<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">25810</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2022.025810</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>An Optimal Framework for SDN Based on Deep Neural Network</article-title>
<alt-title alt-title-type="left-running-head">An Optimal Framework for SDN Based on Deep Neural Network</alt-title>
<alt-title alt-title-type="right-running-head">An Optimal Framework for SDN Based on Deep Neural Network</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Abdallah</surname><given-names>Abdallah</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Ishak</surname><given-names>Mohamad Khairi</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Sani</surname><given-names>Nor Samsiah</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Khan</surname><given-names>Imran</given-names></name><xref ref-type="aff" rid="aff-4">4</xref></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Albogamy</surname><given-names>Fahad R.</given-names></name><xref ref-type="aff" rid="aff-5">5</xref></contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western"><surname>Amano</surname><given-names>Hirofumi</given-names></name><xref ref-type="aff" rid="aff-6">6</xref></contrib>
<contrib id="author-7" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Mostafa</surname><given-names>Samih M.</given-names></name><xref ref-type="aff" rid="aff-7">7</xref><email>samih_montser@sci.svu.edu.eg</email>
</contrib>
<aff id="aff-1"><label>1</label><institution>Department of Industrial Engineering, School of Applied Technical Sciences German Jordanian University</institution>, <addr-line>Amman, 35247</addr-line>, <country>Jordan</country></aff>
<aff id="aff-2"><label>2</label><institution>School of Electrical and Electronic Engineering, Universiti Sains Malaysia</institution>, <addr-line>Nibong Tebal, 14300</addr-line>, <country>Malaysia</country></aff>
<aff id="aff-3"><label>3</label><institution>Center for Artificial Intelligence Technology, Faculty of Information Science and Technology, The National University of Malaysia (UKM)</institution>, <addr-line>Bangi, 43600, Selangor</addr-line>, <country>Malaysia</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Electrical Engineering, University of Engineering and Technology</institution>, <addr-line>Peshawar, 814</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-5"><label>5</label><institution>Turabah University College, Computer Sciences Program, Taif University</institution>, <addr-line>Taif, 21944</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-6"><label>6</label><institution>Research Institute for Information Technology, Kyushu University</institution>, <addr-line>Fukuoka, 819-0395</addr-line>, <country>Japan</country></aff>
<aff id="aff-7"><label>7</label><institution>Computer Science-Mathematics Department, Faculty of Science, South Valley University</institution>, <addr-line>Qena, 83523</addr-line>, <country>Egypt</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Samih M. Mostafa. Email: <email>samih_montser@sci.svu.edu.eg</email></corresp>
</author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2022-05-16"><day>16</day>
<month>05</month>
<year>2022</year></pub-date>
<volume>73</volume>
<issue>1</issue>
<fpage>1125</fpage>
<lpage>1140</lpage>
<history>
<date date-type="received"><day>05</day><month>12</month><year>2021</year></date>
<date date-type="accepted"><day>12</day><month>1</month><year>2022</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2022 Abdallah et al.</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Abdallah et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_25810.pdf"></self-uri>
<abstract>
<p>Software-defined networking (SDN) is a new paradigm that promises to change by breaking vertical integration, decoupling network control logic from the underlying routers and switches, promoting (logical) network control centralization, and introducing network programming. However, the controller is similarly vulnerable to a &#x201C;single point of failure&#x201D;, an attacker can execute a distributed denial of service (DDoS) attack that invalidates the controller and compromises the network security in SDN. To address the problem of DDoS traffic detection in SDN, a novel detection approach based on information entropy and deep neural network (DNN) is proposed. This approach contains a DNN-based DDoS traffic detection module and an information-based entropy initial inspection module. The initial inspection module detects the suspicious network traffic by computing the information entropy value of the data packet&#x0027;s source and destination Internet Protocol (IP) addresses, and then identifies it using the DDoS detection module based on DNN. DDoS assaults were found when suspected irregular traffic was validated. Experiments reveal that the algorithm recognizes DDoS activity at a rate of more than 99&#x0025;, with a much better accuracy rate. The false alarm rate (FAR) is much lower than that of the information entropy-based detection method. Simultaneously, the proposed framework can shorten the detection time and improve the resource utilization efficiency.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Deep neural network</kwd>
<kwd>computer networks</kwd>
<kwd>data security</kwd>
<kwd>optimization</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1"><label>1</label><title>Introduction</title>
<p>Distributed denial of service (DDoS) has always been one of the main threats to the Internet [<xref ref-type="bibr" rid="ref-1">1</xref>&#x2013;<xref ref-type="bibr" rid="ref-4">4</xref>]. The DDoS attackers scan the network to find the vulnerable hosts and use these vulnerable hosts as the puppet machine to send a large number of request packets to the target server, causing the target host to lose its service function and cause network failure. There are many types of DDoS attacks, and the more common ones are distributed reflection DoS attacks using user datagram protocol (UDP) and the use of transmission control protocol (TCP) three-way handshake process attacks such as synchronize (SYN) flood attacks, etc. [<xref ref-type="bibr" rid="ref-5">5</xref>]. Nowadays, the network mostly adopts distributed architecture. This network architecture was originally constructed to reflect its highly scalable distributed structure, but it also led to the emergence of many security vulnerabilities [<xref ref-type="bibr" rid="ref-6">6</xref>]. The software defined network (SDN), as a new network architecture, has gradually become popular and has been widely studied, and is considered as the direction of network development [<xref ref-type="bibr" rid="ref-7">7</xref>]. Therefore, regarding the prevention of DDoS attacks in SDN networks, its safety is very important [<xref ref-type="bibr" rid="ref-8">8</xref>].</p>
<p>SDN is an implementation of network virtualization. It separates the control and data layers of the network to achieve the purpose of &#x201C;software management network&#x201D;. The control layer of the SDN can centrally control the information of the entire network. A programming interface is convenient for the network administrators to manage the network. The centralized control of the SDN makes the controller the main target of DDoS attackers [<xref ref-type="bibr" rid="ref-9">9</xref>]. When the attacker launches a DDoS attack on the SDN, in order to pass the network security equipment, disguising the source IP address, the switch continuously receives a large number of data packets, which are not in the original flow table. The controller continuously receives the forwarded data packets from the switch and becomes the target of attack. When the controller&#x0027;s resources are exhausted, the entire SDN network is paralyzed. Therefore, timely detection and termination of DDoS attack traffic in the SDN network has become a current research hotspot. But how to detect the abnormal traffic in time and accurately identify has become a difficult point in current research [<xref ref-type="bibr" rid="ref-10">10</xref>].</p>
<p>In order to defend against DDoS attacks, how to find the abnormal traffic in the network is the main research method. In most cases, the attackers disguise abnormal traffic as normal traffic, so it is difficult to distinguish the detection methods based on information entropy and detection based on machine learning. The method is two of many detection methods, but both of these detection methods have shortcomings. The detection algorithm based on information entropy has a fast detection speed and does not need to construct more traffic characteristics. But compared with the algorithm based on machine learning (ML), there exists the disadvantages of low accuracy and high FAR. The DDoS traffic recognition method based on ML has a high accuracy rate (AR), but it needs to manually construct more traffic characteristics during the detection process, which affects the detection speed. So how to find a method, which not only has a high detection rate (DR) of abnormal traffic, but also has the ability to respond to high-speed traffic and detection efficiency, that has become a difficult point and challenge for research.</p>
