<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">28287</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2022.028287</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>HDLIDP: A Hybrid Deep Learning Intrusion Detection and Prevention Framework</article-title>
<alt-title alt-title-type="left-running-head">HDLIDP: A Hybrid Deep Learning Intrusion Detection and Prevention Framework</alt-title>
<alt-title alt-title-type="right-running-head">HDLIDP: A Hybrid Deep Learning Intrusion Detection and Prevention Framework</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Fadel</surname><given-names>Magdy M.</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref><email>mfares@mans.edu.eg</email>
</contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>El-Ghamrawy</surname><given-names>Sally M.</given-names></name>
<xref ref-type="aff" rid="aff-2">2</xref>
</contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Ali-Eldin</surname><given-names>Amr M. T.</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Hassan</surname><given-names>Mohammed K.</given-names></name>
<xref ref-type="aff" rid="aff-3">3</xref>
</contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>El-Desoky</surname><given-names>Ali I.</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<aff id="aff-1"><label>1</label><institution>Computer Engineering and Systems Department, Faculty of Engineering, Mansoura University</institution>, <addr-line>Mansoura, 35516, DK</addr-line>, <country>Egypt</country></aff>
<aff id="aff-2"><label>2</label><institution>Head of Communications and Computer Engineering Department, MISR Higher Institute for Engineering and Technology</institution>, <addr-line>Mansoura, 35111, DK</addr-line>, <country>Egypt</country></aff>
<aff id="aff-3"><label>3</label><institution>Mechatronics Department, Faculty of Engineering, Horus University in Egypt (HUE)</institution>, <addr-line>New Damietta, 34517, DT</addr-line>, <country>Egypt</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Magdy M. Fadel. Email: <email>mfares@mans.edu.eg</email></corresp>
</author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2022-06-14"><day>14</day>
<month>06</month>
<year>2022</year></pub-date>
<volume>73</volume>
<issue>2</issue>
<fpage>2293</fpage>
<lpage>2312</lpage>
<history>
<date date-type="received">
<day>07</day>
<month>2</month>
<year>2022</year>
</date>
<date date-type="accepted">
<day>25</day>
<month>3</month>
<year>2022</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2022 Fadel et al.</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Fadel et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_28287.pdf"></self-uri>
<abstract>
<p>Distributed denial-of-service (DDoS) attacks are designed to interrupt network services such as email servers and webpages in traditional computer networks. Furthermore, the enormous number of connected devices makes it difficult to operate such a network effectively. Software defined networks (SDN) are networks that are managed through a centralized control system, according to researchers. This controller is the brain of any SDN, composing the forwarding table of all data plane network switches. Despite the advantages of SDN controllers, DDoS attacks are easier to perpetrate than on traditional networks. Because the controller is a single point of failure, if it fails, the entire network will fail. This paper offers a Hybrid Deep Learning Intrusion Detection and Prevention (HDLIDP) framework, which blends signature-based and deep learning neural networks to detect and prevent intrusions. This framework improves detection accuracy while addressing all of the aforementioned problems. To validate the framework, experiments are done on both traditional and SDN datasets; the findings demonstrate a significant improvement in classification accuracy.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Software defined networks (SDN)</kwd>
<kwd>distributed denial of service attack (DDoS)</kwd>
<kwd>signature-based detection</kwd>
<kwd>whale optimization algorism (WOA)</kwd>
<kwd>deep learning neural network classifier</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Nowadays, the increasing use of Internet services like, data centers, electronic trade and cloud computing [<xref ref-type="bibr" rid="ref-1">1</xref>,<xref ref-type="bibr" rid="ref-2">2</xref>], causes computer network&#x2019;s size increases drastically and becomes hardly managed. Software defined networks (SDN) with its centralized management [<xref ref-type="bibr" rid="ref-3">3</xref>,<xref ref-type="bibr" rid="ref-4">4</xref>], dynamic and programmable architecture becomes more suitable for huge networks rather than using traditional computer networks. The general working strategy of Distributed Denial of Service (DDoS) attacks depends on sending an enormous number of packets to network resources to hamper or even block the reachability of legitimate users [<xref ref-type="bibr" rid="ref-5">5</xref>,<xref ref-type="bibr" rid="ref-6">6</xref>]. However, by deeply studying the structure of both computer networks architecture (traditional and SDN), DDoS attacks specific to SDN characterized by some points. First, SDN attacks aim to exhaust only the network&#x2019;s controller, while traditional networks have many points where attacks can be launched [<xref ref-type="bibr" rid="ref-7">7</xref>]. Second, the attacking packets usually pretend to have fake destination IP addresses, but in traditional networks, the destination IP addresses should be the IP of the targeted server to down [<xref ref-type="bibr" rid="ref-7">7</xref>].</p>
<p>Most of the detection and defense techniques used with SDN are literally a transplanting of traditional network techniques without taking in account the own characteristics of SDN environments. The processes of attack detection and defense are implemented on the SDN controller which increases computation overhead on the processor as well as the communication between SDN controller and switches (south bound) [<xref ref-type="bibr" rid="ref-7">7</xref>]. Several optimization techniques have been deployed to overcome these problems, as Genetic Algorithm (GA) [<xref ref-type="bibr" rid="ref-8">8</xref>], Firefly Algorithm (FF) [<xref ref-type="bibr" rid="ref-9">9</xref>], Particle Swarm Optimization (PSO) [<xref ref-type="bibr" rid="ref-10">10</xref>] and Whale Optimization Algorithm (WOA) [<xref ref-type="bibr" rid="ref-11">11</xref>]. Many of them have their limitations; such GA is more complex, depends on the initial population, and may fail to parameter convergence [<xref ref-type="bibr" rid="ref-8">8</xref>]. PSO has a poor control on discrete optimization problems and easy falls in local optima [<xref ref-type="bibr" rid="ref-10">10</xref>]. Due to these limitations, many hybridized and improved techniques have been applied to the original versions of Machine Learning (ML) to enhance their performance.</p>
<p>This paper deploys the detection of suspicious traffic at the data plane (switches) to alleviate both processing and communication overhead. The process of classifying suspicious packets executed at the controller plane is carried out by two techniques, signature-based [<xref ref-type="bibr" rid="ref-5">5</xref>,<xref ref-type="bibr" rid="ref-12">12</xref>] and deep learning-based to improve the accuracy and reduce the time of the classification process [<xref ref-type="bibr" rid="ref-13">13</xref>&#x2013;<xref ref-type="bibr" rid="ref-15">15</xref>]. In signature-based technique every packet passes through the network have a unique pattern (signature) that is composed by intermediate routers while traversing through the network [<xref ref-type="bibr" rid="ref-16">16</xref>]. Signatures of malicious packets are stored in an attack signatures database, to be used later for identifying any attack packet that has a signature included in it. This technique has a high accuracy and a low false negative rate, but can&#x2019;t detect new (day zero) attacking packets that are not involved in the attack signatures database [<xref ref-type="bibr" rid="ref-17">17</xref>].</p>
<p>An optimized Neural Network (NN) with a set of optimal extracted features is used to classify and detect new offensive packets as part of the proposed deep learning technique. Combining both techniques allows the network to learn new attack patterns and append them to the attack signature database automatically for future use [<xref ref-type="bibr" rid="ref-13">13</xref>]. The contribution of this paper is as follows:
<list list-type="bullet">
<list-item>
<p>Developing DDoS attack detection system that uses both signature-based and deep learning techniques to enhance the detection accuracy in SDN networks.</p></list-item>
<list-item>
<p>Using the Neural Network to select the effective traffic feature set and to tune it (number of hidden layers and number of neurons in each layer), for decreasing the detection time and increasing the accuracy of the detection process.</p></list-item>
<list-item>
<p>Validating the proposed framework using both traditional and SDN datasets to ensure it can handle both environments.</p></list-item>
</list></p>
<p>The remainder of this paper is organized as follow: the next section gives an overview of the related work, Section 3 describes the proposed framework in detail, Section 4 presents the experimental results and performance evaluation and finally Section 5 concludes the paper.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Works</title>
<p>Different detection and defense approaches are implemented by research community of defense since the first reported DDoS attacks in 1999 [<xref ref-type="bibr" rid="ref-18">18</xref>]. This section discusses two integrated categories of anomaly-based detection techniques, statistical approaches and artificial intelligence approaches.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Statistical Detection Approaches</title>
<p>Also called entropy-based approaches, entropy is the measure of the randomness in a dataset. Since every feature of normal network traffic has a special distribution pattern, for example a balance between the count of source and destination IP addresses in normal flow. This entropy pattern will deviate in attack flows since the number of destination IP addresses greatly increases than the number of source IP addresses. Despite this approach is characterized by a fast response and a low computation overhead of processing a large traffic volume. Its detection accuracy is greatly affected by the proper selection of the threshold value for a certain traffic feature to reduce the ratios of false positive and false negative.</p>
