Software-Defined Networking Security Detection Strategies and Their Limitations with a Focus on Distributed Denial-of-Service for Small to Medium-Sized Enterprises
Round 1
Reviewer 1 Report
Comments and Suggestions for AuthorsThanks for submitting to Applied Sciences. This paper presents a systematic review of Software Defined Networking (SDN) security detection strategies, with a specific focus on Distributed Denial of Service (DDoS) attacks targeting small and medium-sized enterprises (SMEs). The topic is timely and relevant, as SMEs increasingly adopt SDN but often lack the resources to deploy robust security solutions. The paper's intent to bridge this gap by reviewing and categorizing existing literature is commendable.
However, the manuscript in its current form requires substantial improvement before it can be considered for publication.
First, the overall structure lacks balance. The figures and tables occupy excessive space—particularly, the table spanning over seven pages significantly disrupts the flow of the paper. The figures are large and not well integrated into the discussion. The authors should consider summarizing the data more concisely and moving detailed tabular content to an appendix.
Second, starting from Section 3.2 (“Analysis of DDoS Detection Articles”), the discussion becomes too brief and lacks substantive analysis. The section primarily lists works without meaningful synthesis, critical comparison, or insight extraction. The paper would benefit from a deeper analysis highlighting key methodological trends, limitations, and lessons learned from the reviewed studies. A comparative summary—such as how detection models trade off accuracy, resource use, and real-world applicability—would strengthen the argument considerably.
Third, the paper would be improved by a more reflective discussion in Section 4 and beyond. There is limited engagement with the practical implications of the findings, particularly regarding the deployment of lightweight and hybrid deep learning models in real-world SME contexts. The authors should also include a “Future Work” subsection that identifies promising directions for SDN-based DDoS mitigation in SMEs (e.g., live testbeds, adaptive controller strategies, or hybrid detection pipelines).
In summary, while the topic is important and the review framework is relevant, the paper currently lacks depth in analysis, synthesis, and critical discussion. I recommend reconsideration after major revision, with attention to improving the analytical rigor, structural clarity, and presentation quality.
Author Response
05 November 2025
Dear Honorary Editors, Respected Reviewers
Thank you very much for so kindly reviewing our article and making very valuable and constructive comments to further improve it.
We have very carefully considered all your comments and have done our best to amend the article accordingly. Your comments have significantly improved the article.
The changes made are summarised in the attached table.
We are very grateful for your kind help and support and hope the revised version of the article meets your expectations.
Best wishes
Professor Reza Saatchi
Sheffield Hallam University, Great Britain
Author Response File:
Author Response.pdf
Reviewer 2 Report
Comments and Suggestions for AuthorsThe proposed review appears to be conducted at a generally high level. The selection of publications seems transparent and reasonably comprehensive. The article can be accepted for publication. However, to further improve the paper and enhance its value for readers and the potential audience interested in the discussed tools and technologies, the following points are recommended:
1. Provide references to the datasets mentioned on page 13, line 241 (CICIDS2017 and Bot-IoT), and clarify the statement in Section 4 that they "still lack the vast assortment of problems that can befall a network." This could be supported by specific examples of such problems and references to relevant studies. It may also be useful to suggest potentially better datasets or approaches to dataset construction.
2. Although the paper focuses on reviewing academic research, including a brief mention and comparison of practical software tools and products analysed in the researches would significantly increase the paper’s value. This would help readers from the potential target audience (those involved in SDN administration and implementation) make a more informed choice of tools. The final decision on whether to include this remains with the Authors and the Editor.
3. The search queries used for paper selection, as shown in Table 1, differ not only in format (which is understandable given the different platforms) but also in their substantive content. In addition, for MDPI only one journal (Sensors) was apparently selected. This requires clarification and verification.
Once these comments are addressed, the article may be accepted for publication.
Author Response
05 November 2025
Dear Honorary Editors, Respected Reviewers
Thank you very much for so kindly reviewing our article and making very valuable and constructive comments to further improve it.
We have very carefully considered all your comments and have done our best to amend the article accordingly. Your comments have significantly improved the article.
The changes made are summarised in the attached table.
We are very grateful for your kind help and support and hope the revised version of the article meets your expectations.
Best wishes
Professor Reza Saatchi
Sheffield Hallam University, Great Britain
Author Response File:
Author Response.pdf
Reviewer 3 Report
Comments and Suggestions for Authors- The majority of the studies cited depend heavily on emulated environments or public datasets such as CICIDS2017 and Bot-IoT, which do not adequately replicate the heterogeneity and resource constraints of actual SME networks.
- The current approaches tend to treat detection and mitigation as isolated modules, often lacking seamless integration, especially in standards for triggering mitigation based on detection events. Moreover, safeguards such as flow rule expiry, rollback, or explainability are often missing or underexplored.
- While lightweight models are promising, their validation on real networks is limited, and they may not fully address the computational overhead or latency constraints in resource-limited SME environments. Deep learning models, despite higher accuracy, are often impractical without significant computational resources.
- Many studies emphasize detection accuracy but neglect metrics such as latency, scalability, resource usage, and false positive rates — critical factors for SME deployment.