<p>The emergence of deep learning (DL) algorithms solves the limitations of ML. The process of DL is to use multiple processing layers to abstract high-level data to obtain multiple nonlinear transformation functions. Deep neural network (DNN) in the image recognition, speech recognition and other fields have achieved good results. Compared with traditional ML, the DNNs combine low-level features to form more abstract high-level representations through multi-layer non-linear transformations, so that a learning system cannot rely on artificial feature selection, and found that the distributed nature of data representation, and learn to express complex function [<xref ref-type="bibr" rid="ref-11">11</xref>]. With the continuous development of graphical processing unit (GPU) technology and a variety of deep learning (DL) platform, making the depth of the neural network can quickly process huge amounts of data classification [<xref ref-type="bibr" rid="ref-12">12</xref>,<xref ref-type="bibr" rid="ref-13">13</xref>]. Therefore, based on the DNN to identify the abnormal DDoS traffic, there is no need to manually design too many traffic characteristics, and it has higher detection accuracy and faster detection time. However, in practical applications, the SDN medium traffic is huge, and the detection of all traffic consumes huge computing resources and affects the real-time performance of the detection.</p>
<p>As a result, based on prior research and learning, this article proposes an innovative DDoS detection framework based on DNN. The proposed framework includes an initial inspection module based on information entropy and a detection module based on DNN. The detection model draws on the advantages of information entropy and DNN algorithm, and the accuracy measurement is performed after the initial inspection module finds the abnormal flow. This model makes up for the shortcomings of the detection algorithm based on information entropy of low DR and high FAR. It also shortens the detection time based on DNN algorithm, reducing the resource occupancy rate, not only can improve the accuracy of detection, but also shorten the processing time of detection, and save the frequency of resource usage by the DNN algorithm.</p>
<p>The main contributions of this article have three aspects:
<list list-type="simple">
<list-item><label>1)</label><p>A model for detecting the DDoS attacks in SDN is proposed. The model includes a preliminary inspection module based on information entropy and a DNN detection module. Combining the advantages of the two methods, it improves the DR and accuracy of the model, and reduces the FAR of the model. It speeds up the DR and reduce the occupancy rate of computing resources.</p></list-item>
<list-item><label>2)</label><p>Using OpenFlow protocol fields, manual extraction and other methods to construct a 19-dimensional feature vector, as the input of the DNN model. After training and testing, the accuracy of the proposed model to identify DDoS traffic is higher than that of traditional ML methods, and has a lower FAR.</p></list-item>
<list-item><label>3)</label><p>Propose a lightweight initial inspection method based on information entropy, and determine the suspected abnormal traffic by calculating the information entropy of the packet unit. The determined threshold allows the proposed method to have a recognition rate of more than 99&#x0025;. As an initial inspection method, high false alarms can be ignored compared with the direct use of DNN-based detection algorithms, 2/3 the detection time and the occupancy rate of computing resources are reduced.</p></list-item>
</list></p>
</sec>
<sec id="s2"><label>2</label><title>Literature Review</title>
<p>The development of DDoS attacks has become a major security threat to the Internet today [<xref ref-type="bibr" rid="ref-14">14</xref>]. The continuous development of network technology, the emergence of various new network architectures and the popularization of smart devices have made DDoS attack methods showing a trend of frequent development [<xref ref-type="bibr" rid="ref-15">15</xref>]. With the advancement of network technology, the DDoS attackers have begun to use new network equipment or network architecture to launch attacks. In recent years, the SDN networks have become a research hotspot for researchers and network service providers, and the problem of DDoS attacks in SDN is one of the research topics [<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-17">17</xref>].</p>
<p>Reference [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed a method of setting up a backup controller. When the SDN network is subjected to a DDoS attack, the switch disconnects from the controller and connects to other backup controllers. This method can temporarily mitigate the DDoS attack. However, it cannot fundamentally prevent it. Once the backup controllers are also attacked, the entire SDN network will lose control. Reference [<xref ref-type="bibr" rid="ref-19">19</xref>] proposed a method to predict the attacks based on traffic thresholds. The method constructs flow characteristics by extracting NetFlow flow data, and calculates the flow characteristics and design thresholds through detection functions. However, this method needs to process the data flow collected in advance and requires a lot of preparatory work. In addition, the success of the test is closely related to the actual experience of the researcher.</p>
<p>Reference [<xref ref-type="bibr" rid="ref-20">20</xref>] proposed a fast entropy calculation method to detect the DDoS attacks in traffic, and calculate the entropy value over a period of time by counting the network traffic. If the entropy value exceeds the threshold, it is determined that a DDoS attack has occurred in the network. This method successfully improved the detection speed, but failed to significantly improve the detection accuracy, and the algorithm has a high FAR. Reference [<xref ref-type="bibr" rid="ref-21">21</xref>] proposed a large-scale network detection mechanism based on flow entropy and packet sampling. This method improves the detection accuracy and reduces the FAR, but it sets a threshold based on relevant experience and increases the influence of human factors. Reference [<xref ref-type="bibr" rid="ref-22">22</xref>] proposed a statistical solution to detect the DDoS attacks in SDN. The method extracts the flow characteristics, generates a characteristic matrix, and finds the abnormal flow by calculating the joint entropy of different combinations of flow characteristics. Compared with the previous detection algorithm based on entropy, this method has a great improvement, and the detection range is accurate. The rate has been greatly improved, but this method requires a long period of preparation and statistics, the calculation is more complicated, the scalability is poor, and the real-time performance is not high. Reference [<xref ref-type="bibr" rid="ref-23">23</xref>] proposed an entropy-based SDN early detection technology for TCP SYN flooding attacks. This technology is based on traffic characteristics and measures the degree of randomness of the data packets received at the SDN controller by calculating the entropy value of the traffic characteristics in a time-based data packet window sequence and compared with the threshold (adaptive) under this example. This method can detect the early attack. However, this method assumes that there is only one target node, which is not universal, and the method is only for TCP SYN flood attacks. The above research shows that, in SDN, it is difficult for the existing DDoS detection methods based on information entropy to have both high accuracy and high DR.</p>
<p>Reference [<xref ref-type="bibr" rid="ref-24">24</xref>] proposed a DDoS traffic detection algorithm based on extreme gradient boost (XGBoost). The method uses the XGBoost classifier to test the knowledge discovery and data mining (KDD) 99 data set. The test results show that the method has the characteristics of high detection accuracy and fast DR. But The detection effect of this method on other experimental environmental data is unknown. Reference [<xref ref-type="bibr" rid="ref-25">25</xref>] used the support vector machines (SVM) to detect the DDoS traffic in SDN. This method is also tested on the KDD 99 data set. The test results show the effectiveness of the method. This method also faces the problem of unknown actual detection effect. At the same time, the methods proposed in [<xref ref-type="bibr" rid="ref-24">24</xref>,<xref ref-type="bibr" rid="ref-25">25</xref>] requires manual construction of a large number of features, which affects the detection efficiency. Reference [<xref ref-type="bibr" rid="ref-26">26</xref>] proposed a method for detecting abnormal traffic in SDN based on DL. This method designs traffic characteristics and uses DL algorithms to detect the abnormal traffic in the SDN. Compared with the previous ML methods, the accuracy is improved. However, the detection efficiency is not high. When the traffic is huge, the detection of normal traffic will consume the resources of the DL hardware and increase the calculation time.</p>
