Distributed denial of service detection and mitigation in software-defined networking-enabled software-defined wide area networks

M Mohamed Musa T Tan Fong Ang Y Yen-Lin Chen U Uzair Aslam Bhatti C Chin Soon Ku Y Yu Luo (Macau Centre for Research and Development in Chinese Medicine, State Key Laboratory of Mechanism and Quality of Chinese Medicine, Institute of Chinese Medical Sciences) J Jiahui Chen L Lip Yee Por

Abstract

Software-defined wide area networks (SD-WAN), empowered by software-defined networking (SDN) technology, offer unparalleled flexibility and efficiency in wireless communication. However, their integration introduces new security challenges, particularly in mitigating distributed denial of service (DDoS) attacks. In this paper, we propose an advanced security framework tailored to SDN-enabled SD-WAN. A dataset collected during experiments was used for training and testing the model’s performance. Our framework leverages machine learning algorithms to detect and classify DDoS attacks targeting SD-WAN controllers, considering the environment’s unique characteristics. We develop adaptive machine learning model capable of accurately discerning high-rate and low-rate DDoS attacks, enhancing the network’s resilience against sophisticated threats. Results from controlled experiments show promise for real-world deployment, though further validation is needed. Our results highlight the framework’s ability to adapt to dynamic network conditions and provide robust security for SDN-enabled SD-WAN. Our adaptive model integrates RF and DT explicitly for SD-WAN contexts, achieving 99.97% accuracy for high-rate attacks and 99.96% for low-rate attacks. Our QT-PCA preprocessing pipeline reduces dimensionality while preserving performance, and PACKET_IN event-triggered mitigation enables dynamic response. This method significantly enhances security solutions’ accuracy, ensuring robust DDoS attack detection in SD-WAN environments. Additionally, by leveraging the SD-WAN architecture’s efficiency, our approach optimizes network performance, underscoring its efficacy and practicality in enhancing security and efficiency.

Article Details

Journal PLoS ONE
Volume / Issue Vol. 21, Issue 5
Published May 12, 2026
Pages e0346673
ISSN 1932-6203
Publisher Public Library of Science

Journal Info

PLoS ONE

Public Library of Science

ISSN: 1932-6203 Open Access Health Sciences

Authors (8)

M

Mohamed Musa

T

Tan Fong Ang

Y

Yen-Lin Chen

U

Uzair Aslam Bhatti

C

Chin Soon Ku

Y

Yu Luo

Macau Centre for Research and Development in Chinese Medicine, State Key Laboratory of Mechanism and Quality of Chinese Medicine, Institute of Chinese Medical Sciences

J

Jiahui Chen

L

Lip Yee Por