Integrated Anomaly Detection and Mitigation in SDN Environments: A Hybrid Approach

Modern network infrastructures are under attack from increasingly sophisticated attacks that static, rule-based defenses cannot adequately mitigate. We introduce a multilayer anomaly detection and mitigation framework for Software-Defined Networking (SDN) environments consisting of four integrated subsystems: (i) a Micro-segmentation Integrated Management and Defense System (MIMDS), (ii) an Adaptive CNN-LSTM-Attention Deep Packet Inspection (MCLA-DPI) module, (iii) a Hybrid Adaptive Cyberattack Prediction (KBGM) framework, and (iv) an AI-driven log analysis pipeline. Detection, prediction and containment operate in parallel (as opposed to conventional approaches) and correlate results through a common risk-scoring mechanism to coordinate policy enforcement via OpenFlow and P4-compatible data planes. The experimental evaluation shows promising performance. MIMDS achieves 94.3%. detection accuracy with full traffic isolation in 10.1 s. MCLA-DPI achieves 98.9% classification accuracy with 14 ms inference latency, outperforming baseline models SVM and LSTM on encrypted traffic. KBGM achieves 98.4% detection accuracy with 7.2 ms mean response time on the CICIDS2017 dataset. All modules are trained in federated learning to preserve data locality with continuous improvements of the global model. The results collectively demonstrate quantifiable improvements over single-paradigm approaches in detection fidelity, response latency, resource efficiency, and privacy compliance. An ablation study isolates the contribution of integration itself. Removing the coordination layer while retaining all four detectors reduces accuracy from 0.892 to 0.634 and raises the false-positive rate from 0.031 to 0.436, while peak rule installation rises from 22.3 to 98.4 rules per second and oscillation events increase by two orders of magnitude; the integrated framework also exceeds its strongest individual subsystem, which reaches 0.831 accuracy at a false-positive rate of 0.117. These figures are obtained from the released reference implementation over a synthetic campaign and are reported separately from the component measurements.

Authors

Institutions

Publication Details

Journal
Computers
Published
2026-09-21
DOI
https://doi.org/10.3390/computers15090641
Primary Topic
Software-Defined Networks and 5G
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Integrated Anomaly Detection and Mitigation in SDN Environments: A Hybrid Approach

Sherzod Gulomov, Alpamis Kutlimuratov, Suhrobjon Bozorov, Islambek Saymanov et al.
Computers
Software-Defined Networks and 5G
article

Integrated Anomaly Detection and Mitigation in SDN Environments: A Hybrid Approach

Sherzod Gulomov, Alpamis Kutlimuratov, Suhrobjon Bozorov, Islambek Saymanov, Boykuziev Ilkhom, Sodikjon Jumayev
article en

Abstract

Modern network infrastructures are under attack from increasingly sophisticated attacks that static, rule-based defenses cannot adequately mitigate. We introduce a multilayer anomaly detection and mitigation framework for Software-Defined Networking (SDN) environments consisting of four integrated subsystems: (i) a Micro-segmentation Integrated Management and Defense System (MIMDS), (ii) an Adaptive CNN-LSTM-Attention Deep Packet Inspection (MCLA-DPI) module, (iii) a Hybrid Adaptive Cyberattack Prediction (KBGM) framework, and (iv) an AI-driven log analysis pipeline. Detection, prediction and containment operate in parallel (as opposed to conventional approaches) and correlate results through a common risk-scoring mechanism to coordinate policy enforcement via OpenFlow and P4-compatible data planes. The experimental evaluation shows promising performance. MIMDS achieves 94.3%. detection accuracy with full traffic isolation in 10.1 s. MCLA-DPI achieves 98.9% classification accuracy with 14 ms inference latency, outperforming baseline models SVM and LSTM on encrypted traffic. KBGM achieves 98.4% detection accuracy with 7.2 ms mean response time on the CICIDS2017 dataset. All modules are trained in federated learning to preserve data locality with continuous improvements of the global model. The results collectively demonstrate quantifiable improvements over single-paradigm approaches in detection fidelity, response latency, resource efficiency, and privacy compliance. An ablation study isolates the contribution of integration itself. Removing the coordination layer while retaining all four detectors reduces accuracy from 0.892 to 0.634 and raises the false-positive rate from 0.031 to 0.436, while peak rule installation rises from 22.3 to 98.4 rules per second and oscillation events increase by two orders of magnitude; the integrated framework also exceeds its strongest individual subsystem, which reaches 0.831 accuracy at a false-positive rate of 0.117. These figures are obtained from the released reference implementation over a synthetic campaign and are reported separately from the component measurements.

ComputersVol. 15(9)
Tashkent University of Information Technology (UZ), National University of Uzbekistan (UZ), Westminster International University in Tashkent (UZ)
Decent work and economic growth
Openalex Percentile: Top 8%
Software-Defined Networks and 5G
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.