<p>Through the above research, it is found that there are many problems in the detection algorithm based on information entropy: the determination of the threshold often brings about the contradiction between the DR and FAR, high computational complexity, poor scalability, low detection rate, and data statistical cycle. Detection algorithms based on ML also have problems such as low DR, high central processing unit (CPU) usage, and unused actual data verification. DL algorithms have high accuracy and low FAR. However, when the network traffic is too large, it will affect the detection time and occupy computing resources. To address the shortcomings of the preceding research methods, this paper proposes a detection model based on information entropy and DL. This model combines the previous detection methods based on information entropy and ML. The information entropy method is used to conduct the preliminary detection of traffic, and then DNN is used to accurately detect the suspected problem traffic. Compared with the traditional methods based on information entropy and ML, this method has higher detection accuracy, lower FAR and higher detection efficiency.</p>
</sec>
<sec id="s3"><label>3</label><title>Proposed Framework</title>
<sec id="s3_1"><label>3.1</label><title>Overall Architecture</title>
<p>The proposed detection model is deployed in the controller in the SDN. It includes two main parts: an abnormal initial detection module based on information entropy and a DDoS traffic detection module based on DNN, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>. In the SDN network, every time the switch receives a new data packet, the controller will update the flow table entry of the switch. When the SDN network is attacked, the controller will receive a large number of data packets from the switch, resulting in control device interrupts the service and the network is paralyzed. The abnormal initial detection module collects the <italic>packet_in</italic> data packets in the SDN controller, calculates the entropy value of the data characteristics in the fixed interval data packet window, and compares it with the set threshold. Once it is not within the normal range, the traffic is deemed to be suspected to be abnormal, and it is subjected to the DNN-based anomaly detection. The DDoS traffic detection module based on DNN extracts the required characteristics through the switch flow table entry, and performs further detection to confirm whether a DDoS attack occurs in the network. If an attack occurs, a warning will be issued and the network manager will be notified for further processing.</p>
<fig id="fig-1"><label>Figure 1</label><caption><title>Proposed system model</title></caption><graphic mimetype="image" mime-subtype="png" xlink:href="CMC_25810-fig-1.png"/></fig>
</sec>
<sec id="s3_2"><label>3.2</label><title>Anomaly Initial Inspection</title>
<p>Information entropy reflects the degree of uncertainty in the value of random variables (RVs). When the value of the RV is more random, the value of information entropy is higher. When the value of the RV is more consistent, the information entropy has lower value [<xref ref-type="bibr" rid="ref-27">27</xref>]. We use the Shannon&#x0027;s formula to calculate the sample entropy:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:munderover><mml:mrow><mml:mo movablelimits="false">&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>N</mml:mi></mml:munderover><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mrow><mml:mi>S</mml:mi></mml:mfrac></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mrow><mml:mi>S</mml:mi></mml:mfrac></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>Among them, the data sample <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mi>x</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>N</mml:mi></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> indicates that a certain sample <italic>i</italic> in the data has occurred <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> times. <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mi>S</mml:mi><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x2211;</mml:mo></mml:mrow><mml:mi>i</mml:mi><mml:mi>N</mml:mi></mml:msubsup><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> which indicates the total number of sample values <italic>X</italic>. From <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>, we can see that the size of the sample entropy changes in the interval (0; <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mi>S</mml:mi></mml:math></inline-formula>). When the value distribution of the sample is the most concentrated, the entropy value is 0, then <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>N</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> means that all the sample values are the same. When the distribution of the sample is the most dispersed, the entropy value is the largest, and all sample values are different at this time.</p>
<p>Due to the self-similarity of network traffic, we consider that the sparseness and denseness of the data packet feature samples are only related to the number of samples, and the size of the entropy value is only determined by the similarities and differences of the sample data. For example, two sample sequences of the same number <italic>X</italic> and <italic>Y</italic>, where <italic>X</italic> is a sample sequence collected within 30&#x2005;s, <italic>Y</italic> is a sample sequence collected within 45&#x2005;s, but the entropy of the two sample sequences is the same. Then it is inferred that <italic>X</italic> and <italic>Y</italic> have the same degree of sparse distribution [<xref ref-type="bibr" rid="ref-28">28</xref>].</p>
<p>In the experiment, the <italic>packet_in</italic> data packet of the SDN controller is regarded as the unit data packet. We define a fixed packet number interval as a packet unit data packet (packetbin). That is, the continuous data packet is divided into a packet unit according to a specific number of packets (bin). We use some feature sequence values in packetbin as sample data, and calculate the entropy value of the feature sequence sample data. We have selected two most important features that can reflect the current network status: source and destination IP addresses. The choice of the number of packets <italic>W</italic> in each packetbin controls the change of sample characteristics in a short period of time. If the value of <italic>W</italic> is too large, the entropy value will not change significantly, which will reduce the accuracy of detection. In the SDN network of this experimental environment, according to the number of hosts and traffic conditions, after measurement and analysis, it is found that <italic>W</italic> &#x003D;&#x2009;100 is a good compromise for the deployed data. When calculating the entropy, it is <italic>S</italic> &#x003D; <italic>W&#x2009;</italic>&#x003D;<italic>&#x2009;</italic>100 in <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>, we calculate the information entropy of the source and destination IP addresses in the first consecutive <italic>W</italic> packets, and then move to the next adjacent <italic>W</italic> packets to calculate the corresponding entropy. We get an abnormal traffic analysis index based on the information entropy, as shown in <xref ref-type="table" rid="table-1">Tab. 1</xref>.</p>
<table-wrap id="table-1"><label>Table 1</label><caption><title>Index variables of flow with abnormalities</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Description</th>
<th align="left">Index</th>
<th align="left">Entropy</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Source IP</td>
<td align="left">SIP</td>
<td align="left"><inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>S</mml:mi><mml:mi>I</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td align="left">Destination IP</td>
<td align="left">DIP</td>
<td align="left"><inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>D</mml:mi><mml:mi>I</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>We set the experimental threshold T. If the information entropy in the indicator is not within the threshold range, it is observed that some abnormality has occurred in the SDN, issue a warning, and start the DDoS traffic detection module based on DL at this moment. The traffic in the SDN is detected, DDoS attacks are found and the warnings are issued. Unlike other entropy-based methods, this study does not set a confidence interval because it does not use a criterion for judging whether the DDoS occurs in the network, but only use it as the initial inspection method. Because the pure entropy-based detection method has limitations, for example, how to determine the threshold will affect the accuracy of the entire algorithm, and this method often results in a higher FAR. In our initial inspection model, the threshold is set to a wider range. This method has a higher detection and recognition rates, but it has a higher FAR. As a preliminary inspection method, it only requires a higher recognition rate.</p>
