A Lightweight Stacking Ensemble Intrusion Detection Framework for Software-Defined Networking Using the InSDN Dataset

Authors

  • Ubakaghinwa Paul Chigbu National Office for Technology Acquisition and Promotion, Nigeria https://orcid.org/0009-0009-2062-3428
  • Abdulrashid Abdulrauf Federal Polytechnic Kaltungo, Nigeria https://orcid.org/0009-0001-9498-0585
  • Ishaq Isa Federal University of Applied Sciences Kachia, Nigeria
  • Badamasi Usman Zuntu Kaduna Polytechnic, Nigeria
  • Maryam Abubakar Sharif Federal Polytechnic Kaltungo, Nigeria

DOI:

https://doi.org/10.64539/sjcs.v2i2.2026.511

Keywords:

DDOS, Detection, Ensemble, Intrusion, InSDN dataset, Stacking

Abstract

Software-Defined Networking (SDN) has become a key enabler of next-generation communication infrastructures because of its centralized control, programmability, and global network visibility. However, the centralized architecture also introduces significant security vulnerabilities, making SDN environments highly susceptible to attacks such as DoS, DDoS, probing, brute-force, and botnet activities. Although deep learning-based intrusion detection systems have achieved high detection accuracy, many existing approaches suffer from high computational complexity, long training time, and limited suitability for real-time deployment. This study addresses this gap by developing a lightweight stacking ensemble intrusion detection framework for SDN using the InSDN dataset. The proposed framework employs XGBoost, LightGBM, CatBoost, Random Forest, and Extra Trees as base learners, with Logistic Regression serving as the meta-learner. Experiments were conducted using 48-feature, 6-feature, and 4-feature configurations derived from previous feature-reduction studies. The results demonstrate consistently high detection performance, achieving accuracies above 99% across all feature subsets, with only marginal degradation under reduced feature dimensions. The framework showed excellent detection capability for major attack categories while maintaining reliable performance for most minority classes. These findings demonstrate that stacking ensemble learning is a practical and computationally efficient alternative to complex deep learning architectures for SDN intrusion detection, with strong potential for scalable and real-time cybersecurity deployment in modern network environments.

References

[1] S. Pandey, M. Chaudhary, and Z. Tóth, “An investigation on real-time insights: enhancing process control with IoT-enabled sensor networks,” Discover Internet of Things, vol. 5, no. 1, p. 29, 2025. https://doi.org/10.1007/s43926-025-00124-6.

[2] A. Salam, “Internet of things for sustainability: perspectives in privacy, cybersecurity, and future trends,” in Internet of Things for Sustainable Community Development: Wireless Communications, Sensing, and Systems, Cham: Springer International Publishing, 2019, pp. 299–326. https://doi.org/10.1007/978-3-030-35291-2_10.

[3] T. Magara and Y. Zhou, “Internet of things (IoT) of smart homes: privacy and security,” Journal of Electrical and Computer Engineering, vol. 2024, no. 1, p. 7716956, 2024. https://doi.org/10.1155/2024/7716956.

[4] J. M. Kizza, “Internet of things (IoT): growth, challenges, and security,” in Guide to Computer Network Security, Cham: Springer International Publishing, 2024, pp. 557–573. https://doi.org/10.1007/978-3-031-47549-8_25.

[5] D. Kreutz, F. M. Ramos, P. E. Verissimo, C. E. Rothenberg, S. Azodolmolky, and S. Uhlig, “Software-defined networking: A comprehensive survey,” Proceedings of the IEEE, vol. 103, no. 1, pp. 14–76, 2014. https://doi.org/10.1109/JPROC.2014.2371999.

[6] S. Singh and R. K. Jha, “A survey on software defined networking: architecture for next generation network,” J. Netw. Syst. Manage., vol. 25, no. 2, pp. 321–374, 2017. https://doi.org/10.1007/s10922-016-9393-9.

