Development of a CNN Model for Anomaly Detection in SDN Environments

Kalarani, S (2025) Development of a CNN Model for Anomaly Detection in SDN Environments. 2025 7th International Conference on Intelligent Sustainable Systems (ICISS). pp. 649-655.

[thumbnail of Development of a CNN Model for Anomaly Detection in SDN Environments.pdf] Text
Development of a CNN Model for Anomaly Detection in SDN Environments.pdf - Published Version

Download (328kB)

Abstract

This work develops a Convolutional Neural Network (CNN) for anomaly detection (AD) in Software-Defined Networking (SDN) environments, utilizing six flow dimensions: bits per second, packets per second, source and destination IP entropy, and source and destination port entropy. The model is designed to identify network anomalies, including DDoS and portscan attacks, by analyzing network traffic and predicting future destination IP entropy. Two decision threshold strategies were evaluated to balance detection accuracy and system reliability. The first method aimed at maximizing the F1 score but resulted in a high number of false positives (15%) and false negatives (18%), decreasing the model’s reliability due to frequent false alarms. The second method focused on minimizing false positives, reducing them to near zero but at the cost of higher false negatives (25%) and delayed anomaly detection by over one second in some cases.

Item Type: Article
Subjects: C Computer Science and Engineering > Computer software
C Computer Science and Engineering > Neural Networks
Divisions: Computer Science and Engineering
Depositing User: Dr Krishnamurthy V
Date Deposited: 23 Dec 2025 08:36
Last Modified: 23 Dec 2025 08:36
URI: https://ir.psgitech.ac.in/id/eprint/1684

Actions (login required)

View Item
View Item