<p>The abnormal initial inspection module based on information entropy observe the network traffic, and inputs the generated suspected abnormal traffic to the DL module for further processing. It not only completes the detection of abnormal traffic, but also slows down the DL module pressure of the required resources.</p>
</sec>
<sec id="s3_3"><label>3.3</label><title>Feature Extraction and Construction</title>
<p>In traditional ML algorithms, how to select the features will affect the success of the entire algorithm. Choosing good features can improve the accuracy of the algorithm. But too many feature designs will increase the complexity, and the process of manually selecting features will affect the detection speed. The DNN model can automatically extract the features layer by layer, and assign weights to the extracted features to achieve the best results.</p>
<p>In the experimental DNN model, we directly extracted some of the fields in the OpenFlow flow table as the feature input of the first layer. In addition to the features that can be directly extracted in the flow table, we manually designed two features, which are also used as the input of the DL network. The input characteristics are shown in <xref ref-type="table" rid="table-2">Tab. 2</xref>.</p>
<table-wrap id="table-2"><label>Table 2</label><caption><title>Input characteristics</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Characteristic</th>
<th align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left"><italic>table_id</italic></td>
<td align="left">Table of id</td>
</tr>
<tr>
<td align="left"><italic>cockie</italic></td>
<td align="left">Cockie</td>
</tr>
<tr>
<td align="left"><italic>Duration</italic></td>
<td align="left">Flow duration</td>
</tr>
<tr>
<td align="left"><italic>n_packets</italic></td>
<td align="left">Number of packets</td>
</tr>
<tr>
<td align="left"><italic>n_Bytes</italic></td>
<td align="left">Number of bytes</td>
</tr>
<tr>
<td align="left"><italic>protocol</italic></td>
<td align="left">Protocol of IP</td>
</tr>
<tr>
<td align="left"><italic>ip_src</italic></td>
<td align="left">Source IP</td>
</tr>
<tr>
<td align="left"><italic>ip_dst</italic></td>
<td align="left">Destination IP</td>
</tr>
<tr>
<td align="left"><italic>tcp_src</italic></td>
<td align="left">Source port number of TCP</td>
</tr>
<tr>
<td align="left"><italic>actions</italic></td>
<td align="left">Switch action</td>
</tr>
<tr>
<td align="left"><italic>mac_dst</italic></td>
<td align="left">Destination address of MAC</td>
</tr>
<tr>
<td align="left"><italic>mac_src</italic></td>
<td align="left">Source address of MAC</td>
</tr>
<tr>
<td align="left"><italic>idle_timeout</italic></td>
<td align="left">Time-out duration</td>
</tr>
<tr>
<td align="left"><italic>tcp_dst</italic></td>
<td align="left">Destination port number of TCP</td>
</tr>
<tr>
<td align="left"><italic>n_packets_ave</italic></td>
<td align="left">Average number of packets</td>
</tr>
<tr>
<td align="left"><italic>n_bytes_ave</italic></td>
<td align="left">Average number of bytes</td>
</tr>
<tr>
<td align="left"><italic>udp_src</italic></td>
<td align="left">Source port number of UDP</td>
</tr>
<tr>
<td align="left"><italic>udp_dst</italic></td>
<td align="left">Destination port number of UDP</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The two features manually extracted are the average number of data packets and the number of data packets. Among them, the average number of data packets <italic>n</italic>_<italic>packets</italic>_<italic>ave</italic> is the number of packets (<italic>n</italic>_<italic>packets</italic>) divided by the flow duration (duration), which is the number of data packets per second:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mi>n</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>s</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>a</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>n</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>s</mml:mi></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>u</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>The average number of data packets (<italic>n_bytes_ave</italic>) is the number of packets (<italic>n_bytes</italic>) divided by the stream duration (<italic>duration</italic>), that is, the number of data packets per second:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mi>n</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>b</mml:mi><mml:mi>y</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>a</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>n</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>b</mml:mi><mml:mi>y</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>u</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>In summary, this paper constructed the 19-dimensional feature input of the DL detection model based on the flow table information. These features can be directly read in the flow table entry, and the manually constructed features are also easier to obtain. This 19 dimensional feature vector is used as the input of the DL detection model to identify the abnormal DDoS traffic.</p>
</sec>
<sec id="s3_4"><label>3.4</label><title>Detection Model</title>
<p>DNN is a fully connected network that includes an input layer, multiple hidden layers, and an output layer [<xref ref-type="bibr" rid="ref-29">29</xref>]. <xref ref-type="fig" rid="fig-2">Fig. 2</xref> depicts a 5-dimensional vector input, 7-dimensional vector output and DNN network model with <italic>L&#x2009;</italic>&#x2212;<italic>&#x2009;</italic>1 hidden layers.</p>
<fig id="fig-2"><label>Figure 2</label><caption><title>Proposed DNN model</title></caption><graphic mimetype="image" mime-subtype="png" xlink:href="CMC_25810-fig-2.png"/></fig>
<p>In the DNN network, each layer contains the weight vector <italic>W</italic> and the offset vector <bold><italic>b</italic></bold>. We calculate the output <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mrow><mml:msup><mml:mi>l</mml:mi><mml:mi>h</mml:mi></mml:msup></mml:mrow></mml:math></inline-formula> of the <italic>h</italic>-th layer:
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mrow><mml:msup><mml:mi>l</mml:mi><mml:mi>h</mml:mi></mml:msup></mml:mrow><mml:mo>=</mml:mo><mml:mi>tanh</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi mathvariant="bold-italic">b</mml:mi></mml:mrow><mml:mi>h</mml:mi></mml:msup></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi mathvariant="bold-italic">w</mml:mi></mml:mrow><mml:mi>h</mml:mi></mml:msup></mml:mrow><mml:mrow><mml:msup><mml:mi>l</mml:mi><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>Among them, <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mrow><mml:msup><mml:mi mathvariant="bold-italic">b</mml:mi><mml:mi>h</mml:mi></mml:msup></mml:mrow></mml:math></inline-formula> is the offset vector, <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mrow><mml:msup><mml:mi mathvariant="bold-italic">w</mml:mi><mml:mi>h</mml:mi></mml:msup></mml:mrow></mml:math></inline-formula> is the weight matrix, and the nonlinear function is the tanh. The top-level output <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mrow><mml:msup><mml:mi>l</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msup></mml:mrow></mml:math></inline-formula> and the supervised target output <italic>y</italic> are combined to form the loss function <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>&#x03C9;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mrow><mml:msup><mml:mi>l</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mi>y</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. The output layer linear regression function is
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:msubsup><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msubsup><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup><mml:mo>+</mml:mo><mml:msubsup><mml:mi>w</mml:mi><mml:mi>i</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup><mml:mrow><mml:msup><mml:mi>l</mml:mi><mml:mrow><mml:mi>&#x03BC;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mo movablelimits="false">&#x2211;</mml:mo></mml:mrow><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msubsup><mml:mi>b</mml:mi><mml:mi>j</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup><mml:mo>+</mml:mo><mml:msubsup><mml:mi>w</mml:mi><mml:mi>j</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup><mml:mrow><mml:msup><mml:mi>l</mml:mi><mml:mrow><mml:mi>&#x03BC;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>Among them, <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msubsup><mml:mi>w</mml:mi><mml:mi>i</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup></mml:math></inline-formula> is the <italic>i</italic>-th row of <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mrow><mml:msup><mml:mi>w</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msup></mml:mrow></mml:math></inline-formula>. In this case, we use the conditional log-likelihood function as the loss function with <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msubsup><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup><mml:mo>&#x003E;</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> and <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:munder><mml:mrow><mml:mo movablelimits="false">&#x2211;</mml:mo></mml:mrow><mml:mi>i</mml:mi></mml:munder><mml:mo>&#x2061;</mml:mo><mml:msubsup><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mi>&#x03B7;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mrow><mml:msup><mml:mi>l</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mi>y</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>Y</mml:mi><mml:mo>=</mml:mo><mml:mi>y</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>x</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msubsup><mml:mi>l</mml:mi><mml:mi>y</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msubsup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>The expected value on the <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> pair is minimized. During training, back propagation (BP) and gradient descent (GD) algorithms are used to adjust the weight value and bias according to the output error value of each neuron. The amount of shift is adjusted. When the output of the cost function is the smallest, the best result is achieved.</p>
