Article navigation
Purpose

The purpose of the study concludes detecting address resolution protocol (ARP) Spoofing attack in software-defined network (SDN) architecture meanwhile using different machine learning models to evaluate their effectiveness.

Design/methodology/approach

This research originates from building a SDN topology and researching into its changes under ARP Spoofing attack. Based on that, the authors propose four features which show obvious abnormalities in network under attack stage. The data collected from SDN controller is used to build a data set, which is then put into different machine learning models, which are: Artificial Neuron network (ANN), Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM), CNN-LSTM and Gated Recurrent Unit (GRU).

Findings

After applying this proposal in simulation and experimental environments, they achieve impressive performance metrics. In simulation environment, the GRU model stands out with the highest accuracy of 98.94%. In real environments, the CNN-LSTM model leads with a recall of 98.38% and an F1-Score of 98.57%, while the LSTM model has the highest precision (98.8%). The GRU model also performs strongly in real scenarios with a high accuracy of 97.65%. ANN, despite its reliability, struggles with lower recall and F1-Score across both environments.

Originality/value

This analysis emphasizes the importance of the proposed features when applied to different models and their high potential to conduct in practical environment.

Licensed re-use rights only
You do not currently have access to this content.
Don't already have an account? Register

Purchased this content as a guest? Enter your email address to restore access.

Pay-Per-View Access
$41.00
Rental

or Create an Account

Close Modal
Close Modal