Integrated Anomaly Detection and Mitigation in SDN Environments: A Hybrid Approach
Modern network infrastructures are under attack from increasingly sophisticated attacks that static, rule-based defenses cannot adequately mitigate. We introduce a multilayer anomaly detection and mitigation framework for Software-Defined Networking (SDN) environments consisting of four integrated subsystems: (i) a Micro-segmentation Integrated Management and Defense System (MIMDS), (ii) an Adaptive CNN-LSTM-Attention Deep Packet Inspection (MCLA-DPI) module, (iii) a Hybrid Adaptive Cyberattack Prediction (KBGM) framework, and (iv) an AI-driven log analysis pipeline. Detection, prediction and containment operate in parallel (as opposed to conventional approaches) and correlate results through a common risk-scoring mechanism to coordinate policy enforcement via OpenFlow and P4-compatible data planes. The experimental evaluation shows promising performance. MIMDS achieves 94.3%. detection accuracy with full traffic isolation in 10.1 s. MCLA-DPI achieves 98.9% classification accuracy with 14 ms inference latency, outperforming baseline models SVM and LSTM on encrypted traffic. KBGM achieves 98.4% detection accuracy with 7.2 ms mean response time on the CICIDS2017 dataset. All modules are trained in federated learning to preserve data locality with continuous improvements of the global model. The results collectively demonstrate quantifiable improvements over single-paradigm approaches in detection fidelity, response latency, resource efficiency, and privacy compliance. An ablation study isolates the contribution of integration itself. Removing the coordination layer while retaining all four detectors reduces accuracy from 0.892 to 0.634 and raises the false-positive rate from 0.031 to 0.436, while peak rule installation rises from 22.3 to 98.4 rules per second and oscillation events increase by two orders of magnitude; the integrated framework also exceeds its strongest individual subsystem, which reaches 0.831 accuracy at a false-positive rate of 0.117. These figures are obtained from the released reference implementation over a synthetic campaign and are reported separately from the component measurements.
Authors
- Sherzod Gulomov (ORCID: https://orcid.org/0000-0003-3806-8425)
- Alpamis Kutlimuratov (ORCID: https://orcid.org/0000-0001-7472-4165)
- Suhrobjon Bozorov (ORCID: https://orcid.org/0000-0002-2377-934X)
- Islambek Saymanov (ORCID: https://orcid.org/0000-0003-3530-4488)
- Boykuziev Ilkhom (ORCID: https://orcid.org/0000-0001-5685-7546)
- Sodikjon Jumayev
Institutions
- Tashkent University of Information Technology (UZ)
- National University of Uzbekistan (UZ)
- Westminster International University in Tashkent (UZ)
Publication Details
- Journal
- Computers
- Published
- 2026-09-21
- DOI
- https://doi.org/10.3390/computers15090641
- Primary Topic
- Software-Defined Networks and 5G
- Type
- article
- Field-Weighted Citation Impact
- 0.00