<p>The output selects the softmax function and defines the cross entropy error as follows
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mi>F</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munderover><mml:mrow><mml:mo movablelimits="false">&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>N</mml:mi></mml:munderover><mml:mo>&#x2061;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:mn>1</mml:mn><mml:mo>+</mml:mo><mml:mrow><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:msup><mml:mi>y</mml:mi><mml:mi>n</mml:mi></mml:msup></mml:mrow><mml:mrow><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:msup><mml:mi>x</mml:mi><mml:mi>n</mml:mi></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></disp-formula></p>
<p>Wherein, <italic>N</italic> is the number of units by the <italic>w</italic> obtained with respect to each weight <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> cost function <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>F</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, which is defined as
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>h</mml:mi></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mi mathvariant="normal">&#x2202;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2202;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mrow></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac><mml:mi>F</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula>where
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>h</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>h</mml:mi></mml:msub></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>h</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>h</mml:mi></mml:msub></mml:mrow></mml:math></disp-formula></p>
<p>Among them, <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mrow><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>h</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> is called the learning efficiency [<xref ref-type="bibr" rid="ref-30">30</xref>]. Finally, according to <xref ref-type="disp-formula" rid="eqn-7">Eqs. (7)</xref>&#x2013;<xref ref-type="disp-formula" rid="eqn-9">(9)</xref>, the corresponding stochastic gradient descent algorithm is used to minimize the cost function, and finally we will get the best weight value. The experiment uses a DNN structure including an input layer, an output layer and 10 hidden layers. In the hidden layer, the hyperbolic tanh function is used for nonlinear processing, and the current activation is performed in the output layer. After multiple batches of GD training, the final detection model is determined.</p>
</sec>
</sec>
<sec id="s4"><label>4</label><title>Experimental Results</title>
<sec id="s4_1"><label>4.1</label><title>Configuration</title>
<p>This article uses Mininet to build an SDN, where the controller uses the JAVA-based open source controller Floodlight, and the operating system is Ubuntu 16.04. The DL module is developed based on the Tensorflow framework. The developed hardware environment is a 48-core CPU server. Before the experiment, we used the scapy tool to inject the traffic into the mininet virtual network (VN) to imitate the DDoS attack. The network topology created by Mininet is shown in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>. The SDN consists of ten switches, each switch connects ten hosts, select two of them as the source of DDoS attacks, and launch an attack on the SDN network.</p>
<fig id="fig-3"><label>Figure 3</label><caption><title>Proposed network configuration</title></caption><graphic mimetype="image" mime-subtype="png" xlink:href="CMC_25810-fig-3.png"/></fig>
<p>The experiment uses three indicators: <italic>DR</italic>, accuracy (<italic>ACC</italic>), and <italic>FAR</italic> as the criteria for evaluating the model. The DR is the ratio of the correctly identified to all DDoS attack traffic in the sample which is expressed as
<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mi>D</mml:mi><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>The ACC is the ratio of correctly identifying normal and abnormal flows in the total data set
<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:mi>A</mml:mi><mml:mi>C</mml:mi><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>The FAR refers to the ratio of normal traffic that is misidentified as DDoS attack traffic by the model to all normal traffic in the test set. The lower the FAR, the better the classification effect of the model
<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:mi>F</mml:mi><mml:mi>A</mml:mi><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>F</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>F</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>Among them, the true positive (TP) rate refers to the rate at which the abnormal DDoS traffic is identified by the model, and the false positive (FP) rate refers to the rate at which normal traffic is incorrectly identified as DDoS traffic. The true negative (TN) rate refers to the rate at which the normal traffic is correctly identified. False negative (FN) rate refers to the rate at which the DDoS traffic is incorrectly identified as normal traffic [<xref ref-type="bibr" rid="ref-31">31</xref>].</p>
</sec>
<sec id="s4_2"><label>4.2</label><title>Results Analysis Based on Information Entropy</title>
<p>In the abnormal initial detection module based on information entropy, we propose an abnormal traffic analysis indicator, by calculating the entropy value of each feature vector in several windows, and judging whether the network has occurred according to whether the entropy value exceeds the threshold collect the <italic>packet-in</italic> of normal network traffic in the switch, read the source and destination IP addresses in the data packet, and then calculate the characteristic entropy value in each window, namely 100 data packets. The SDN network is subject to DDoS during the attack, 100,000 pieces of data traffic are collected, the source and destination IP addresses are analyzed, and the information entropy value is calculated. The comparison is shown in <xref ref-type="fig" rid="fig-4">Figs. 4</xref> and <xref ref-type="fig" rid="fig-5">5</xref>.</p>
<fig id="fig-4"><label>Figure 4</label><caption><title>Entropy evaluation <italic>vs.</italic> number of windows of source-IP</title></caption><graphic mimetype="image" mime-subtype="png" xlink:href="CMC_25810-fig-4.png"/></fig>
<fig id="fig-5"><label>Figure 5</label><caption><title>Entropy evaluation <italic>vs.</italic> number of windows of destination IP</title></caption><graphic mimetype="image" mime-subtype="png" xlink:href="CMC_25810-fig-5.png"/></fig>
<p>It can be seen from <xref ref-type="fig" rid="fig-4">Figs. 4</xref> and <xref ref-type="fig" rid="fig-5">5</xref> that when a DDoS attack occurs in SDN, the characteristic information entropy value has changed significantly, and the characteristic vector value has dropped rapidly, and the range of change is small. The initial inspection module based on information entropy is to be able to identify the abnormal traffic in the network, so it must have a high DR, but because it is only a preliminary inspection module, it is not required to have a very low FAR. According to the above principles, to analyze the experimental data, the threshold of the feature entropy value is shown in <xref ref-type="table" rid="table-3">Tab. 3</xref>.</p>
<table-wrap id="table-3"><label>Table 3</label><caption><title>IP values analysis</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Parameter</th>
<th align="left">Source IP</th>
<th align="left">Destination IP</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Threshold value</td>
<td align="left">2.5192</td>
<td align="left">2.5557</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>According to the analysis of experimental data, when the source IP address information entropy threshold is set to 2.5192, the DR of abnormal traffic identification is 100&#x0025;, and the FAR is 42.769&#x0025;. When the destination IP address information entropy threshold is set to 2.5557, the DR of abnormal traffic is 100&#x0025;, and the FAR is 39.231&#x0025;. When one of the two feature entropy values exceeds the specified threshold, it is concluded that an abnormality has occurred in the network.</p>