<p>In [<xref ref-type="bibr" rid="ref-19">19</xref>] authors proposed a hybrid system for attack detection that merges both entropy and traffic volume characteristics, which offers good results than using each technique alone. Kalkan et al. [<xref ref-type="bibr" rid="ref-20">20</xref>] introduced a joint entropy-based scoring system (JESS) to defend attacks in SDN environments, by utilizing Joint entropy they can defend even unfamiliar attacks efficiently. Lima et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] suggested a system based on statistical analysis of traffic entropy in SDN environments.</p>
<p>Wang et al. [<xref ref-type="bibr" rid="ref-22">22</xref>] proposed a flow statistics process in SDN switches, then performed lightweight entropy-based detection model executed in the edge switches to reduce the communication overhead between the data plane and controller plane. Ahmed et al. [<xref ref-type="bibr" rid="ref-23">23</xref>] introduced a new structure called application fingerprints to express packet attributes and traffic flow level statistics to differentiate legitimate packets from attack packets. However, this approach is not proper for online systems, since some flow attributes such total bytes, number of packets between source and destination and flow duration cannot compute their statistics while gathering them. In [<xref ref-type="bibr" rid="ref-24">24</xref>] authors introduced new hybrid approaches where flow level statistics or entropy based are combined with some techniques of Machine Learning (ML) or Artificial Neural Networks (ANN) to overcome some limitations of flow statistics approaches. The ML and ANN mechanisms will be introduced in detail in the next subsection.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Artificial Intelligence (AI) Detection Approaches</title>
<p>Buczak et al. [<xref ref-type="bibr" rid="ref-25">25</xref>] introduced summaries for different methods of Machine Learning (ML) and Data Mining (DM) used for attack detection, such Support Vector Machine (SVM), k-Nearest Neighbor (k-NN), Random Forest (RF), etc. over recent years, with the abundance of real network traffic datasets. These methods perform better results in traffic classification field.</p>
<p>He et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] suggested a new source side (active defense) machine learning technique instead of defending attacks at destination side (passive defense) preventing malicious network flows from being sent outside the attacking network. This showed a high accuracy and low false positive rates. Hoon et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] introduced the concept of dataset feature selection which reduces the feature engineering processes and increasing classification accuracy. Few papers addressed the implementation of Deep Learning (DL) approaches in attack detection; authors in [<xref ref-type="bibr" rid="ref-28">28</xref>] combined the entropy-based techniques with DL methods to easily control the problem of setting accurate threshold. Conducted experiments showed a high accuracy. Yin et al. [<xref ref-type="bibr" rid="ref-29">29</xref>] proposed a deep learning attack detection model deploying a Recurrent Neural Network (RNN) to perform binary and multiclass classification. They compared its performance with a set of known Machine Learning (ML) models such SVM, Random Forest (RF) and Artificial Neural Networks (ANN). Their proposed model showed a higher performance from point of accurate classification. Wu et al. [<xref ref-type="bibr" rid="ref-30">30</xref>] introduced a multiclass Convolutional Neural Network (CNN) intrusion detection system, deploying CNN to select highly related features from the massive data gathered to improve the classification accuracy and reduce computation overload. Over traditional ML algorithms, CNN showed better performance. Kwon et al. [<xref ref-type="bibr" rid="ref-31">31</xref>] studied the performance of three different models of CNN (shallow, moderate and deep) to check the effect of depth of the CNN to the detection performance. The models are verified using two datasets NSL-KDD [<xref ref-type="bibr" rid="ref-32">32</xref>] and MAWILab [<xref ref-type="bibr" rid="ref-33">33</xref>] showing that shallow CNN model with a single convolutional layer and single maximum pooling layer performed best.</p>
<p>Authors in [<xref ref-type="bibr" rid="ref-34">34</xref>] converted the suspicious traffic traces into arrays that contain flow features by combining both CNNs and RNNs, testing their model on ISCX2012 dataset [<xref ref-type="bibr" rid="ref-35">35</xref>] showing good results from point of reducing classification error from 7.517% to 2.103% relative to conventional machine learning algorithms. Despite the efficiency of deep learning algorithms for detecting DDoS attacks, they are time-consuming, resource-intensive, and require large numbers of model parameters to be trained.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>The Proposed Hybrid Deep Learning Intrusion Detection and Prevention (HDLIDP) Framework</title>
<p>Traditional networks&#x2019; routers are assigned many customary duties like determining packets routes, assigning priorities, carrying out policies specified by the network administrator and many others, so they cannot detect and respond to DDoS attacks automatically. By leveraging SDN architecture, these attacks can be processed automatically and yield a fast and accurate response. <xref ref-type="fig" rid="fig-1">Fig. 1</xref> illustrates that.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Traditional <italic>vs</italic>. SDN network architectures</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-1.png"/>
</fig>
<p>Three layers SDN architecture is show in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, the switching task is split between a data layer and a control layer that are implemented on separate devices. The data plane is mainly responsible for forwarding network packets, while the brain or control plane performs all intelligent tasks in the network. In standard SDN, the control layer performs both the attack detection and defense tasks this may increase the controller&#x2019;s CPU utilization and communication workload through southbound interface, observe hourly the traffic flowing through switches to detect the DDoS attack.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>SDN three layers architecture</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-2.png"/>
</fig>
<p>The proposed framework (HDLIDP) may help to overcome this defect. It is made up of two layers, Data Layer Detection (DLD) and Control Layer Defense (CLD) as depicted in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>The proposed (HDLIDP) framework</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-3.png"/>
</fig>
<sec id="s3_1">
<label>3.1</label>
<title>Data Layer Detection (DLD)</title>
<p>This layer detects any suspicious flows and raises an alarm to the control layer for accurately classifying whether it is an actual DDoS attack or legitimate burst traffic then carrying out proper response. This way the load on CPU Controller and the traffic overload through southbound interface may decrease drastically, it is designed as two modules:</p>
<sec id="s3_1_1">
<label>3.1.1</label>
<title>Legitimate Traffic Module</title>
<p>Packets in SDN arrive first at the data plane devices, these packets may be classified into four categories: Known traffic that is already found in the switch&#x2019;s forwarding table; hence it is forwarded to its proper destination. The second type is a new legitimate traffic, when the switch does not find matching entries in its forwarding table, and after sending a pktIN message to the controller it will get a reply with a suitable forwarding route to be registered in its forwarding table for future use. The other two categories occur when the switch receives a suspicious packet. Such a packet does not have a matching entry in the forwarding table, and the controller does not able to determine its forwarding route, due to tampering in the source and/or destination IP addresses of it. All DDoS detection systems are concerned about the arrival rate of the last two categories of received packets (suspicious).</p>
</sec>
<sec id="s3_1_2">
<label>3.1.2</label>
<title>Suspicious Traffic Module</title>
<p>The maximum packets counter method is utilized at the data plane to calculate the suspicious packet&#x2019;s arrival rate within a predefined time window. In the framework, when a switch classifies the received packet as a suspicious flow, the suspicious flow counter is incremented (Susp&#x002B;&#x002B;) and its features appended in both current interval and training datasets. Then, the value of the Susp variable is compared with the value of predefined adaptive maximum attacking packets (Val). The detection is in safe condition if Susp value is less than Val, so dropping this packet and processing any new incoming one.</p>
<p>Otherwise, if Susp equals or exceeds the predefined value (Val), the detection system calculates the time window, packets&#x2019; arrival rate (PR) and initializes all counters. If the packets&#x2019; arrival rate (PR) exceeds the predefined value, a suspicious alarm is raised to the control layer.</p>
</sec>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Control Layer Defense (CLD):</title>
<p>This layer is composed of two modules, Signature Based Detection and Deep Learning Classification.</p>
<sec id="s3_2_1">
<label>3.2.1</label>
<title>Signature Based Detection Module</title>
<p>Traceback enabled routers utilize one of two techniques to insert their identification ID numbers in the packet&#x2019;s header, Deterministic Packet Marking (DPM) [<xref ref-type="bibr" rid="ref-36">36</xref>] or Probabilistic Packet Marking (PPM) [<xref ref-type="bibr" rid="ref-37">37</xref>]. The accumulation of all IDs along the packet&#x2019;s path forms what is called path&#x2019;s signature. It is used to characterize the exact route of received packet regardless of its source IP address that could be easily forged. After isolating attacking traffic, its signature is stored in attack signature database for future use.</p>
</sec>
<sec id="s3_2_2">
<label>3.2.2</label>
<title>Deep Learning Classification Module</title>
<p>Is the conclusive classification stage that identifies the fourth category of suspicious packets. Because of the large-scale exploration of the search space, the simplicity of implementation, the wide range of applications and its potential development [<xref ref-type="bibr" rid="ref-10">10</xref>], the Whale Optimization Algorithm (WOA) is used to select the optimal set of features and to tune parameters of the classification Neural Network.</p>
<p>The WOA is an optimization algorithm that mimics the hunting mechanism of humpback whales in nature. Whales prefer to hunt in a group of whales, initially every whale searches globally for a prey in a random direction, this process is called exploration phase, the following mathematical model illustrates it.
