Exploring Rapid Detection of DDoS Attack in SDN Using Machine Learning Algorithms With the Classification Technique

Abstract
An emerging technology called software-defined networking (SDN) brings programmability and centralized control to future network design. Operators can design monitor and manage the network, as well as identify malicious traffic and failures thanks to the programmable console architecture. Notwithstanding these benefits, the SDN control plane is still susceptible to security risks, particularly distributed denial-of-service (DDoS) attacks, which have the potential to bring down the entire network. This study thoroughly assesses DDoS detection techniques for SDN controllers, focusing on dataset-based analysis instead of real-time experiments that could be impacted by hardware anomalies. To guarantee reproducibility and transparency, the KNIME analytics platform with a visual workflow environment was utilized. To differentiate between malicious floods and legitimate surges, flow-level features like packet volume byte volume and flow duration were investigated. XGBoost outperformed the other seven tested algorithms with an accuracy of 99.20% and a latency of 8.2 ms. These findings demonstrate that sophisticated machine learning (ML) models, when paired with SDN-specific feature analysis, provide precise, scalable, and efficient DDoS detection solutions. Random Forest (RF) came in second with 98.40% accuracy, while the Decision Tree excelled in efficiency, processing flows in 4.1 ms. Overall, the results show that KNIMEs no-code workflow framework can offer productionlevel DDoS detection comparable to conventional code-based techniques, providing a workable and extremely accurate way to safeguard programmable networks.
Keywords: DDoS, KNIME, Machine Learning, Software DeWined Network.

Author(s): Sudhir Bhagat*, Himanshu Gupta, Ashish Seth
Volume: 7 Issue: 3 Pages: 1797-1809
DOI: https://doi.org/10.47857/irjms.2026.v07i03.010756