<p>In order to prove the effectiveness of the threshold, this study simulate the DDoS attacks and collect data, mark them to distinguish between normal and abnormal traffic, mix normal traffic with abnormal traffic, and perform anomaly detection based on information entropy. If the information entropy of a certain characteristic value is lower than the threshold, it is marked as abnormal traffic. Finally, the marking result is compared with the initial label to calculate the DR and FAR of the algorithm. The experimental results are shown in <xref ref-type="table" rid="table-4">Tab. 4</xref>.</p>
<table-wrap id="table-4"><label>Table 4</label><caption><title>DR and FAR evaluation</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left" rowspan="2">Parameter</th>
<th align="center" colspan="3">Number of flows (million)</th>
</tr>
<tr>
<th align="left">5</th>
<th align="left">8</th>
<th align="left">10</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">DR</td>
<td align="left">99.8995</td>
<td align="left">99.9871</td>
<td align="left">99.8635</td>
</tr>
<tr>
<td align="left">FAR</td>
<td align="left">43.781</td>
<td align="left">37.364</td>
<td align="left">48.654</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>From the experimental results, it can be seen that the proposed method has a very high DR, which proves that it can effectively identify DDoS attack traffic. Although it has a high FAR, it does not affect its use as an initial check for the effectiveness.</p>
</sec>
<sec id="s4_3"><label>4.3</label><title>Results Analysis Based on DNN</title>
<p>The experimental data set is the real traffic in the SDN. A total of 120,000 traffic data, including 70,000 normal traffic and 50,000 DDoS attack traffic is collected. Among them, 79,970 data sets are used as training sets and 40030 pieces of data are used as the test set, as shown in <xref ref-type="table" rid="table-5">Tab. 5</xref>.</p>
<table-wrap id="table-5"><label>Table 5</label><caption><title>Dataset values</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left" rowspan="2">Parameter</th>
<th align="center" colspan="2">Dataset</th>
</tr>
<tr>
<th align="left">Test set</th>
<th align="left">Training set</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Number of normal flows</td>
<td align="left">23250</td>
<td align="left">46750</td>
</tr>
<tr>
<td align="left">Number of DDoS flows</td>
<td align="left">16780</td>
<td align="left">33220</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The choice of the number of hidden layers of the DNN model will affect the accuracy of the model&#x0027;s recognition of DDoS traffic. It is very important to choose how many layers of DNN as the detection model. Therefore, we have constructed the number of hidden layers as 5 and 10 respectively. In the experiment, we use the same data set to perform 1,000 iterations of these five DNN models, and evaluate each DNN model through accuracy rate. <xref ref-type="table" rid="table-6">Tab. 6</xref> shows the comparison of the results of five DNN models with different structures after being trained for 1,000 rounds under the same training and test sets.</p>
<table-wrap id="table-6"><label>Table 6</label><caption><title>Hidden layers ACC evaluation</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left" rowspan="2">Parameter</th>
<th align="center" colspan="5">Number of hidden layers</th>
</tr>
<tr>
<th align="left">5</th>
<th align="left">10</th>
<th align="left">20</th>
<th align="left">50</th>
<th align="left">100</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Accuracy (&#x0025;)</td>
<td align="left">86.43</td>
<td align="left">97.87</td>
<td align="left">96.12</td>
<td align="left">94.72</td>
<td align="left">81.48</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>It can be seen from the results in <xref ref-type="table" rid="table-6">Tab. 6</xref> that the DNN model does not have more layers and has better training results. It is because too many hidden layers will even cause the accuracy of the recognition results to decline. Therefore, the experimental model chooses a 10-layer DNN model.</p>
<p>The actual data traffic set is deployed to compare the experiments with the XGBoost [<xref ref-type="bibr" rid="ref-24">24</xref>] and SVM models [<xref ref-type="bibr" rid="ref-25">25</xref>]. At the same time, the proposed model is compared with the traditional ML based K-nearest neighbor (KNN) model. The results are shown in <xref ref-type="table" rid="table-7">Tab. 7</xref>. It can be seen from <xref ref-type="table" rid="table-7">Tab. 7</xref> that the proposed DNN model is better than the traditional methods in terms of DR, ACC and FAR. The ACC rate of the proposed model is 97.87&#x0025;, and the FAR has dropped significantly. From the experimental results, it can be seen that the proposed model is better than traditional ML models.</p>
<table-wrap id="table-7"><label>Table 7</label><caption><title>Comparison of the proposed and existing algorithms</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left" rowspan="2">Parameter</th>
<th align="center" colspan="4">Model</th>
</tr>
<tr>
<th align="left">XGBoost</th>
<th align="left">SVM</th>
<th align="left">KNN</th>
<th align="left">Proposed</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">DR</td>
<td align="left">94.36</td>
<td align="left">93.12</td>
<td align="left">93.78</td>
<td align="left">95.42</td>
</tr>
<tr>
<td align="left">ACC</td>
<td align="left">95.91</td>
<td align="left">95.19</td>
<td align="left">95.08</td>
<td align="left">97.87</td>
</tr>
<tr>
<td align="left">FAR</td>
<td align="left">4.74</td>
<td align="left">6.21</td>
<td align="left">7.15</td>
<td align="left">3.16</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>At the same time, we conducted two sets of comparative experiments using the experimental data set and using the DNN model to detect the DDoS traffic. The first group of experiments directly used the 17 feature fields extracted directly from the OpenFlow as inputs. The second group of experiments is in addition to directly extracting the 17 feature fields. Two features &#x201C;Average data grouping number&#x201D; and &#x201C;Average data grouping bit number&#x201D; are manually constructed in real time, and these 19 features are used as model inputs. At the same time, the accuracy of abnormal traffic under two different traffic feature inputs are calculated. The results are shown in <xref ref-type="table" rid="table-8">Tab. 8</xref>.</p>
<table-wrap id="table-8"><label>Table 8</label><caption><title>ACC and time cost evaluation of the proposed algorithm</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left" rowspan="2">Parameter</th>
<th align="center" colspan="2">Input feature</th>
</tr>
<tr>
<th align="left">Directly and hand-build</th>
<th align="left">Directly extracted</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">ACC (&#x0025;)</td>
<td align="left">97.87</td>
<td align="left">97.12</td>
</tr>
<tr>
<td align="left">Time cost (s)</td>
<td align="left">67.57</td>
<td align="left">67.54</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>It can be seen from <xref ref-type="table" rid="table-8">Tab. 8</xref> that after adding two manually constructed features, the accuracy recognition increased by 0.75&#x0025;, while the time only increased by 0.03&#x2005;s. This proves the effectiveness of manually constructed features.</p>
<p>In addition, we also conducted two comparison experiments. The first experiment used only the detection module based on DL to detect the flow, while the second experiment used the preliminary inspection module based on information entropy for the initial inspection and the detection module based on deep learning. The results are shown in <xref ref-type="table" rid="table-9">Tab. 9</xref>.</p>
<table-wrap id="table-9"><label>Table 9</label><caption><title>Performance comparison of the proposed method</title></caption>
<table>
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Parameter</th>
<th align="center" colspan="2">Method</th>
</tr>
<tr>
<th></th>
<th align="left">DNN</th>
<th align="left">Entropy and DNN</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">ACC (&#x0025;)</td>
<td align="left">97.87</td>
<td align="left">97.89</td>
</tr>
<tr>
<td align="left">CPU utility (&#x0025;)</td>
<td align="left">53</td>
<td align="left">22</td>
</tr>
<tr>
<td align="left">Time cost (s)</td>
<td align="left">67</td>
<td align="left">24</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>It can be seen from the detection accuracy that the two methods have high accuracy for the identification of abnormal traffic, both reaching more than 97&#x0025;, and both have a good recognition effect. However, the detection method based on information entropy and deep learning saves CPU usage rate and reduce the processing time. The initial inspection method based on information entropy is a lightweight calculation, its occupancy rate of computing resources is not high, and has a faster processing speed.</p>