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mrow><mml:mover><mml:mi>D</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mover><mml:mi>C</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:msub><mml:mrow><mml:mover><mml:mi>X</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mover><mml:mi>X</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mrow><mml:mover><mml:mi>X</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>X</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mover><mml:mi>A</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mover><mml:mi>D</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:math></disp-formula>where: <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>rand</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is a random position vector (random whale) and t indicates the current iteration.</p>
<p>Since the optimum position of the prey in the search space is not known previously, the group of whales will communicate to identify the current best elected solution. The other whales will update their direction towards the current elected whale; this step is called exploitation phase, modeled as follows:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mover><mml:msup><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:msup><mml:mrow><mml:mtext>e</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>bt</mml:mtext></mml:mrow></mml:mrow></mml:msup><mml:mi>cos</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:mi mathvariant="normal">&#x03C0;</mml:mi></mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mover><mml:msup><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where: <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mrow><mml:mover><mml:msup><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mover><mml:msup><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula> indicating the i<sup>th</sup> of whale the prey (best solution obtained so far), b is constant defining the shape of legitimate spiral and t is a random number in [&#x2212;1,1].
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable columnalign="left left" rowspacing=".2em" columnspacing="1em" displaystyle="false"><mml:mtr><mml:mtd><mml:mrow><mml:mover><mml:msup><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mover><mml:mrow><mml:mtext>A</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mover><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mrow><mml:mtext>p</mml:mtext></mml:mrow><mml:mo>&#x003C;</mml:mo><mml:mn>0.5</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mover><mml:msup><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:msup><mml:mrow><mml:mtext>e</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>bt</mml:mtext></mml:mrow></mml:mrow></mml:msup><mml:mi>cos</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:mi mathvariant="normal">&#x03C0;</mml:mi></mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mover><mml:msup><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mrow><mml:mtext>p</mml:mtext></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mn>0.5</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math></disp-formula>where: p is a random number in [0,1].</p>
<p>In encircling prey, after defining the best search agent, the other search agents will try to update their positions towards the best search agent. This behavior is represented by the following equations:
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mrow><mml:mover><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mover><mml:mrow><mml:mtext>C</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo>.</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>P</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>|</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>P</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mover><mml:mrow><mml:mtext>A</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo>.</mml:mo><mml:mrow><mml:mover><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:math></disp-formula>where: <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>P</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the position vector of the prey, <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mrow><mml:mover><mml:mrow><mml:mtext>X</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:math></inline-formula> is the position vector of a whale and <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mrow><mml:mover><mml:mrow><mml:mtext>A</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mspace width="0.2em"/><mml:mtext>and</mml:mtext><mml:mspace width="0.2em"/></mml:mrow><mml:mrow><mml:mover><mml:mrow><mml:mtext>C</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:math></inline-formula> are coefficient vectors.</p>
<p>The pseudo of WOA is shown in Algorithm 1.</p>
<fig id="fig-11">
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-11.png"/>
</fig>
<p><xref ref-type="fig" rid="fig-4">Fig. 4</xref> represents the four stages deployed to determine the status of the received packet. The first two stages (searching the switch&#x2019;s forwarding table and inquiring the controller to specify the packet forwarding path) are performed by any standard SDN environment. While the other two stages (search attack signature DB and a deep learning classification) are appended. Algorithm 2 and the logic diagram of the received packet flow status in <xref ref-type="fig" rid="fig-4">Fig. 4</xref> clarify the classification process in detail.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Received packet flow status</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-4.png"/>
</fig>
<fig id="fig-12">
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-12.png"/>
</fig>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Experiments and Evaluation</title>
<p>A hybrid classification algorithm composed of Whale Optimization Algorithm (WOA) in <xref ref-type="table" rid="table-1">Tab. 1</xref> and a tuned Neural Network (NN) in <xref ref-type="table" rid="table-2">Tab. 2</xref> is used in experiments. WOA is used to select the most effective set of features from the used datasets, whereas the tuned ANN is used to accurately classify the newly unknown suspicious packets, reducing the computation overhead and increasing the IDS classification accuracy.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Configuration values for the WOA optimizer</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Configuration</th>
<th>Value</th>
</tr>
</thead>
<tbody>
<tr>
<td>MaxIter</td>
<td>500</td>
</tr>
<tr>
<td>SearchAgentsNo</td>
<td>50</td>
</tr>
<tr>
<td>Dimension</td>
<td>No. of selected features from the dataset</td>
</tr>
<tr>
<td>No. of run repetitions</td>
<td>20</td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Parameters of the NN structure</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Structure Parameters</th>
<th>Value</th>
</tr>
</thead>
<tbody>
<tr>
<td>No. of hidden layers</td>
<td>1 or 2 or 3</td>
</tr>
<tr>
<td>No. of neurons</td>
<td>10</td>
</tr>
<tr>
<td>Biases</td>
<td>Random</td>
</tr>
<tr>
<td>Activation function</td>
<td>TanH</td>
</tr>
<tr>
<td>Initial weights</td>
<td>Default</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s4_1">
<label>4.1</label>
<title>Benchmark Dataset</title>
<p>The framework is evaluated using three datasets, NSL-KDD and CSE-CIC-IDS2018 are the most traditional network&#x2019;s datasets commonly used, where the third is SDN specific dataset. First, NSL-KDD dataset contains 4,898,430 records each of 41 features. Feature no. 42 is the records&#x2019; labels, which may be Normal or attack; attack records are categorized into 4 types DoS, Probe, R2L or U2R.</p>
<p>Despite its simplicity, NSL-KDD dataset is not the ideal representation of the actual network model, so CIC-IDS2018 dataset is used to accurately evaluate any IDS since it represents real attacks. It has 83 features, of 2,830,540 distinct records, and categorized in the label field to 15 classes.</p>
<p>Although the characteristics of CIC-IDS2018 dataset have some weaknesses, first with this huge number of records (3,119,345) and 83 features each, enormous loading and processing overhead is required. Second, it contains some missing data. The last demerit is class imbalance problem [<xref ref-type="bibr" rid="ref-38">38</xref>], in which different attacking classes do not have equal number of instances, some are represented by a large number (BENIGN &#x003D; 2,359,087 instances) others have few number (HeartBleed &#x003D; 11 instances). So, when using this dataset for training classifiers or detectors it will make the classifiers biasing toward the majority class [<xref ref-type="bibr" rid="ref-38">38</xref>] degrading the classifier&#x2019;s accuracy with a higher false ratio. Alleviating methods for these shortcomings will be introduced in the Data preprocessing subsection.</p>
