Software-defined DDoS Detection with Information Entropy Analysis and Optimized Deep Learning

Ying Liu, Ming Shen

Research output: Contribution to journalJournal articleResearchpeer-review

4 Citations (Scopus)


Software Defined Networking (SDN) decouples the control plane and the data plane and solves the difficulty of new services deployment. However, the threat of a single point of failure is also introduced at the same time. Attackers usually launch distributed denial of service (DDoS) attacks towards the controller through switches. However, it is difficult for the traditional DDoS detection methods to balance the relationship between accuracy and efficiency. Statistical analysis-based methods have low accuracy, while machine learning-based methods have low efficiency and high training cost. In this paper, a two-level DDoS attack detection method based on information entropy and deep learning is proposed. First, the information entropy detection mechanism detects suspicious components and ports in coarse granularity. Then, a fine-grained packet-based detection mechanism is executed by the convolutional neural network (CNN) model to distinguish normal traffic from suspicious traffic. Finally, the controller performs the defense strategy to intercept the attack. The experiment results indicate that the detection accuracy of the proposed method reaches 98.98%, which shows the potential of detecting DDoS attack traffic effectively in the SDN environment.

Original languageEnglish
JournalFuture Generation Computer Systems
Pages (from-to)99-114
Number of pages16
Publication statusPublished - Apr 2022


  • DDoS attack detection
  • Deep learning
  • Information entropy
  • Software Defined Network


Dive into the research topics of 'Software-defined DDoS Detection with Information Entropy Analysis and Optimized Deep Learning'. Together they form a unique fingerprint.

Cite this