CORTEXA
← Browse
crossrefApplied Sciences2026-06-19Cited by 0

Impact of Network Topology on Machine Learning-Based DDoS and Anomaly Detection in Software-Defined Networks

Łukasz Bakuła, Andrzej Jasinski

The development of Software-Defined Networks (SDNs) introduces new challenges in network security, particularly in detecting Distributed Denial of Service (DDoS) attacks and network anomalies. Due to the centralized architecture of SDN, traditional detection methods are often insufficient in dynamic environments. Therefore, machine learning techniques are increasingly applied to improve detection effectiveness. This paper analyzes the impact of network topology on the performance of machine learning-based detection methods in SDN environments. A controlled experimental setup based on the RYU controller and OpenFlow 1.3 was implemented using Mininet. Two network topologies (linear and hierarchical) were evaluated under multiple attack scenarios, including TCP SYN flood and TCP/UDP port scanning. Two supervised learning models, Random Forest (RF) and K-Nearest Neighbors (KNN), were implemented and compared using standard evaluation metrics: accuracy, precision, recall, F1-score, and detection time. The results show that Random Forest significantly outperforms KNN, achieving up to 100% accuracy and detection times as low as 4.24 s, while KNN exhibits lower stability and reduced recall in anomaly detection scenarios. The study demonstrates that network topology has a measurable impact on both detection performance and latency. The observed effects varied across attack scenarios and machine learning models. Hierarchical topology generally improved detection sensitivity in DDoS scenarios, while linear topology often enabled lower detection latency during selected anomaly detection experiments. The results indicate that both machine learning model selection and network topology should be jointly considered when designing intrusion detection systems for SDN environments. These findings contribute to improving the effectiveness and responsiveness of security mechanisms in modern programmable networks.

View free PDFSource page

Related papers

crossrefApplied Sciences2025-08-21Cited by 6

Machine Learning-Based Prediction of Autism Spectrum Disorder and Discovery of Related Metagenomic Biomarkers with Explainable AI

Mustafa Temiz, Burcu Bakir-Gungor, Nur Ersoz, Malik Yousef

Background: Autism spectrum disorder (ASD) is a complex neurodevelopmental disorder characterized by social communication deficits and repetitive behaviors. Recent studies have suggested that gut microbiota may play a role in the pathophysiology of ASD. This study aims to develop…

View free PDFSource page
crossrefApplied Sciences2025-09-20Cited by 2

Machine Learning-Based Data Quality Assessment for the Textile and Clothing Digital Product Passport

Estrela Ferreira Cruz, Pedro Silva, Sérgio Serra, Rodrigo Rodrigues, Marcelo Alves, João Oliveira, et al.

Transparency in business practices is essential for sustainability, ensuring that resources are used responsibly and that environmental and social impacts are properly measured and monitored, allowing the end consumer to make informed purchasing decisions without feeling cheated.…

View free PDFSource page
crossrefApplied Sciences2026-03-17

A Study on Machine Learning-Based Cost Estimation Models for AI Training Data Construction

Yoon-Seok Ko, Bong Gyou Lee

This study proposes an explainable machine learning framework for estimating the total project cost (TPC) of AI training-data construction, where cost information is difficult to structure due to heterogeneous workflows and quality requirements. Using 386 public AI training-data…

View free PDFSource page
crossrefApplied Sciences2026-07-18

Rigorous Evaluation of Machine Learning Intrusion Detection for Water Treatment Systems on SWaT Network Traffic

Sebastian Mesca, Emil Pricop, Grigore Stamatescu

Intrusion detection systems (IDSs) for industrial control networks are commonly evaluated using random stratified splits, placing rows from every recorded attack in both training and test sets. Although convenient, this practice measures a model’s ability to recognise repetitions…

View free PDFSource page
crossrefApplied Sciences2026-01-06

A Stacking-Based Ensemble Model for Multiclass DDoS Detection Using Shallow and Deep Machine Learning Algorithms

Eduardo Angulo, Leonardo Lizcano, Jose Marquez

Distributed Denial-of-Service (DDoS) attacks remain a significant threat to the stability and reliability of modern networked systems. This study presents a hierarchical stacking ensemble that integrates multiple Shallow Machine Learning (S-ML) and Deep Machine Learning (D-ML) al…

View free PDFSource page
crossrefApplied Sciences2025-07-30Cited by 3

The Choice of Training Data and the Generalizability of Machine Learning Models for Network Intrusion Detection Systems

Marcin Iwanowski, Dominik Olszewski, Waldemar Graniszewski, Jacek Krupski, Franciszek Pelc

Network Intrusion Detection Systems (NIDS) driven by Machine Learning (ML) algorithms are usually trained using publicly available datasets consisting of labeled traffic samples, where labels refer to traffic classes, usually one benign and multiple harmful. This paper studies th…

View free PDFSource page