<p>Since the architecture of traditional network differs from that of SDN, which results in a major difference in the feature sets of the data gathered from both. Mininet emulator [<xref ref-type="bibr" rid="ref-39">39</xref>] software has been used to create a realistic virtual network, 23 features in the designed SDN topology with the total number and different categories used in following experiments.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Data Preprocessing</title>
<p>Network collected dataset may include some error values like duplicate, infinity, missing or categorical data, this may cause classification problems. These error values should be eliminated or mitigated before training and testing phase. Duplicate records should be removed, deleting records having outlier&#x2019;s values. Techniques like one-hot encoder are used to convert categorical data into numeric values.</p>
<p>Feature scaling methods (Normalization and Standardization) [<xref ref-type="bibr" rid="ref-40">40</xref>]: features having values of varying degrees of magnitude, may hurdle the performance of some machine learning algorithms especially those types using gradient descent as optimization techniques. So, these scaling methods may be used to scale their values between 0 and 1, or &#x002B;a and &#x2013;a.</p>
<p>Data imbalance reduction [<xref ref-type="bibr" rid="ref-41">41</xref>]: where some features are highly underrepresented, causing the classifier to bias towards the majority features. Many techniques are designed to handle class imbalance problem, one of them deployed in this paper is class relabeling. By either splitting the majority classes into more classes or merging some minority classes to form one class.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Evaluation Metrics</title>
<p>Evaluating the trained model&#x2019;s performance can be done using the confusion matrix and advanced evaluation metrics are shown in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Confusion matrix and evaluation metrics</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-5.png"/>
</fig>
<p>True Positive (TP): denotes the no. of positive class correctly judged as positive. False Negative (FN): denotes the no. of positive class mistakenly judged as negative. False Positive (FP): denotes the no. of negative class mistakenly judged as positive. True Negative (TN): denotes the no. of negative class correctly judged as negative.</p>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Experimental Results</title>
<p>Three experiments have been conducted to validate the performance of the (HDLIDP) framework.</p>
<p><bold>Experiment 1: (NSL-KDD dataset):</bold> using a two hidden layers tuned ANN classifier.</p>
<p><xref ref-type="table" rid="table-4">Tab. 4</xref> shows the advanced metrics obtained from the confusion matrix shown in <xref ref-type="table" rid="table-3">Tab. 3</xref>. The average results of confusion matrix when utilizing two hidden layers are 97.903, 91.690, 98.271 and 94.798 for Accuracy, Precision, Recall and F1 Score, respectively.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Confusion matrix of NSL-KDD classifier of two hidden layers</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<th>Actual class</th>
<td>Normal</td>
<td>491</td>
<td>19</td>
<td>5</td>
<td>1</td>
<td>0</td>
<td>516</td>
</tr>
<tr>
<td/>
<td>DoS</td>
<td>17</td>
<td>358</td>
<td>4</td>
<td>1</td>
<td>0</td>
<td>380</td>
</tr>
<tr>
<td/>
<td>Probe</td>
<td>3</td>
<td>1</td>
<td>86</td>
<td>0</td>
<td>1</td>
<td>91</td>
</tr>
<tr>
<td/>
<td>R2L</td>
<td>0</td>
<td>1</td>
<td>0</td>
<td>12</td>
<td>0</td>
<td>13</td>
</tr>
<tr>
<td/>
<td>U2R</td>
<td>0</td>
<td>0</td>
<td>0</td>
<td>0</td>
<td>11</td>
<td>11</td>
</tr>
<tr>
<td/>
<td style="background:#FFFFFF;">&#x2211;</td>
<td>511</td>
<td>379</td>
<td>95</td>
<td>14</td>
<td>12</td>
<td><bold>1,011</bold></td>
</tr>
<tr>
<td/>
<td/>
<td>Normal</td>
<td>DoS</td>
<td>Probe</td>
<td>R2L</td>
<td>U2R</td>
<td>&#x2211;</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td colspan="5" align="center"><bold>Predicted class</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>NSL-KDD metrics of the above confusion matrix</title>
</caption>
<table frame="hsides">
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th rowspan="2">No.</th>
<th rowspan="2">New labels</th>
<th colspan="4" align="center">Confusion matrix metrics</th>
<th colspan="4" align="center">Advanced evaluation metrics (%)</th>
</tr>
<tr>
<th>TP</th>
<th>FN</th>
<th>FP</th>
<th>TN</th>
<th>Acc.</th>
<th>Pre.</th>
<th>Recall</th>
<th>F1</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td>Normal</td>
<td>491</td>
<td>25</td>
<td>20</td>
<td>475</td>
<td>95.549</td>
<td>96.086</td>
<td>95.960</td>
<td>96.023</td>
</tr>
<tr>
<td>2</td>
<td>DoS</td>
<td>358</td>
<td>22</td>
<td>21</td>
<td>610</td>
<td>95.747</td>
<td>94.459</td>
<td>96.672</td>
<td>95.553</td>
</tr>
<tr>
<td>3</td>
<td>Probe</td>
<td>86</td>
<td>5</td>
<td>9</td>
<td>911</td>
<td>98.615</td>
<td>90.526</td>
<td>99.022</td>
<td>94.584</td>
</tr>
<tr>
<td>4</td>
<td>R2L</td>
<td>12</td>
<td>1</td>
<td>2</td>
<td>996</td>
<td>99.703</td>
<td>85.714</td>
<td>99.800</td>
<td>92.222</td>
</tr>
<tr>
<td>5</td>
<td>U2R</td>
<td>11</td>
<td>0</td>
<td>1</td>
<td>999</td>
<td>99.901</td>
<td>91.667</td>
<td>99.900</td>
<td>95.607</td>
</tr>
<tr>
<td colspan="6" align="center"><bold>Summation</bold></td>
<td>489.515</td>
<td>458.452</td>
<td>491.354</td>
<td>473.989</td>
</tr>
<tr>
<td colspan="6" align="center"><bold>Average</bold></td>
<td><bold>97.903</bold></td>
<td><bold>91.690</bold></td>
<td><bold>98.271</bold></td>
<td><bold>94.798</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-5">Tab. 5</xref> and <xref ref-type="fig" rid="fig-6">Figs. 6</xref> and <xref ref-type="fig" rid="fig-7">7</xref> show the parameters of the ANN classification in case of single, two and three hidden layers compared with the Genetic Algorithm (GA) and Difficult Set Sampling Technique (DSSTE) algorithm. The DSSTE algorithm employs both Edited Nearest Neighbor (ENN) and K-Means clustering algorithms to reduce the data set&#x2019;s majority class for improving the classifier&#x2019;s training stage consequently enhances performance. The results show, using two hidden layers NN each contains maximum of 10 neurons provides best performance and approximately good time.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>NSL-KDD comparison results among different classifier structures</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th rowspan="2">Neural network structure</th>
<th colspan="5">NSL-KDD (%)</th>
</tr>
<tr>
<th>Acc.</th>
<th>Pre.</th>
<th>Recall</th>
<th>F1</th>
<th>Time(S)</th>
</tr>
</thead>
<tbody>
<tr>
<td>1 Hidden layer</td>
<td>96.396</td>
<td>85.988</td>
<td>97.016</td>
<td>90.989</td>
<td>8</td>
</tr>
<tr>
<td>2 Hidden layer</td>
<td><bold>97.903</bold></td>
<td><bold>91.690</bold></td>
<td><bold>98.271</bold></td>
<td><bold>94.798</bold></td>
<td><bold>11</bold></td>
</tr>
<tr>
<td>3 Hidden layer</td>
<td>96.987</td>
<td>89.121</td>
<td>97.821</td>
<td>92.813</td>
<td>15</td>
</tr>
<tr>
<td>Genetic algorithm</td>
<td>79.564</td>
<td>76.154</td>
<td>78.841</td>
<td>76.783</td>
<td>21</td>
</tr>
<tr>
<td>DSSTE [<xref ref-type="bibr" rid="ref-42">42</xref>]</td>
<td>82.840</td>
<td>84.680</td>
<td>82.780</td>
<td>81.660</td>
<td>&#x2013;</td>
</tr>
</tbody>
</table>
</table-wrap>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>NSL-KDD comparison results among deep learning classifier with different hidden layers</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-6.png"/>
</fig>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>NSL-KDD Time comparison results among DL classifier with different hidden layers</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-7.png"/>
</fig>
<p><bold>Experiment 2: (CIC-IDS2018 dataset):</bold> using a two hidden layers tuned ANN classifier.</p>
<p><xref ref-type="table" rid="table-6">Tabs. 6</xref> and <xref ref-type="table" rid="table-7">7</xref> show the average results of confusion matrix as 99.849, 93.333, 99.761 and 96.325 for Accuracy, Precision, Recall and F1 Score, respectively.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Confusion matrix of CIC-IDS2018 classifier of two hidden layers</title>
</caption>
<table frame="hsides">
<colgroup>
<col />
<col />
<col />
<col />
<col />
<col />
