IDEAS home Printed from https://ideas.repec.org/a/gam/jftint/v15y2023i12p401-d1299181.html
   My bibliography  Save this article

Distributed Denial of Service Classification for Software-Defined Networking Using Grammatical Evolution

Author

Listed:
  • Evangelos D. Spyrou

    (Department of Informatics and Telecommunications, University of Ioannina, 47150 Arta, Greece)

  • Ioannis Tsoulos

    (Department of Informatics and Telecommunications, University of Ioannina, 47150 Arta, Greece)

  • Chrysostomos Stylios

    (Department of Informatics and Telecommunications, University of Ioannina, 47150 Arta, Greece
    Industrial Systems Institute, Athena Research Center, 26504 Patras, Greece)

Abstract

Software-Defined Networking (SDN) stands as a pivotal paradigm in network implementation, exerting a profound influence on the trajectory of technological advancement. The critical role of security within SDN cannot be overstated, with distributed denial of service (DDoS) emerging as a particularly disruptive threat, capable of causing large-scale disruptions. DDoS operates by generating malicious traffic that mimics normal network activity, leading to service disruptions. It becomes imperative to deploy mechanisms capable of distinguishing between benign and malicious traffic, serving as the initial line of defense against DDoS challenges. In addressing this concern, we propose the utilization of traffic classification as a foundational strategy for combatting DDoS. By categorizing traffic into malicious and normal streams, we establish a crucial first step in the development of effective DDoS mitigation strategies. The deleterious effects of DDoS extend to the point of potentially overwhelming networked servers, resulting in service failures and SDN server downtimes. To investigate and address this issue, our research employs a dataset encompassing both benign and malicious traffic within the SDN environment. A set of 23 features is harnessed for classification purposes, forming the basis for a comprehensive analysis and the development of robust defense mechanisms against DDoS in SDN. Initially, we compare GenClass with three common classification methods, namely the Bayes, K-Nearest Neighbours (KNN), and Random Forest methods. The proposed solution improves the average class error, demonstrating 6.58% error as opposed to the Bayes method error of 32.59%, KNN error of 18.45%, and Random Forest error of 30.70%. Moreover, we utilize classification procedures based on three methods based on grammatical evolution, which are applied to the aforementioned data. In particular, in terms of average class error, GenClass exhibits 6.58%, while NNC and FC2GEN exhibit average class errors of 12.51% and 15.86%, respectively.

Suggested Citation

  • Evangelos D. Spyrou & Ioannis Tsoulos & Chrysostomos Stylios, 2023. "Distributed Denial of Service Classification for Software-Defined Networking Using Grammatical Evolution," Future Internet, MDPI, vol. 15(12), pages 1-13, December.
  • Handle: RePEc:gam:jftint:v:15:y:2023:i:12:p:401-:d:1299181
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/1999-5903/15/12/401/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/1999-5903/15/12/401/
    Download Restriction: no
    ---><---

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:15:y:2023:i:12:p:401-:d:1299181. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.