Deep Learning-Powered Intrusion Detection for Software-Defined Networking: Architecture, Threat Modeling and Performance Analysis
Keywords:
artificial intelligence, cybersecurity, deep learning, Intrusion Detection System (IDS), Software-Defined Networking (SDN)Abstract
Software-Defined Networking (SDN) decouples the control plane from the data plane, providing remarkable flexibility, centralized management, and dynamic programmability. However, this architectural centralization introduces single points of failure and novel cyber-attack surfaces. Traditional signature-based intrusion detection systems (IDS) fall short against polymorphic malware and advanced zero-day threats in modern programmable environments. This paper proposes a hybrid deep learning-powered intrusion detection architecture tailored specifically for SDN frameworks. The system integrates a Convolutional Neural Network (CNN) for spatial feature extraction with a Long Short-Term Memory (LSTM) network for temporal pattern recognition of real-time flow metrics gathered at the controller level. Experimental evaluations utilizing adapted network flow benchmarks demonstrate that the proposed model achieves a detection accuracy of 98.5% with a low false-positive rate of 1.2%, significantly outperforming conventional rule-based and shallow machine learning baselines.