<col />
<col />
<col />
<col />
</colgroup>
<tbody>
<tr>
<td>Actual class</td>
<td>Normal</td>
<td>588,462</td>
<td>23</td>
<td>98</td>
<td>824</td>
<td>0</td>
<td>349</td>
<td>16</td>
<td>589,772</td>
</tr>
<tr>
<td/>
<td>Botnet ARES</td>
<td>0</td>
<td>490</td>
<td>0</td>
<td>0</td>
<td>1</td>
<td>0</td>
<td>0</td>
<td>491</td>
</tr>
<tr>
<td/>
<td>Brute Force</td>
<td>9</td>
<td>0</td>
<td>3,431</td>
<td>0</td>
<td>0</td>
<td>0</td>
<td>19</td>
<td>3,459</td>
</tr>
<tr>
<td/>
<td>DoS/DDoS</td>
<td>985</td>
<td>7</td>
<td>41</td>
<td>72,247</td>
<td>0</td>
<td>329</td>
<td>17</td>
<td>73,626</td>
</tr>
<tr>
<td/>
<td>Infiltration</td>
<td>0</td>
<td>0</td>
<td>0</td>
<td>0</td>
<td>9</td>
<td>0</td>
<td>0</td>
<td>9</td>
</tr>
<tr>
<td/>
<td>Port Scan</td>
<td>592</td>
<td>3</td>
<td>62</td>
<td>324</td>
<td>1</td>
<td>38,722</td>
<td>28</td>
<td>39,732</td>
</tr>
<tr>
<td/>
<td>Web Attack</td>
<td>0</td>
<td>1</td>
<td>0</td>
<td>1</td>
<td>0</td>
<td>3</td>
<td>540</td>
<td>545</td>
</tr>
<tr>
<td/>
<td style="background:#FFFFFF;">&#x2211;</td>
<td>590,048</td>
<td>524</td>
<td>3,632</td>
<td>73,396</td>
<td>11</td>
<td>39,403</td>
<td>620</td>
<td><bold>707,634</bold></td>
</tr>
<tr>
<td/>
<td></td>
<td>Normal</td>
<td>Botnet ARES</td>
<td>Brute Force</td>
<td>DoS/DDoS</td>
<td>Infiltra-tion</td>
<td>Port Scan</td>
<td>Web Attack</td>
<td>&#x2211;</td>
</tr>
<tr>
<td/>
<td></td>
<td></td>
<td colspan="7" align="center"><bold>Predicted class</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>CIC-IDS2018 metrics of the above confusion matrix</title>
</caption>
<table frame="hsides">
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>No.</th>
<th>New labels</th>
<th colspan="4" align="center">Confusion matrix metrics</th>
<th colspan="4" align="center">Advanced evaluation metrics (%)</th>
</tr>
<tr>
<th/>
<th/>
<th>TP</th>
<th>FN</th>
<th>FP</th>
<th>TN</th>
<th>Acc.</th>
<th>Pre.</th>
<th>Recall</th>
<th>F1</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td>Normal</td>
<td>588,462</td>
<td>1,310</td>
<td>1,586</td>
<td>116,276</td>
<td>99.591</td>
<td>99.731</td>
<td>98.654</td>
<td>99.190</td>
</tr>
<tr>
<td>2</td>
<td>Botnet ARES</td>
<td>490</td>
<td>1</td>
<td>34</td>
<td>707,109</td>
<td>99.995</td>
<td>93.511</td>
<td>99.995</td>
<td>96.644</td>
</tr>
<tr>
<td>3</td>
<td>Brute Force</td>
<td>3,431</td>
<td>28</td>
<td>201</td>
<td>703,974</td>
<td>99.968</td>
<td>94.466</td>
<td>99.971</td>
<td>97.141</td>
</tr>
<tr>
<td>4</td>
<td>DoS/DDoS</td>
<td>72,247</td>
<td>1,379</td>
<td>1,149</td>
<td>632,859</td>
<td>99.643</td>
<td>98.435</td>
<td>99.819</td>
<td>99.122</td>
</tr>
<tr>
<td>5</td>
<td>Infiltration</td>
<td>9</td>
<td>0</td>
<td>2</td>
<td>707,623</td>
<td>99.999</td>
<td>81.818</td>
<td>99.999</td>
<td>89.999</td>
</tr>
<tr>
<td>6</td>
<td>PortScan</td>
<td>38,722</td>
<td>1,010</td>
<td>681</td>
<td>667,221</td>
<td>99.761</td>
<td>98.272</td>
<td>99.898</td>
<td>99.078</td>
</tr>
<tr>
<td>7</td>
<td>Web Attack</td>
<td>540</td>
<td>5</td>
<td>80</td>
<td>707,009</td>
<td>99.988</td>
<td>87.097</td>
<td>99.989</td>
<td>93.099</td>
</tr>
<tr>
<td colspan="6" align="center"><bold>Summation</bold></td>
<td>698.945</td>
<td>653.330</td>
<td>698.325</td>
<td>674.273</td>
</tr>
<tr>
<td colspan="6" align="center"><bold>Average</bold></td>
<td><bold>99.849</bold></td>
<td><bold>93.333</bold></td>
<td><bold>99.761</bold></td>
<td><bold>96.325</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Since the framework has been designed to be deployed in real time world, so both performance accuracy and running time should be highly improved. From <xref ref-type="table" rid="table-8">Tab. 8</xref> and <xref ref-type="fig" rid="fig-8">Figs. 8</xref> and <xref ref-type="fig" rid="fig-9">9</xref>, show that the best accuracy is obtained when using two hidden layers NN, while the best running time obtained with a single hidden layer NN. According to the results obtained, it is advised to deploy the framework with two hidden layers NN as it has best accuracy and approximately good running time.</p>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>CIC-IDS2018 Comparison results among different classifiers structure</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th rowspan="2">Neural network structure</th>
<th colspan="5">CIC-IDS2018 (%)</th>
</tr>
<tr>
<th>Acc.</th>
<th>Pre.</th>
<th>Recall</th>
<th>F1</th>
<th>Time(S)</th>
</tr>
</thead>
<tbody>
<tr>
<td>1 Hidden layer</td>
<td>99.003</td>
<td>68.714</td>
<td>99.077</td>
<td>78.392</td>
<td>12</td>
</tr>
<tr>
<td>2 Hidden layer</td>
<td><bold>99.849</bold></td>
<td>93.333</td>
<td><bold>99.761</bold></td>
<td><bold>96.325</bold></td>
<td><bold>15</bold></td>
</tr>
<tr>
<td>3 Hidden layer</td>
<td>99.218</td>
<td>78.942</td>
<td>99.214</td>
<td>84.657</td>
<td>23</td>
</tr>
<tr>
<td>Genetic algorithm</td>
<td>93.154</td>
<td>71.458</td>
<td>94.345</td>
<td>76.845</td>
<td>34</td>
</tr>
<tr>
<td>DSSTE</td>
<td>96.990</td>
<td><bold>97.460</bold></td>
<td>96.970</td>
<td>97.040</td>
<td>&#x2013;</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In the next experiment, the proposed framework is evaluated using SDN dataset collected from the Mininet emulator and comparing its results with those of the framework introduced in [<xref ref-type="bibr" rid="ref-43">43</xref>].</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>CIC-IDS2018 comparison results among DL classifier with different hidden layers</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-8.png"/>
</fig>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>CIC-IDS time comparison results among DL classifier with different hidden layers</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-9.png"/>
</fig>
<p><bold>Experiment 3: (SDN dataset):</bold> the experiment has been done on a two hidden layers ANN classifier.</p>
<p><xref ref-type="table" rid="table-10">Tabs. 9</xref> and <xref ref-type="table" rid="table-10">10</xref> shows the average values of Accuracy, Precision, Recall and F1 Score.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Confusion matrix of SDN classifier of two hidden layers</title>
</caption>
<table frame="hsides">
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<tbody>
<tr>
<td>Actual class</td>
<td>Benign ICMP</td>
<td>24,352</td>
<td>125</td>
<td>146</td>
<td>81</td>
<td>178</td>
<td>75</td>
<td>24,957</td>
</tr>
<tr>
<td/>
<td>Malicious ICMP</td>
<td style="background:#FFFFFF;">119</td>
<td>15,945</td>
<td>91</td>
<td>50</td>
<td>108</td>
<td>51</td>
<td>16,364</td>
</tr>
<tr>
<td/>
<td>Benign TCP</td>
<td>147</td>
<td style="background:#FFFFFF;">89</td>
<td>18,405</td>
<td style="background:#FFFFFF;">63</td>
<td>132</td>
<td>61</td>
<td>18,897</td>
</tr>
<tr>
<td/>
<td>Malicious TCP</td>
<td>75</td>
<td style="background:#FFFFFF;">48</td>
<td style="background:#FFFFFF;">56</td>
<td>10,264</td>
<td>71</td>
<td>25</td>
<td>10,539</td>
</tr>
<tr>
<td/>
<td>Benign UDP</td>
<td>184</td>
<td style="background:#FFFFFF;">122</td>
<td style="background:#FFFFFF;">138</td>
<td style="background:#FFFFFF;">73</td>
<td>22,179</td>
<td>76</td>
<td>22,772</td>
</tr>
<tr>
<td/>
<td>Malicious UDP</td>
<td>79</td>
<td>51</td>
<td>60</td>
<td>30</td>
<td>72</td>
<td>10,524</td>
<td>10,816</td>
</tr>
<tr>
<td/>
<td><bold>&#x2211;</bold></td>
<td>24,956</td>
<td>16,380</td>
<td>18,896</td>
<td>10,561</td>
<td>22,740</td>
<td>10,812</td>
<td><bold>104,345</bold></td>
</tr>
<tr>
<td/>
<td></td>
<td>Benign ICMP</td>
<td>Malicious ICMP</td>
<td>Benign TCP</td>
<td>Malicious TCP</td>
<td>Benign UDP</td>
<td>Malicious UDP</td>
<td>&#x2211;</td>
</tr>
<tr>
<td/>
<td></td>
<td></td>
<td colspan="6" align="center"><bold>Predicted class</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>SDN metrics of the above confusion matrix</title>
</caption>
<table frame="hsides">
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th rowspan="2">No.</th>
<th rowspan="2">Traffic labels</th>
<th colspan="4">Confusion matrix metrics</th>
<th colspan="4">Advanced evaluation metrics (%)</th>
</tr>
<tr>
<th>TP</th>
<th>FN</th>
<th>FP</th>
<th>TN</th>
<th>Acc.</th>
<th>Pre.</th>
<th>Recall</th>
<th>F1</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td>Benign ICMP</td>
<td>24,352</td>
<td>605</td>
<td>604</td>
<td>78,784</td>
<td>98.841</td>
<td>97.580</td>
<td>99.239</td>
<td>98.403</td>
</tr>
<tr>
<td>2</td>
<td>Malicious ICMP</td>
<td>15,945</td>
<td>419</td>
<td>435</td>
<td>87,546</td>
<td>99.182</td>
<td>97.344</td>
<td>99.506</td>
<td>98.413</td>
</tr>
<tr>
<td>3</td>
<td>Benign TCP</td>
<td>18,405</td>
<td>492</td>
<td>491</td>
<td>84,957</td>
<td>99.058</td>
<td>97.402</td>
<td>99.425</td>
