SDN-ATK: a novel SDN-specific attack dataset


DOĞAN S. B., Arikan K. E., ALKAN M.

PeerJ Computer Science, cilt.12, 2026 (SCI-Expanded, Scopus) identifier identifier

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 12
  • Basım Tarihi: 2026
  • Doi Numarası: 10.7717/peerj-cs.3556
  • Dergi Adı: PeerJ Computer Science
  • Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Scopus, Compendex, Directory of Open Access Journals
  • Anahtar Kelimeler: Dataset, Deep learning, Explainable artificial intelligence, Intrusion prevention and mitigation systems, Machine learning, Software-defined network, Threat vectors
  • Gazi Üniversitesi Adresli: Evet

Özet

This study presents the development of a realistic and comprehensive SDN-ATK dataset designed to evaluate the effectiveness of machine learning (ML) and deep learning (DL) approaches for attack detection in Software-Defined Networking (SDN) environments. Unlike existing datasets, SDN-ATK explicitly includes attacks targeting key SDN components such as SDN controllers and OpenFlow switches, addressing a critical gap in current research. We evaluated three ML (XGBoost, Random Forest, and Decision Tree) and three DL (Convolutional Neural Network (CNN), Feed-forward Neural Network (FNN), and Long Short-Term Memory (LSTM)) algorithms across binary and multiclass classification tasks to assess detection performance. Our results demonstrate that DL models, particularly FNN and CNN outperform ML counterparts, achieving 98 - 99% accuracy, precision, and recall in binary classification. Explainability analyses were conducted using SHAP (SHapley Additive explanations) on the XGBoost model, offering valuable insights into the importance of feature and improving transparency in ML-based attack detection. The study's findings provide critical guidance for both academia and industry, highlighting that within our Ryu-based SDN testbed, DL models demonstrated more reliable and balanced performance for large-scale attack detection. This work lays a solid foundation for future research, including developing real-time, intelligent, and explainable intrusion detection systems for SDN environments.