[7] N. Anand et al., “Securing Software Defined Networks: A Comprehensive Analysis of approaches, applications, and Future Strategies against DoS Attacks,” IEEE Access, vol. 13, pp. 64473 – 64515, 2024. https://doi.org/10.1109/ACCESS.2024.3520478.

[8] N. Indrason and G. Saha, “Exploring Blockchain-driven security in SDN-based IoT networks,” Journal of Network and Computer Applications, vol. 224, p. 103838, 2024. https://doi.org/10.1016/j.jnca.2024.103838.

[9] S. M. Mousavi and M. St-Hilaire, “Early detection of DDoS attacks against SDN controllers,” in 2015 International Conference on Computing, Networking and Communications (ICNC), 2015, pp. 77–81. https://doi.org/10.1109/ICCNC.2015.7069319.

[10] M. S. Ataa, E. E. Sanad, and R. A. El-khoribi, “Intrusion detection in software defined network using deep learning approaches,” Sci. Rep., vol. 14, p. 29159, 2024. https://doi.org/10.1038/s41598-024-79001-1.

[11] S. Layeghy, M. Gallagher, and M. Portmann, “Benchmarking the benchmark—Comparing synthetic and real-world Network IDS datasets,” Journal of Information Security and Applications, vol. 80, p. 103689, 2024. https://doi.org/10.1016/j.jisa.2023.103689.

[12] C. Singh and A. K. Jain, “A comprehensive survey on DDoS attacks detection & mitigation in SDN-IoT network,” e-Prime-Advances in Electrical Engineering, Electronics and Energy, vol. 8, p. 100543, 2024. https://doi.org/10.1016/j.prime.2024.100543.

[13] A. Abderrahmane, H. Drid, and A. Behaz, “A survey of controller placement problem in SDN-IoT network,” International Journal of Networked and Distributed Computing, vol. 12, no. 2, pp. 170–184, 2024. https://doi.org/10.1007/s44227-024-00035-y.

[14] T. A. Tang, L. Mhamdi, D. McLernon, S. A. R. Zaidi, and M. Ghogho, “Deep learning approach for network intrusion detection in software defined networking,” in 2016 International Conference on Wireless Networks and Mobile Communications (WINCOM), 2016, pp. 258–263. https://doi.org/10.1109/WINCOM.2016.7777224.

[15] Q. Yan, W. Huang, X. Luo, Q. Gong, and F. R. Yu, “A multi-level DDoS mitigation framework for the industrial internet of things,” IEEE Commun. Mag., vol. 56, no. 2, pp. 30–36, 2018. https://doi.org/10.1109/MCOM.2018.1700621.

[16] H. Dhirar and A. Hamad, “Comparative evaluation of a novel IDS dataset for SDN-IoT using deep learning models against InSDN, BoT-IoT, and ToN-IoT,” Measurement: Digitalization, p. 100015, 2025. https://doi.org/10.1016/j.meadig.2025.100015.

[17] Sarika and R. Dass, “Design of a Novel Network Intrusion Detection Technique for SDN-based IoT Network Using Machine Learning,” Optoelectronics, Instrumentation and Data Processing, vol. 61, no. 3, pp. 396–407, 2025. https://doi.org/10.3103/S8756699025700451.

[18] M. S. Elsayed, N. A. Le-Khac, and A. D. Jurcut, “InSDN: A novel SDN intrusion dataset,” IEEE Access, vol. 8, pp. 165263–165284, 2020. https://doi.org/10.1109/ACCESS.2020.3022633.

[19] M. W. Nadeem, H. G. Goh, V. Ponnusamy, and Y. Aun, “DDoS Detection in SDN using Machine Learning Techniques,” Computers, Materials & Continua, vol. 71, no. 1, pp. 771–789, 2022. http://dx.doi.org/10.32604/cmc.2022.021669.

