IDEAS home Printed from https://ideas.repec.org/a/gam/jdataj/v11y2026i8p195-d2008356.html

A Multi-Class SDN Intrusion Detection Dataset with Synchronized OpenFlow Control-Plane Telemetry

Author

Listed:
  • Juliana Arévalo-Herrera

    (Departamento de Informática y Estadística, Universidad Rey Juan Carlos, 28933 Móstoles, Spain)

  • Jorge E. Camargo

    (Departamento Ingeniería de Sistemas e Industrial, Universidad Nacional de Colombia, Bogotá 111321, Colombia)

  • José Ignacio Martínez Torre

    (Departamento de Informática y Estadística, Universidad Rey Juan Carlos, 28933 Móstoles, Spain)

  • Juan Marcos Ramírez

    (IMDEA Networks Institute, 28918 Madrid, Spain)

  • Tatiana Zona-Ortiz

    (Ingeniería de Telecomunicaciones, Universidad Santo Tomás, Bogotá 111321, Colombia)

Abstract

Software-Defined Networking (SDN) separates the control and data planes, introducing a logically centralized controller that is itself a high-value attack target. Despite growing interest in SDN intrusion detection, publicly available datasets either restrict evaluation to binary normal-vs-DDoS classification or lack control-plane telemetry, leaving multi-class detection of SDN-architectural attacks without a dedicated benchmark. This work presents LAN-SDN-NIDS, a publicly available, multi-class flow-level dataset of 1,125,059 records generated in a fully containerized Containernet/OpenDaylight testbed across five standard network topologies. Each flow record combines 29 traffic-level features with 11 control-plane-aware metrics—including Packet-In and Flow-Mod counts and first-seen delay. The dataset covers five attack classes in two categories: three that exploit SDN control-plane mechanisms (link fabrication, host injection, and port hijack) alongside DDoS and port scan, plus normal traffic. An XGBoost classifier trained on the full feature set achieved a macro F1 of 0.94; an ablation study showed that removing OpenFlow features causes link fabrication F1 to collapse from 0.97 to 0.19, indicating that control-plane telemetry is decisive for detecting SDN-architectural attacks under the conditions evaluated. A UMAP embedding is consistent with class separability, except for a structural overlap between host injection and normal traffic attributable to their shared ARP protocol.

Suggested Citation

  • Juliana Arévalo-Herrera & Jorge E. Camargo & José Ignacio Martínez Torre & Juan Marcos Ramírez & Tatiana Zona-Ortiz, 2026. "A Multi-Class SDN Intrusion Detection Dataset with Synchronized OpenFlow Control-Plane Telemetry," Data, MDPI, vol. 11(8), pages 1-22, August.
  • Handle: RePEc:gam:jdataj:v:11:y:2026:i:8:p:195-:d:2008356
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/2306-5729/11/8/195/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/2306-5729/11/8/195/
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jdataj:v:11:y:2026:i:8:p:195-:d:2008356. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.