<td>98.403</td>
</tr>
<tr>
<td>4</td>
<td>Malicious TCP</td>
<td>10,264</td>
<td>275</td>
<td>297</td>
<td>93,509</td>
<td>99.452</td>
<td>97.188</td>
<td>99.683</td>
<td>98.420</td>
</tr>
<tr>
<td>5</td>
<td>Benign UDP</td>
<td>22,179</td>
<td>593</td>
<td>561</td>
<td>81,012</td>
<td>98.894</td>
<td>97.533</td>
<td>99.312</td>
<td>98.414</td>
</tr>
<tr>
<td>6</td>
<td>Malicious UDP</td>
<td>10,524</td>
<td>292</td>
<td>288</td>
<td>93,241</td>
<td>99.444</td>
<td>97.336</td>
<td>99.692</td>
<td>98.500</td>
</tr>
<tr>
<td colspan="6" align="center"><bold>Summation</bold></td>
<td>594.871</td>
<td>584.383</td>
<td>596.857</td>
<td>590.553</td>
</tr>
<tr>
<td colspan="6" align="center"><bold>Average</bold></td>
<td><bold>99.145</bold></td>
<td><bold>97.397</bold></td>
<td><bold>99.476</bold></td>
<td><bold>98.430</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-11">Tab. 11</xref> and <xref ref-type="fig" rid="fig-10">Fig. 10</xref> show a comparison in case of one, two and three hidden layers with the GA and Automated DDoS attack detection in SDN [<xref ref-type="bibr" rid="ref-43">43</xref>] framework.</p>
<table-wrap id="table-11">
<label>Table 11</label>
<caption>
<title>SDN Comparison results among different classifier structures</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th rowspan="2">Neural network structure</th>
<th colspan="4">NSL-KDD</th>
</tr>
<tr>
<th>Acc.</th>
<th>Pre.</th>
<th>Recall</th>
<th>F1</th>
</tr>
</thead>
<tbody>
<tr>
<td>1 Hidden Layer</td>
<td>99.000</td>
<td>96.950</td>
<td>99.388</td>
<td>98.153</td>
</tr>
<tr>
<td>2 Hidden Layer</td>
<td><bold>99.145</bold></td>
<td><bold>97.397</bold></td>
<td><bold>99.476</bold></td>
<td><bold>98.430</bold></td>
</tr>
<tr>
<td>3 Hidden Layer</td>
<td>99.060</td>
<td>97.102</td>
<td>99.413</td>
<td>98.211</td>
</tr>
<tr>
<td>Genetic Algorithm</td>
<td>96.201</td>
<td>94.253</td>
<td>97.142</td>
<td>95.981</td>
</tr>
<tr>
<td>Automated detection [<xref ref-type="bibr" rid="ref-43">43</xref>]</td>
<td>98.800</td>
<td>98.270</td>
<td>98.180</td>
<td>97.650</td>
</tr>
</tbody>
</table>
</table-wrap>
<fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>SDN comparison results among DL classifier with different hidden layers</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_28287-fig-10.png"/>
</fig>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusions and Future Work</title>
<p>Despite the importance of computer networks and its different services, it is difficult to manage and secure a huge number of distributed devices. A Hybrid Deep Learning Intrusion Detection and Prevention framework (HDLIDP) that is suitable for use with SDN networks has been proposed in this paper. Signature-based and deep learning detection techniques have been deployed to improve framework performance. A signature based technique ensure that a packet is an attack, but not that it is legitimate, while deep learning technique classifies packets based on their type, if it is an attacker or not, successfully taking the needed action. Both techniques may improve attack detection accuracy and speed. The outcomes are determined by important factors such as classification accuracy and system responsiveness. A comprehensive study has been conducted using three datasets that have been applied to single, two, and three layers NN classifiers. Additionally, we cannot ignore the role played by using the WOA optimizer in selecting the effective set of dataset&#x2019;s features for improving the classification process. Results revealed the superiority of the proposed framework, especially in cases of double NN hidden layers. In future, the proposed framework could be improved by deploying different optimization algorithms and evaluated by using more SDN environment datasets.</p>
</sec>
</body>
<back>
<fn-group>
<fn fn-type="other"><p><bold>Funding Statement:</bold> The authors received no specific funding for this study.</p>
</fn>
<fn fn-type="conflict"><p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Azizi</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Hashemi</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Khonsari</surname></string-name></person-group>, &#x201C;<article-title>A flexible and high-performance data center network topology</article-title>,&#x201D; <source>Supercomputing</source>, vol. <volume>73</volume>, no. <issue>4</issue>, pp. <fpage>1484</fpage>&#x2013;<lpage>1503</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Birje</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Challagidad</surname></string-name>, <string-name><given-names>R. H.</given-names> <surname>Goudar</surname></string-name> and <string-name><given-names>M. T.</given-names> <surname>Tapale</surname></string-name></person-group>, &#x201C;<article-title>Cloud computing review: Concepts, technology, challenges and security</article-title>,&#x201D; <source>International Journal of Cloud Computing</source>, vol. <volume>6</volume>, no. <issue>1</issue>, pp. <fpage>32</fpage>&#x2013;<lpage>57</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D. S.</given-names> <surname>Rana</surname></string-name>, <string-name><given-names>S. A.</given-names> <surname>Dhondiyaland</surname></string-name> and <string-name><given-names>S. K.</given-names> <surname>Chamoli</surname></string-name></person-group>, &#x201C;<article-title>Software defined networking (SDN) challenges, issues and solution</article-title>,&#x201D; <source>International Journal of Computer Science and Engineering</source>, vol. <volume>7</volume>, no. <issue>1</issue>, pp. <fpage>884</fpage>&#x2013;<lpage>889</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. H.</given-names> <surname>Haji</surname></string-name>, <string-name><given-names>S. R. M.</given-names> <surname>Zeebaree</surname></string-name>, <string-name><given-names>R. H.</given-names> <surname>Saeed</surname></string-name>, <string-name><given-names>S. Y.</given-names> <surname>Ameen</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Shukur</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Comparison of software defined networking with traditional networking</article-title>,&#x201D; <source>Asian Journal of Computer Science and Information Technology</source>, vol. <volume>9</volume>, no. <issue>2</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>18</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. M.</given-names> <surname>Fadel</surname></string-name>, <string-name><given-names>A. I.</given-names> <surname>El-Desoky</surname></string-name>, <string-name><given-names>A. Y.</given-names> <surname>Haikel</surname></string-name> and <string-name><given-names>L. M.</given-names> <surname>Labib</surname></string-name></person-group>, &#x201C;<article-title>A low-storage precise IP traceback technique based on packet marking and logging</article-title>,&#x201D; <source>Oxford University Press, The Computer Journal</source>, vol. <volume>59</volume>, no. <issue>11</issue>, pp. <fpage>1581</fpage>&#x2013;<lpage>1592</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. M.</given-names> <surname>Fadel</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Areed</surname></string-name> and <string-name><given-names>A. I.</given-names> <surname>El-Desoky</surname></string-name></person-group>, &#x201C;<article-title>A hybrid approach for detecting, preventing, and traceback DDoS attacks</article-title>,&#x201D; <source>WSEAS Transactions on Computers</source>, vol. <volume>11</volume>, no. <issue>7</issue>, pp. <fpage>191</fpage>&#x2013;<lpage>196</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Singh</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Behal</surname></string-name></person-group>, &#x201C;<article-title>Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions</article-title>,&#x201D; <source>ElSevier Computer Science Review</source>, vol. <volume>37</volume>, no. <issue>2</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>25</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Katoch</surname></string-name>, <string-name><given-names>S. S.</given-names> <surname>Chauhan</surname></string-name> and <string-name><given-names>V.</given-names> <surname>Kumar</surname></string-name></person-group>, &#x201C;<article-title>A review on genetic algorithm: Past, present, and future</article-title>,&#x201D; <source>Multimedia Tools and Applications</source>, vol. <volume>80</volume>, no. <issue>17</issue>, pp. <fpage>8091</fpage>&#x2013;<lpage>8126</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>W. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>N. N.</given-names> <surname>Hamadneh</surname></string-name>, <string-name><given-names>S. L.