<p>By adjusting the number of DNN layers and manually designing input features, the optimal DNN detection model suitable for the experimental environment is obtained. At the same time, a comparative test was carried out with previous research methods, and the results showed that, the proposed model has a high accuracy rate for identifying the DDoS traffic in the traffic, occupies less computing resources and faster processing speed.</p>
</sec>
</sec>
<sec id="s5"><label>5</label><title>Conclusion</title>
<p>This paper proposes a DDoS attack detection framework based on information entropy and DNN, as well as an abnormal traffic analysis index for calculating information entropy with a 19-dimensional flow table feature vector. The initial inspection model based on information entropy can effectively identify the abnormal traffic, and the DNN detection module confirms it. The proposed model not only solves the problem of low accuracy of detection methods based on information entropy, but also alleviates the long detection time of DL methods and occupation of computing resources. Experiments show that, the proposed method can effectively identify the abnormal DDoS traffic, provide effective information for network administrators, and provide effective guarantee for SDN network security.</p>
</sec>
</body>
<back>
<ack><p>The authors would like to acknowledge the support from Taif University Researchers Supporting Project Number (TURSP-2020/331), Taif University, Taif, Saudi Arabia.</p>
</ack>
<fn-group>
<fn fn-type="other"><p><bold>Funding Statement:</bold> This publication was supported by the Ministry of Education, Malaysia (Grant code: FRGS/1/2018/ICT02/UKM/02/6).</p></fn>
<fn fn-type="conflict"><p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p></fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Tareq</surname></string-name>, <string-name><given-names>E. A.</given-names> <surname>Sundarajan</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Mohd</surname></string-name> and <string-name><given-names>N. S.</given-names> <surname>Sani</surname></string-name></person-group>, &#x201C;<article-title>Online clustering of evolving data streams using a density grid-based method</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>166472</fpage>&#x2013;<lpage>166490</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Nasif</surname></string-name>, <string-name><given-names>Z. A.</given-names> <surname>Othman</surname></string-name> and <string-name><given-names>N. S.</given-names> <surname>Sani</surname></string-name></person-group>, &#x201C;<article-title>The deep learning solutions on lossless compression methods for alleviating data load on iot nodes in smart cities</article-title>,&#x201D; <source>Sensors Journal</source>, vol. <volume>21</volume>, no. <issue>12</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>23</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A. S.</given-names> <surname>Abdulameer</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Tiun</surname></string-name>, <string-name><given-names>N. S.</given-names> <surname>Sani</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ayob</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Taha</surname></string-name></person-group>, &#x201C;<article-title>Enhanced clustering models with wiki-based k-neared neighbors-based representation for web search result clustering</article-title>,&#x201D; <source>Journal of King Saud University</source>, vol. <volume>8</volume>, no. <issue>3</issue>, pp. <fpage>878</fpage>&#x2013;<lpage>891</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Fook</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Rahman</surname></string-name>, <string-name><given-names>N. S.</given-names> <surname>Sani</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Adam</surname></string-name></person-group>, &#x201C;<article-title>Resource optimization using multithreading in support vector machine</article-title>,&#x201D; <source>International Journal of Advanced Computer Science and Applications</source>, vol. <volume>11</volume>, no. <issue>4</issue>, pp. <fpage>356</fpage>&#x2013;<lpage>359</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G. M.</given-names> <surname>Alathamneh</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abdullah</surname></string-name> and <string-name><given-names>N. S.</given-names> <surname>Sani</surname></string-name></person-group>, &#x201C;<article-title>Genetic algorithm selection strategies based rough set for attribute reduction</article-title>,&#x201D; <source>International Journal of Computer Science and Network Security</source>, vol. <volume>19</volume>, no. <issue>9</issue>, pp. <fpage>187</fpage>&#x2013;<lpage>194</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Bashir</surname></string-name>, <string-name><given-names>M. H.</given-names> <surname>Alsharif</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Albreem</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Sali</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>MIMO-terahertz in 6G nano-communications: Channel modeling and analysis</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>66</volume>, no. <issue>1</issue>, pp. <fpage>263</fpage>&#x2013;<lpage>274</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Alsafasfeh</surname></string-name>, <string-name><given-names>O. A.</given-names> <surname>Saraereh</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Ali</surname></string-name>, <string-name><given-names>L. A.</given-names> <surname>Tarawneh</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Khan</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Efficient power control framework for small-cell heterogeneous networks</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>20</volume>, no. <issue>5</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>14</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K. M.</given-names> <surname>Awan</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Nadeem</surname></string-name>, <string-name><given-names>A. S.</given-names> <surname>Sadiq</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Alghushami</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Khan</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Smart handoff technique for internet of vehicles communication using dynamic edge-backup node</article-title>,&#x201D; <source>Electronics</source>, vol. <volume>9</volume>, no. <issue>3</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>17</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Shahjehan</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Bashir</surname></string-name>, <string-name><given-names>S. L.</given-names> <surname>Mohammed</surname></string-name>, <string-name><given-names>A. B.</given-names> <surname>Fakhri</surname></string-name>, <string-name><given-names>A. A.</given-names> <surname>Isaiah</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Efficient modulation scheme for intermediate relay-aided IoT networks</article-title>,&#x201D; <source>Applied Sciences</source>, vol. <volume>10</volume>, no. <issue>6</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>12</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B. M.</given-names> <surname>Lee</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Patil</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Hunt</surname></string-name> and <string-name><given-names>I.</given-names> <surname>Khan</surname></string-name></person-group>, &#x201C;<article-title>An easy network onboarding scheme for internet of things network</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, pp. <fpage>8763</fpage>&#x2013;<lpage>8772</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>O. A.</given-names> <surname>Saraereh</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Alsaraira</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Khan</surname></string-name> and <string-name><given-names>B. J.</given-names> <surname>Choi</surname></string-name></person-group>, &#x201C;<article-title>A hybrid energy harvesting design for on-body internet-of-things (IoT) networks</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>20</volume>, no. <issue>2</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>14</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A. A.</given-names> <surname>Nimrat</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Smadi</surname></string-name>, <string-name><given-names>O. A.</given-names> <surname>Saraereh</surname></string-name> and <string-name><given-names>I.</given-names> <surname>Khan</surname></string-name></person-group>, &#x201C;<article-title>An efficient channel estimation scheme for mmWave massive MIMO systems</article-title>,&#x201D; in <conf-name>IEEE Int. Conf. on Communications, Networks and Satellite (Comnetsat)</conf-name>, <conf-loc>Makassar, Indonesia</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Sun</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Cheng</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Wang</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Energy-efficient routing algorithm based on small-world characteristics</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>69</volume>, no. <issue>2</issue>, pp. <fpage>2749</fpage>&#x2013;<lpage>2759</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Yan</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Yu</surname></string-name> and <string-name><given-names>Q.