[20] G. Logeswari, S. Bose, and T. J. Anitha, “An intrusion detection system for sdn using machine learning,” Intelligent Automation & Soft Computing, vol. 35, no. 1, pp. 867–880, 2023. http://dx.doi.org/10.32604/iasc.2023.026769.

[21] M. Z. Mahmud, S. R. Alve, S. Islam, and M. M. Khan, “Sdn intrusion detection using machine learning method,” arXiv preprint arXiv:2411.05888, 2024. https://doi.org/10.48550/arXiv.2411.05888.

[22] M. R. Hadi and A. S. Mohammed, “A novel approach to network intrusion detection system using deep learning for Sdn: Futuristic approach,” arXiv preprint arXiv:2208.02094, 2022. https://doi.org/10.48550/arXiv.2208.02094.

[23] M. Maddu and Y. N. Rao, “Network intrusion detection and mitigation in SDN using deep learning models,” International Journal of Information Security, vol. 23, no. 2, pp. 849–862, 2024. https://doi.org/10.1007/s10207-023-00771-2.

[24] S. Rohith, G. Logeswari, K. Tamilarasi, and G. Sudhakaran, “A federated deep learning approach for SDN security with quantum optimized feature selection and hybrid MSDC net architecture,” Sci. Rep., vol. 16, p. 8038, 2026. https://doi.org/10.1038/s41598-026-37289-1.

[25] R. Chaganti, W. Suliman, V. Ravi, and A. Dua, “Deep learning approach for SDN-enabled intrusion detection system in IoT networks,” Information, vol. 14, no. 1, p. 41, 2023. https://doi.org/10.3390/info14010041.

[26] R. A. Elsayed, R. A. Hamada, M. I. Abdalla, and S. A. Elsaid, “Securing IoT and SDN systems using deep-learning based automatic intrusion detection,” Ain Shams Engineering Journal, vol. 14, no. 10, p. 102211, 2023. https://doi.org/10.1016/j.asej.2023.102211.

[27] A. Wani, R. S, and R. Khaliq, “SDN‐based intrusion detection system for IoT using deep learning classifier (IDSIoT‐SDL),” CAAI Transactions on Intelligence Technology, vol. 6, no. 3, pp. 281–290, 2021. https://doi.org/10.1049/cit2.12003.

[28] T. L. Yasarathna and N. A. Le-Khac, “ASEADOS-SDN-IoT: A novel SDN-IoT network intrusion detection dataset and framework,” Internet of Things, p. 101891, 2026. https://doi.org/10.1016/j.iot.2026.101891.

[29] A. O. Alzahrani and M. J. Alenazi, “ML‐IDSDN: Machine learning based intrusion detection system for software‐defined network,” Concurrency and Computation: Practice and Experience, vol. 35, no. 1, p. e7438, 2023. https://doi.org/10.1002/cpe.7438.

[30] K. Rui, H. Pan, and S. Shu, “Secure routing in the Internet of Things (IoT) with intrusion detection capability based on software-defined networking (SDN) and Machine Learning techniques,” Sci. Rep., vol. 13, no. 1, p. 18003, 2023. https://doi.org/10.1038/s41598-023-44764-6.

[31] G. Kumar and H. Alqahtani, “Machine Learning Techniques for Intrusion Detection Systems in SDN-Recent Advances, Challenges and Future Directions,” Computer Modeling in Engineering & Sciences (CMES), vol. 134, no. 1, 2023. https://doi.org/10.32604/cmes.2022.020724.

Downloads

Published

2026-07-25

How to Cite

Chigbu, U. P., Abdulrauf, A., Isa, I., Zuntu, B. U., & Sharif, M. A. (2026). A Lightweight Stacking Ensemble Intrusion Detection Framework for Software-Defined Networking Using the InSDN Dataset. Scientific Journal of Computer Science, 2(2), 276–291. https://doi.org/10.64539/sjcs.v2i2.2026.511

Similar Articles

1 2 > >> 

You may also start an advanced similarity search for this article.