</given-names> <surname>Tilahun</surname></string-name> and <string-name><given-names>J. M. T.</given-names> <surname>Ngnotchouye</surname></string-name></person-group>, &#x201C;<chapter-title>A review and comparative study of Firefly algorithm and its modified versions</chapter-title>,&#x201D; in <source>Optimization Algorithms-Methods and Applications</source>, <edition>First</edition> ed., vol. <volume>1</volume>. <publisher-loc>London, United Kingdom</publisher-loc>: <publisher-name>IntechOpen Press</publisher-name>, pp. <fpage>281</fpage>&#x2013;<lpage>313</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Tan</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Ren</surname></string-name></person-group>, &#x201C;<article-title>Research on particle swarm optimization of variable parameter</article-title>,&#x201D; in <conf-name>Proc. Int, Conf. Advances on P2P, Parallel, Grid, Cloud and Internet Computing (3PGCIC 2016)</conf-name>, <conf-loc>Lecture Notes on Data Engineering and Communications Technologies, Springer, Cham, Germany</conf-loc>, vol. <volume>1</volume>, pp. <fpage>25</fpage>&#x2013;<lpage>33</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Mirjalili</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Lewis</surname></string-name></person-group>, &#x201C;<article-title>The whale optimization algorithm</article-title>,&#x201D; <source>Advances in Engineering Software</source>, vol. <volume>95</volume>, no. <issue>12</issue>, pp. <fpage>51</fpage>&#x2013;<lpage>67</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Kaur</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Kumar</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Bhandari</surname></string-name></person-group>, &#x201C;<article-title>A review of detection approaches for distributed denial of service attacks</article-title>,&#x201D; <source>Systems Science &#x0026; Control Engineering</source>, vol. <volume>5</volume>, no. <issue>1</issue>, pp. <fpage>301</fpage>&#x2013;<lpage>320</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Xie</surname></string-name>, <string-name><given-names>F. R.</given-names> <surname>Yu</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Xie</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Liu</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>A survey of machine learning techniques applied to software defined networking (SDN): Research issues and challenges</article-title>,&#x201D; <source>IEEE Communications Surveys &#x0026; Tutorials</source>, vol. <volume>21</volume>, no. <issue>1</issue>, pp. <fpage>393</fpage>&#x2013;<lpage>430</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Sun</surname></string-name>, <string-name><given-names>G. Z.</given-names> <surname>Dai</surname></string-name>, <string-name><given-names>X. R.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>X. Z.</given-names> <surname>He</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>TBE-Net: A three-branch embedding network with part-aware ability and feature complementary learning for vehicle re-identification</article-title>,&#x201D; <source>IEEE Transactions on Intelligent Transportation Systems</source>, vol. 99, pp. <fpage>1</fpage>&#x2013;<lpage>13</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Sun</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Dai</surname></string-name>, <string-name><given-names>X. R.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>P. S.</given-names> <surname>Chang</surname></string-name> and <string-name><given-names>X. Z.</given-names> <surname>He</surname></string-name></person-group>, &#x201C;<article-title>RSOD: Real-time small object detection algorithm in UAV-based traffic monitoring</article-title>,&#x201D; <source>Applied Intelligence</source>, vol. <volume>92</volume>, no. <issue>6</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>16</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. M.</given-names> <surname>Fadel</surname></string-name></person-group>, &#x201C;<article-title>HDSL: A hybrid distributed single-packet low-storage IP traceback framework</article-title>,&#x201D; <source>Mansoura Engineering Journal (MEJ)</source>, vol. <volume>46</volume>, no. <issue>4</issue>, pp. <fpage>75</fpage>&#x2013;<lpage>89</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Khraisat</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Gondal</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Vamplew</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Kamruzzaman</surname></string-name></person-group>, &#x201C;<article-title>Survey of intrusion detection systems: Techniques, datasets and challenges</article-title>,&#x201D; <source>Cybersecurity</source>, vol. <volume>2</volume>, no. <issue>20</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>22</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P. J.</given-names> <surname>Criscuolo</surname></string-name></person-group>, &#x201C;<article-title>Distributed denial of service, tribe flood network 2000, and stacheldraht, CIAC-2319</article-title>,&#x201D; <source>Department of Energy Computer Incident Advisory Capability (CIAC), UCRLID-136939, Rev. 1</source>, vol. <volume>1</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>18</lpage>, <year>2000</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P. D.</given-names> <surname>Bojovic</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Basicevic</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Ocovaj</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Popovic</surname></string-name></person-group>, &#x201C;<article-title>A practical approach to detection of distributed denial-of-service attacks using a hybrid detection method</article-title>,&#x201D; <source>Computers and Electrical Engineering</source>, vol. <volume>73</volume>, pp. <fpage>84</fpage>&#x2013;<lpage>96</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Kalkan</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Altay</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Gur</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Alagoz</surname></string-name></person-group>, &#x201C;<article-title>JESS: Joint entropy-based DDoS defense scheme in SDN</article-title>,&#x201D; <source>IEEE Journal on Selected Areas in Communications</source>, vol. <volume>36</volume>, no. <issue>10</issue>, pp. <fpage>2358</fpage>&#x2013;<lpage>2372</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N. A. S.</given-names> <surname>Lima</surname></string-name> and <string-name><given-names>M. P.</given-names> <surname>Fernandez</surname></string-name></person-group>, &#x201C;<article-title>Towards an efficient DDoS detection scheme for software-defined networks</article-title>,&#x201D; <source>IEEE Latin America Transactions</source>, vol. <volume>16</volume>, no. <issue>8</issue>, pp. <fpage>2296</fpage>&#x2013;<lpage>2301</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Jia</surname></string-name> and <string-name><given-names>L.</given-names> <surname>Ju</surname></string-name></person-group>, &#x201C;<article-title>An entropy-based distributed DDoS detection mechanism in software-defined networking</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. on Trust, Security and Privacy in Computing and Communications (TrustCom)</conf-name>, <conf-loc>Helsinki, Finland</conf-loc>, pp. <fpage>310</fpage>&#x2013;<lpage>317</lpage>, <year>2015</year>. </mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. E.</given-names> <surname>Ahmed</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Ullah</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Kim</surname></string-name></person-group>, &#x201C;<article-title>Statistical application fingerprinting for DDoS attack mitigation</article-title>,&#x201D; <source>IEEE Transactions on Information Forensics and Security</source>, vol. <volume>14</volume>, no. <issue>6</issue>, pp. <fpage>1471</fpage>&#x2013;<lpage>1484</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>E.</given-names> <surname>Min</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Long</surname></string-name>, <string-name><given-names>Q.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Cui</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>TR-IDS: Anomaly-based intrusion detection through text-convolutional neural network and random forest</article-title>,&#x201D; <source>Security and Communication Networks</source>, vol. <volume>2018</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>9</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A. L.</given-names> <surname>Buczak</surname></string-name> and <string-name><given-names>E.