Previous Article in Journal
MDSCNet: A Lightweight Complex Convolutional Network for Automatic Modulation Classification
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Article

Performance and Structural Symmetry Evaluation of Machine Learning-Driven Intrusion Detection Systems in Software-Defined Networks

1
School of Computing and Digital Technologies, Sheffield Hallam University, Sheffield S1 1WB, UK
2
School of Engineering and Built Environment, Sheffield Hallam University, Sheffield S1 1WB, UK
*
Author to whom correspondence should be addressed.
Symmetry 2026, 18(9), 1433; https://doi.org/10.3390/sym18091433
Submission received: 29 July 2026 / Revised: 19 August 2026 / Accepted: 24 August 2026 / Published: 26 August 2026

Abstract

Software-Defined Networking (SDN) provides fine-grained control over network architectures, yet integrating intrusion detection systems (IDSs) into the control plane frequently introduces prohibitive computational overhead. This issue is compounded by the fact that existing machine learning models, typically trained on static benchmark datasets, often degrade under real-time polling conditions and unpredictable traffic bursts. To bridge this gap, this paper evaluates an ultra-compact five-feature polling scheme (F1–F5) designed to preserve statistical symmetry between control-plane monitoring and telemetry overhead within a dynamic Mininet–Ryu testbed. The experimental framework incorporates 15% background noise, and a 10% stealth attack overlaps across a 120 s dynamic trace. Four distinct classifiers—Random Forest (RF), Decision Tree (DT), Multi-Layer Perceptron (MLP), and Long Short-Term Memory (LSTM)—were evaluated across frame-by-frame snapshot and windowed prediction tasks. Empirical findings reveal that tree-based ensembles consistently outperform deep learning approaches, with RF attaining an overall accuracy of 97.57% and DT achieving 96.74%, compared to 90.77% for MLP and 90.73% for LSTM. Analysis of the time-series logs demonstrates that RF’s orthogonal decision boundaries successfully isolate transient, high-intensity threats such as WebAttack and PortScan vectors without needing memory-intensive recurrent architectures. Ultimately, pairing minimal feature extraction with lightweight tree ensembles offers an optimal balance between low control-plane latency and high detection efficacy.
Keywords: software-defined networking; intrusion detection; machine learning; deep learning; Ryu controller; network security software-defined networking; intrusion detection; machine learning; deep learning; Ryu controller; network security

Share and Cite

MDPI and ACS Style

Giri, R.; Salama, A.; Saatchi, R.; Bagheri, M. Performance and Structural Symmetry Evaluation of Machine Learning-Driven Intrusion Detection Systems in Software-Defined Networks. Symmetry 2026, 18, 1433. https://doi.org/10.3390/sym18091433

AMA Style

Giri R, Salama A, Saatchi R, Bagheri M. Performance and Structural Symmetry Evaluation of Machine Learning-Driven Intrusion Detection Systems in Software-Defined Networks. Symmetry. 2026; 18(9):1433. https://doi.org/10.3390/sym18091433

Chicago/Turabian Style

Giri, Rohan, Abdussalam Salama, Reza Saatchi, and Maryam Bagheri. 2026. "Performance and Structural Symmetry Evaluation of Machine Learning-Driven Intrusion Detection Systems in Software-Defined Networks" Symmetry 18, no. 9: 1433. https://doi.org/10.3390/sym18091433

APA Style

Giri, R., Salama, A., Saatchi, R., & Bagheri, M. (2026). Performance and Structural Symmetry Evaluation of Machine Learning-Driven Intrusion Detection Systems in Software-Defined Networks. Symmetry, 18(9), 1433. https://doi.org/10.3390/sym18091433

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop