Abdinasir Hirsi, Mohammed A. Alhartomi, Lukman Audah, Mustafa Maad Hamdi, Adeb Salah, Godwin Ansa, Salman Ahmed, A. Farah
Software-Defined Networking (SDN) enhances programmability and control but remains highly vulnerable to distributed denial-of-service (DDoS) attacks. Existing solutions often adapt conventional methods without leveraging SDN’s native features or addressing real-time mitigation. This study introduces a novel hybrid deep learning framework for DDoS detection and mitigation in SDN, significantly advancing the state of the art. We develop a custom dataset in a Mininet–Ryu testbed that reflects realistic SDN traffic conditions, and employ a multistage feature selection pipeline to reduce redundancy and highlight the most discriminative flow attributes. A hybrid Convolutional Neural Network–Long Short-Term Memory (CNN-LSTM) model is then applied, capturing both spatial and temporal traffic patterns. The proposed system achieves 99.5% accuracy and a 97.7% F1-score, demonstrating a significant improvement over baseline ML and DL approaches. In addition, a lightweight and scalable mitigation module embedded in the SDN controller dynamically drops or reroutes malicious flows, enabling real-time, low-latency responsiveness. Experimental results across diverse topologies confirm the framework’s scalability and applicability in real-world SDN environments.