</given-names> <surname>Guven</surname></string-name></person-group>, &#x201C;<article-title>A survey of data mining and machine learning methods for cyber security intrusion detection</article-title>,&#x201D; <source>IEEE Communications Surveys &#x0026; Tutorials</source>, vol. <volume>18</volume>, no. <issue>2</issue>, pp. <fpage>1153</fpage>&#x2013;<lpage>1176</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>He</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Zhang</surname></string-name> and <string-name><given-names>R. B.</given-names> <surname>Lee</surname></string-name></person-group>, &#x201C;<article-title>Machine learning based DDoS attack detection from source side in csloud</article-title>,&#x201D; in <conf-name>Proc. IEEE 4th Int. Conf. on Cyber Security and Cloud Computing (CSCloud)</conf-name>, <conf-loc>New York, NY, USA</conf-loc>, pp. <fpage>114</fpage>&#x2013;<lpage>120</lpage>, <year>2017</year>. </mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>K. S.</given-names> <surname>Hoon</surname></string-name>, <string-name><given-names>K. C.</given-names> <surname>Yeo</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Azam</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Shunmugam</surname></string-name> and <string-name><given-names>F. D.</given-names> <surname>Boer</surname></string-name></person-group>, &#x201C;<article-title>Critical review of machine learning approaches to apply big data analytics in DDoS forensics</article-title>,&#x201D; in <conf-name>Proc. Int. Conf. on Computer Communication and Informatics (ICCCI)</conf-name>, <conf-loc>Coimbatore, India</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>5</lpage>, <year>2018</year>. </mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Koay</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Welch</surname></string-name> and <string-name><given-names>W. K. G.</given-names> <surname>Seah</surname></string-name></person-group>, &#x201C;<article-title>A new multi classifier system using entropy-based features in DDoS attack detection</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. on Information Networking (ICOIN)</conf-name>, <conf-loc>Chiang Mai, Thailand</conf-loc>, pp. <fpage>162</fpage>&#x2013;<lpage>167</lpage>, <year>2018</year>. </mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Yin</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Fei</surname></string-name> and <string-name><given-names>X.</given-names> <surname>He</surname></string-name></person-group>, &#x201C;<article-title>A deep learning approach for intrusion detection using recurrent neural networks</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>5</volume>, pp. <fpage>21954</fpage>&#x2013;<lpage>21961</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Chen</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>A novel intrusion detection model for a massive network using convolutional neural networks</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>6</volume>, pp. <fpage>50850</fpage>&#x2013;<lpage>50859</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Kwon</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Natarajan</surname></string-name>, <string-name><given-names>S. C.</given-names> <surname>Suh</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Kim</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Kim</surname></string-name></person-group>, &#x201C;<article-title>An empirical study on network anomaly detection using convolutional neural networks</article-title>,&#x201D; in <conf-name>Proc. IEEE 38th Int. Conf. on Distributed Computing Systems (ICDCS)</conf-name>, <conf-loc>Vienna, Austria</conf-loc>, pp. <fpage>1595</fpage>&#x2013;<lpage>1598</lpage>, <year>2018</year>. </mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>University of New Brunswick benchmark dataset</collab></person-group>, <comment>[Accessed: 28-Dec-2021]</comment>. <italic>Available:</italic> <uri xlink:href="https://www.unb.ca/cic/datasets/nsl.html">https://www.unb.ca/cic/datasets/nsl.html</uri>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>MAWILab dataset</collab></person-group>, <comment>[Accessed: 3-Jan-2022]</comment>. <italic>Available:</italic> <uri xlink:href="http://www.fukuda-lab.org/mawilab/data.html">http://www.fukuda-lab.org/mawilab/data.html</uri>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Yuan</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>Deep defense: Identifying DDoS attack via deep learning</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. on Smart Computing (SMARTCOMP)</conf-name>, <conf-loc>Hong Kong, China</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Intrusion detection evaluation dataset (ISCXIDS2012)</collab></person-group>, <comment>[Accessed: 23-Dec.-2021]</comment>. <italic>Available:</italic> <uri xlink:href="https://www.unb.ca/cic/datasets/ids.html">https://www.unb.ca/cic/datasets/ids.html</uri>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Suresh</surname></string-name> and <string-name><given-names>N. S.</given-names> <surname>Ram</surname></string-name></person-group>, &#x201C;<article-title>A review on various DPM traceback schemes to detect DDoS attacks</article-title>,&#x201D; <source>Indian Journal of Science and Technology</source>, vol. <volume>9</volume>, no. <issue>47</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Bhavani</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Janaki</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Sridevi</surname></string-name></person-group>, &#x201C;<article-title>Survey on packet marking algorithms for IP traceback</article-title>,&#x201D; <source>Oriental Journal of Computer Science &#x0026; Technology</source>, vol. <volume>10</volume>, no. <issue>2</issue>, pp. <fpage>507</fpage>&#x2013;<lpage>512</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>L. L.</given-names> <surname>Minku</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Yao</surname></string-name></person-group>, &#x201C;<article-title>A systematic study of online class imbalance learning with concept drift</article-title>,&#x201D; <source>IEEE Transactions on Neural Networks and Learning Systems</source>, vol. <volume>29</volume>, no. <issue>10</issue>, pp. <fpage>4802</fpage>&#x2013;<lpage>4821</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Mininet emulator software</collab></person-group>, <comment>[Accessed: 11-Jan.-2022]</comment>. <italic>Available:</italic> <uri xlink:href="mininet.org">mininet.org</uri>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. M.</given-names> <surname>Ahsan</surname></string-name>, <string-name><given-names>M. A. P.</given-names> <surname>Mahmud</surname></string-name>, <string-name><given-names>P. K.</given-names> <surname>Saha</surname></string-name>, <string-name><given-names>K. D.</given-names> <surname>Gupta</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Siddique</surname></string-name></person-group>, &#x201C;<article-title>Effect of data scaling methods on machine learning algorithms and model performance</article-title>,&#x201D; <source>Technologies</source>, vol. <volume>9</volume>, no. <issue>52</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>17</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Zhao</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Mu</surname></string-name> and <string-name><given-names>L.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Experimental study and comparison of imbalance ensemble classifiers with dynamic selection strategy</article-title>,&#x201D; <source>Entropy</source>, vol. <volume>23</volume>, no. <issue>7</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>22</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Lin</surname></string-name> and <string-name><given-names>L.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Intrusion detection of imbalanced network traffic based on machine learning and deep learning</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>9</volume>, pp. <fpage>7550</fpage>&#x2013;<lpage>7563</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Ahuja</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Singal</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Mukhopadhyay</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Kumar</surname></string-name></person-group>, &#x201C;<article-title>Automated DDOS attack detection in software defined networking</article-title>,&#x201D; <source>Journal of Network and Computer Applications</source>, vol. <volume>187</volume>, no. <issue>6</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>42</lpage>, <year>2021</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>