</given-names> <surname>Gong</surname></string-name></person-group>, &#x201C;<article-title>Software-defined networking (SDN) and distributed denial of service (DDoS) attacks in cloud computing environments: A survey, some research issues, and challenges</article-title>,&#x201D; <source>IEEE Communication Surveys &#x0026; Tutorials</source>, vol. <volume>18</volume>, no. <issue>1</issue>, pp. <fpage>602</fpage>&#x2013;<lpage>622</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>An</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Su</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Lu</surname></string-name></person-group>, &#x201C;<article-title>Hypergraph clustering model-based association analysis of ddos attacks in fog computing intrusion detection system</article-title>,&#x201D; <source>EURASIP Journal on Wireless Communications and Networking</source>, vol. <volume>8</volume>, no. <issue>4</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>15</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Ibrahim</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Tarik</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Konstantinos</surname></string-name></person-group>, &#x201C;<article-title>Network slicing and softwarization: A survey on principles, enabling technologies, and solutions</article-title>,&#x201D; <source>IEEE Communications Surveys &#x0026; Tutorials</source>, vol. <volume>20</volume>, no. <issue>3</issue>, pp. <fpage>2429</fpage>&#x2013;<lpage>2453</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Yi</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>A comprehensive survey of network function virtualization</article-title>,&#x201D; <source>Computer Networks</source>, vol. <volume>133</volume>, no. <issue>5</issue>, pp. <fpage>212</fpage>&#x2013;<lpage>262</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Fonseca</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Bennesby</surname></string-name> and <string-name><given-names>E.</given-names> <surname>Mota</surname></string-name></person-group>, &#x201C;<article-title>A replication component for resilient openflow-based networking</article-title>,&#x201D; in <conf-name>IEEE Symp. on Network Operations and Management</conf-name>, <conf-loc>Washington DC, USA</conf-loc>, pp. <fpage>933</fpage>&#x2013;<lpage>939</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Kang</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Hong</surname></string-name></person-group>, &#x201C;<article-title>A flow-based method for abnormal network traffic detection</article-title>,&#x201D; in <conf-name>IEEE Symp. on Network Operations and Management</conf-name>,&#x00B8; <conf-loc>Washington DC, USA</conf-loc>, pp. <fpage>599</fpage>&#x2013;<lpage>612</lpage>, <year>2004</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Giseop</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Ilkyeun</surname></string-name></person-group>, &#x201C;<article-title>Adaptive ddos detector design using fast entropy computation method</article-title>,&#x201D; in <conf-name>IEEE 5th Int. Conf. on Innovative Mobile and Internet Services in Ubiquitous Computing</conf-name>, <conf-loc>Seoul, South Korea</conf-loc>, pp. <fpage>86</fpage>&#x2013;<lpage>93</lpage>, <year>2011</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Jun</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Ahn</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Kim</surname></string-name></person-group>, &#x201C;<article-title>DDoS attack detection by using packet sampling and flow features</article-title>,&#x201D; in <conf-name>IEEE 29th Annual ACM Symp. on Applied Computing</conf-name>, <conf-loc>New York, USA</conf-loc>, pp. <fpage>711</fpage>&#x2013;<lpage>712</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Kalkan</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Altay</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Gur</surname></string-name></person-group>, &#x201C;<article-title>JESS: Joint entropy based ddos defense scheme in sdn</article-title>,&#x201D; <source>IEEE Journal on Selected Areas in Communications</source>, vol. <volume>36</volume>, no. <issue>10</issue>, pp. <fpage>2358</fpage>&#x2013;<lpage>2372</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Kumar</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Tripathi</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Nehra</surname></string-name></person-group>, &#x201C;<article-title>SAFETY: Early detection and mitigation of tcp syn flood utilizing entropy in sdn</article-title>,&#x201D; <source>IEEE Transactions on Network and Service Management</source>, vol. <volume>15</volume>, no. <issue>4</issue>, pp. <fpage>1545</fpage>&#x2013;<lpage>1559</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Jiang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Cheng</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Gu</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Liu</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>XGBoost classifier for ddos attack detection and analysis in sdn-based cloud</article-title>,&#x201D; in <conf-name>IEEE Int. Conf. on Big Data and Smart Computing</conf-name>, <conf-loc>Shanghai, China</conf-loc>, pp. <fpage>251</fpage>&#x2013;<lpage>256</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Yang</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Zhao</surname></string-name></person-group>, &#x201C;<article-title>DDoS attack identification and defense using sdn based on machine learning method</article-title>,&#x201D; in <conf-name>IEEE 15th Int. Symp. on Pervasive Systems, Algorithms and Networks (I-SPAN)</conf-name>, <conf-loc>Yichang, China</conf-loc>, pp. <fpage>174</fpage>&#x2013;<lpage>178</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Mhamdi</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Mclernon</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zaidi</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Ghogho</surname></string-name></person-group>, &#x201C;<article-title>Deep learning approach for network intrusion detection in software defined networking</article-title>,&#x201D; in <conf-name>IEEE Int. Conf. on Wireless Networks and Mobile Communications</conf-name>, <conf-loc>Fez, Morocco</conf-loc>, pp. <fpage>258</fpage>&#x2013;<lpage>263</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Chen</surname></string-name> and <string-name><given-names>V.</given-names> <surname>Singh</surname></string-name></person-group>, &#x201C;<article-title>Entropy-based derivation of generalized distributions for hydrometeorological frequency analysis</article-title>,&#x201D; <source>Journal of Hydrology</source>, vol. <volume>557</volume>, no. <issue>1</issue>, pp. <fpage>699</fpage>&#x2013;<lpage>712</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Lutsiv</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Maksymyuk</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Beshley</surname></string-name>, <string-name><given-names>O.</given-names> <surname>Lavriv</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Andrushchak</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Deep semisupervised learning-based network anomaly detection in heterogeneous information systems</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>70</volume>, no. <issue>1</issue>, pp. <fpage>413</fpage>&#x2013;<lpage>431</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Kojima</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Toh</surname></string-name></person-group>, &#x201C;<article-title>A lagrangian-dnn relaxation: A fast method for computing tight lower bounds for a class of quadratic optimization problems</article-title>,&#x201D; <source>Mathematical Programming</source>, vol. <volume>156</volume>, no. <issue>1</issue>, pp. <fpage>161</fpage>&#x2013;<lpage>187</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Fan</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Qian</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Soong</surname></string-name></person-group>, &#x201C;<article-title>Multi-speaker modeling and speaker adaptation for dnn-based tts synthesis</article-title>,&#x201D; in <conf-name>IEEE Int. Conf. on Acoustics, Speech and Signal Processing</conf-name>, <conf-loc>South Brisbane, Australia</conf-loc>, pp. <fpage>4475</fpage>&#x2013;<lpage>4479</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Mhamdi</surname></string-name>, <string-name><given-names>D.</given-names> <surname>McLernon</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zaidi</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ghogho</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>DeepIDS: Deep learning approach for intrusion detection in software defined networking</article-title>,&#x201D; <source>Electronics Journal</source>, vol. <volume>9</volume>, no. <issue>9</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>18</lpage>, <year>2020</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>