conducted using SDN emulation platforms such as Mininet integrated with controllers, including Ryu and OpenDaylight, with performance commonly measured using accuracy, precision, recall, and F1 score, alongside emerging system-level metrics such as detection latency and controller resource utilization. Public datasets, including CICIDS2017, CICDDoS2019, and InSDN, are widely used, although a significant portion of studies rely on custom SDN-generated datasets to capture control-plane-specific behaviors. Despite notable advances in detection accuracy, several challenges persist, including limited generalization to low-rate and unknown attacks, dependency on synthetic traffic, and insufficient validation under real-time operational conditions. Based on the synthesized findings, this review highlights key research directions toward intelligent, scalable, and resilient DDoS defense mechanisms for future Internet architectures, emphasizing adaptive learning, lightweight deployment, and integration with programmable networking infrastructures.

View free PDFSource page

Related papers

crossrefFuture Internet2026-02-21Cited by 4

Machine Learning-Driven Intrusion Detection for Securing IoT-Based Wireless Sensor Networks

Yirga Yayeh Munaye, Abebaw Demelash Gebeyehu, Li-Chia Tai, Zemenu Alem Abebe, Aeneas Bekele Workneh, Robel Berie Tarekegn, et al.

Wireless sensor networks (WSNs) have become a critical component of modern Internet of Things (IoT) infrastructures; however, their constrained resources and distributed deployment expose them to various cyber threats. In this work, we present a machine learning-driven intrusion…

View free PDFSource page
crossrefFuture Internet2026-04-27Cited by 1

Enhancing Network Intrusion Detection with Quantum Machine Learning: A Comprehensive Survey of Methods, Metrics, and Applications

Antanios Kaissar, Ali Bou Nassif, Ahmed Bouridane

Quantum computing introduces new computational capabilities that can support advanced cybersecurity solutions when combined with machine learning. In recent years, quantum machine learning (QML) has emerged as a promising approach for enhancing network intrusion detection systems…

View free PDFSource page
crossrefFuture Internet2026-03-07

Sentiment Classification of Amazon Product Reviews Based on Machine and Deep Learning Techniques: A Comparative Study

Eman Daraghmi, Noora Zyadeh

Sentiment classification plays a crucial role in analyzing customer feedback to identify market trends, enhance product recommendations, and improve customer satisfaction. This study focuses on sentiment analysis of Amazon reviews using two major datasets—Fine Food Reviews and Un…

View free PDFSource page
crossrefFuture Internet2026-05-14

Entropy-Based Spectrum Sensing for Cognitive Radio Networks Using Machine Learning and Software Defined Radio

Ernesto Cadena Muñoz, Diego Armando Giral, César Hernández Suárez

Efficient spectrum sensing remains a main challenge for Cognitive Radio Networks (CRNs), especially in a wireless environment where methods like energy detection have high uncertainty. This work proposes an entropy-based spectrum-sensing system enhanced with machine-learning algo…

View free PDFSource page
crossrefFuture Internet2026-05-28

Data-Driven and Machine Learning-Based Analysis of Handover Behavior and Network Stability in Mobile Networks

Akzhibek Amirova, Aliya Abdiraman, Laura Aldasheva, Ibraheem Shayea, Didar Yedilkhan, Akhmet Tussupov

Handover management is a fundamental process in modern mobile networks, ensuring service continuity under user mobility. However, the relationship between network conditions and handover behavior remains insufficiently understood under real-world measurement conditions. This stud…

View free PDFSource page
crossrefFuture Internet2026-01-07Cited by 7

A Multiclass Machine Learning Framework for Detecting Routing Attacks in RPL-Based IoT Networks Using a Novel Simulation-Driven Dataset

Niharika Panda, Supriya Muthuraman

The use of resource-constrained Low-Power and Lossy Networks (LLNs), where the IPv6 Routing Protocol for LLNs (RPL) is the de facto routing standard, has increased due to the Internet of Things’ (IoT) explosive growth. Because of the dynamic nature of IoT deployments and the lack…

View free PDFSource page