Hierarchical SDN DDoS Detection in IoT Networks via Shannon Entropy and Adaptive Thresholding
DOI:
https://doi.org/10.25170/jurnalelektro.v19i1.8311Keywords:
DDOS attack, Internet of Think, SDN, Shannon EntropyAbstract
Internet of Things (IoT) devices integrated with Software-Defined Networking (SDN) have increased network flexibility and centralized management. However, this architecture is increasingly vulnerable to volumetric Distributed Denial-of-Service (DDoS) attacks, which can degrade Quality of Service (QoS) and disrupt critical network services. Existing entropy-based detection approaches generally rely on flat SDN topologies and static thresholds, resulting in delayed attack isolation and increased false-positive rates during legitimate traffic surges. To address these limitations, this study proposes a lightweight DDoS detection and mitigation framework that combines Shannon Entropy with Adaptive Dynamic Thresholds in a hierarchical SDN architecture. The proposed system is implemented using Mininet, Open vSwitch, and Ryu Controller, and evaluated against UDP Flood, ICMP Flood, and TCP SYN Flood attacks. The hierarchical architecture enables mitigation at the Gateway layer, preventing malicious traffic from reaching the core network. Experimental results show that the proposed approach effectively recovers network performance after mitigation, increasing throughput from 0.09 Mbps during the attack to 6.36 Mbps while reducing packet loss from 100% to 0%. The classification performance achieves an overall accuracy of 91% with an AUC-ROC of 0.941, demonstrating strong capability in distinguishing malicious traffic from legitimate traffic. These results demonstrate that the proposed framework provides an effective and computationally efficient solution for securing SDN-based IoT networks against volumetric DDoS attacks while maintaining normal network performance.
References
[1]
C. Singh and A. K. Jain, "A comprehensive survey on DDoS attacks detection & mitigation in SDN-IoT network," e-Prime - Advances in Electrical Engineering, Electronics and Energy, vol. 8, 2024, doi:10.1016/j.prime.2024.100543.
[2]
S. Vijay and M. K. Banga, "Managing Large IoT Network Using SDN and Hierarchical Tree Topology," Theory and Practice, vol. 2024, no. 5, pp. 6484–6495, 2024, doi:10.53555/kuey.v30i5.3969.
[3]
J. G. Almaraz-Rivera et al., "Toward the Protection of IoT Networks: Introducing the LATAM-DDoS-IoT Dataset," IEEE Access, vol. 10, pp. 106909–106920, 2022, doi:10.1109/ACCESS.2022.3211513.
[4]
S. Qureshi et al., "A Hybrid DL-Based Detection Mechanism for Cyber Threats in Secure Networks," IEEE Access, vol. 9, pp. 73938–73947, 2021, doi:10.1109/ACCESS.2021.3081069.
[5]
F. M. Salem, H. Youssef, I. Ali, and A. Haggag, "A variable-trust threshold-based approach for DDoS attack mitigation in software defined networks," PLoS ONE, vol. 17, no. 8, Art. no. e0273681, 2022, doi:10.1371/journal.pone.0273681.
[6]
C. Fan et al., "Detection of DDoS Attacks in Software Defined Networking Using Entropy," Applied Sciences, vol. 12, no. 1, Art. no. 370, 2022, doi:10.3390/app12010370.
[7]
M. A. Ferrag et al., "Deep Learning for Cyber Security Intrusion Detection: Approaches, Datasets, and Comparative Study," Journal of Information Security and Applications, vol. 50, Art. no. 102419, 2020, doi:10.1016/j.jisa.2019.102419.
[8]
J. P. Bharadiya, "Machine Learning in Cybersecurity: Techniques and Challenges," European Journal of Technology, vol. 7, no. 2, pp. 1–14, 2023, doi:10.47672/ejt.1486.
[9]
D. T. T. Mai et al., "DDoS Attacks Detection Using Dynamic Entropy in Software-Defined Network Practical Environment," International Journal of Computer Networks and Communications, vol. 15, no. 3, pp. 113–128, 2023, doi:10.5121/ijcnc.2023.15307.
[10]
T. Bai, Y. Liu, Y. Gao, and Y. Zhou, "ATS-DTA: Adaptive Two-Stage DDoS Detection with Dynamic Threshold Adjustment in SDN Networks," Cybersecurity, vol. 9, Art. no. 12, 2026, doi:10.1186/s42400-025-00414-0.
[11]
T. Wang, Y. Feng, and K. Sakurai, "Improving the Two-stage Detection of Cyberattacks in SDN Environment Using Dynamic Thresholding," in Proc. 15th Int. Conf. Ubiquitous Information Management and Communication (IMCOM), Seoul, South Korea, 2021, doi:10.1109/IMCOM51814.2021.9377395.
[12]
V. Hnamte and J. Hussain, "DCNNBiLSTM: An Efficient Hybrid Deep Learning-Based Intrusion Detection System," Telematics and Informatics Reports, vol. 10, Art. no. 100053, 2023, doi:10.1016/j.teler.2023.100053.
[13]
Y. Zhou, G. Cheng, and S. Yu, "An SDN-Enabled Proactive Defense Framework for DDoS Mitigation in IoT Networks," IEEE Transactions on Information Forensics and Security, vol. 16, pp. 5366–5380, 2021, doi:10.1109/TIFS.2021.3127009.
[14]
A. Hirsi et al., "Comprehensive Analysis of DDoS Anomaly Detection in Software-Defined Networks," IEEE Access, 2025, doi:10.1109/ACCESS.2025.3535943.
[15]
J. L. Herrera et al., "Optimizing the Response Time in SDN-Fog Environments for Time-Strict IoT Applications," IEEE Internet of Things Journal, vol. 8, no. 23, pp. 17172–17185, 2021, doi:10.1109/JIOT.2021.3077992.
[16]
Q. Syahputra, D. Akbi, and D. Risqiwati, "Deteksi dan Mitigasi Serangan DDoS pada Software Defined Network Menggunakan Algoritma Decision Tree," REPOSITOR, vol. 2, no. 11, pp. 1491–1502, 2020.
[17]
M. N. Ali, M. Imran, M. S. Ud Din, and B. S. Kim, "Low Rate DDoS Detection Using Weighted Federated Learning in SDN Control Plane in IoT Network," Applied Sciences, vol. 13, no. 3, Art. no. 1431, 2023, doi:10.3390/app13031431.