- The absence of standardized protocols or frameworks for triggering mitigation actions upon detection events hampers interoperability and consistent deployment strategies across SME networks.
- The reliance on generic datasets limits the ability to generalize findings to SME contexts. There is a notable lack of SME-specific datasets or testbeds for validation.
- The analysis often notes the computational challenges but stops short of offering concrete solutions or design guidelines tailored for SMEs with limited hardware and expertise.
- Few references address model explainability, which is essential for trust and troubleshooting, especially in critical SME operations. Also, the long-term robustness (e.g., against evolving attack vectors) is insufficiently discussed.
Author Response
05 November 2025
Dear Honorary Editors, Respected Reviewers
Thank you very much for so kindly reviewing our article and making very valuable and constructive comments to further improve it.
We have very carefully considered all your comments and have done our best to amend the article accordingly. Your comments have significantly improved the article.
The changes made are summarised in the attached table.
We are very grateful for your kind help and support and hope the revised version of the article meets your expectations.
Best wishes
Professor Reza Saatchi
Sheffield Hallam University, Great Britain
Author Response File:
Author Response.pdf
Round 2
Reviewer 1 Report
Comments and Suggestions for AuthorsThanks for the revision. The paper has addressed the former issues. Please check the grammar issues and to prepare the final version.
Author Response
Dear Respected Reviewer
Thank you very much for so kindly reviewing our article and making very valuable and constructive comments to further improve it. We have very carefully considered your comments and have done our best to amend the article accordingly. Your comments have significantly improved the article. The changes made are summarised in the attached table.
We are very grateful for your kind help and support and hope the revised version of the article meets your expectations.
Yours Sincerely
Professor Reza Saatchi
Sheffield Hallam University, Great Britain
Author Response File:
Author Response.pdf
Reviewer 2 Report
Comments and Suggestions for AuthorsThe authors have addressed the comments, and the article may be accepted for publication. I believe the final version of the paper would benefit from including direct references to the sources of the datasets (e.g., CICIDS2017) and the tools listed in Table 5 at the points where they are mentioned.
Author Response
Dear Respected Reviewer
Thank you very much for so kindly reviewing our article and making very valuable and constructive comments to further improve it. We have very carefully considered your comments and have done our best to amend the article accordingly. Your comments have significantly improved the article. The changes made are summarised in the attached table.
We are very grateful for your kind help and support and hope the revised version of the article meets your expectations.
Yours Sincerely
Professor Reza Saatchi
Sheffield Hallam University, Great Britain
Author Response File:
Author Response.pdf
Reviewer 3 Report
Comments and Suggestions for AuthorsThe paper emphasizes that most detection and mitigation models are validated primarily through simulation or controlled testbeds. To strengthen the contribution, it is recommended that future work include practical validation on live SME networks or deployments with resource constraints. Real-world datasets and field tests would enhance the applicability and credibility of proposed solutions.
While the paper advocates lightweight detection models suitable for SMEs, it does not sufficiently analyze the potential trade-offs between accuracy and resource consumption in real-time scenarios. Providing empirical data or benchmarks comparing resource utilization (CPU, memory, latency) of different models (heuristic vs. deep learning) would clarify the practicality of these approaches.
The discussion highlights a gap in the integration of detection and mitigation modules, yet the proposed conceptual framework remains high-level. Implementing and evaluating an integrated prototype that demonstrates seamless triggering of mitigation based on detection events at the network edge would significantly improve the paper’s contribution.
The reliance on common benchmark datasets (e.g., CICIDS2017, Bot-IoT) is noted, but SME-specific traffic heterogeneity and burstiness are not sufficiently addressed. Including or developing datasets that reflect typical SME traffic patterns, including bursty or low-volume attacks, would make the evaluation more relevant.
The paper acknowledges the importance of low latency for SME networks but lacks detailed analysis or quantification of how proposed models perform under high traffic loads or scale with network size. Future work should incorporate latency measurements and scalability assessments to validate the models' deployment feasibility.
The paper notes the high accuracy of deep learning models but also their resource intensity, ironically contrasting their applicability for SMEs. Consider including hybrid approaches or incremental learning techniques that balance accuracy with resource constraints, and analyze their comparative advantages.
The absence of standardized procedures or protocols for how detection triggers mitigation responses at the controller level hampers reproducibility and practical implementation. Developing and advocating for such standards would be valuable.
The paper should discuss the limitations of current datasets and how their characteristics (e.g., centralized, homogeneous traffic) might limit generalizability to SME environments with diverse, heterogeneous traffic.
The concluding suggestions could be strengthened by proposing specific experimental setups, datasets, or open challenges (e.g., attack adaptation, false positives management) to guide subsequent research efforts.
Author Response
Dear Respected Reviewer
Thank you very much for so kindly reviewing our article and making very valuable and constructive comments to further improve it. We have very carefully considered your comments and have done our best to amend the article accordingly. Your comments have significantly improved the article. The changes made are summarised in the attached table.
We are very grateful for your kind help and support and hope the revised version of the article meets your expectations.
Yours Sincerely
Professor Reza Saatchi
Sheffield Hallam University, Great Britain
Author Response File:
Author Response.pdf

