Analisis dan Mitigasi Serangan Distributed Denial of Service (DDoS) Menggunakan Metode Machine Learning Berbasis Deteksi Anomali
DOI:
https://doi.org/10.62951/bridge.v4i3.1011Keywords:
Anomaly Detection, Attack Mitigation, DDoS Attacks, Machine Learning, Network SecurityAbstract
Distributed Denial of Service (DDoS) attacks, particularly Volumetric DDoS, pose a serious threat to network infrastructure by disrupting service availability through traffic flooding. Signature-based defense approaches are often less effective in detecting new and adaptive attack patterns. This study aims to implement a Random Forest algorithm based on anomaly detection and evaluate the effectiveness of automated mitigation in a Software-Defined Networking (SDN) architecture in real time. The study employed a quantitative experiment based on network simulation. The model was trained using the CICIDS2017 dataset with stratified random sampling of 300,000 data rows. Network traffic features were normalized using Min-Max Scaler to optimize classification performance. The validated model was exported in pickle (.pkl) format and integrated into the Ryu Controller as a hybrid defense mechanism combined with a volumetric threshold. The simulation was conducted using the Mininet emulator with a single-switch topology and an ICMP Flood/Ping Flood attack scenario. The results showed that Random Forest achieved an accuracy of 99.80% during test data evaluation. Real-time testing in the SDN environment achieved a mitigation success rate of 99.79%, reducing attack traffic from 22,358 packets to only 48 packets reaching the target through automatic injection of DROP rules based on OFPFlowMod messages. The integration of machine learning and SDN effectively provides protection against Volumetric DDoS attacks with minimal mitigation response delay.
Downloads
References
Alwabisi, S., Ouni, R., & Saleem, K. (2022). Using machine learning and software-defined networking to detect and mitigate DDoS attacks in fiber-optic networks. Electronics, 11(23), 4065. https://doi.org/10.3390/electronics11234065
Bhaskara, I. M. W., Suputra, I. P. G. H., Widiartha, I. M., Kadyanan, I. G. A. G. A., Putra, I. G. N. A. C., & Dwidasmara, I. B. G. (2022). Klasifikasi serangan Distributed Denial of Service (DDoS) menggunakan Random Forest dengan CFS. JELIKU (Jurnal Elektronik Ilmu Komputer Udayana), 11(2), 215–222. https://doi.org/10.24843/JLK.2022.v11.i02.p01
Butt, H. A., Al Harthy, K. S., Shah, M. A., Hussain, M., Amin, R., & Rehman, M. U. (2024). Enhanced DDoS detection using advanced machine learning and ensemble techniques in software defined networking. Computers, Materials & Continua, 81(2), 3003–3031. https://doi.org/10.32604/cmc.2024.057185
Ekawijana, A., Bakhrun, A., & Kurniawan, M. T. (2024). Deteksi serangan DDOS pada jaringan SDN dengan metode Random Forest. Jurnal Media Informatika Budidarma, 8(1), 685–694. https://doi.org/10.30865/mib.v8i1.6928
El Sayed, M. S., Le-Khac, N.-A., Azer, M. A., & Jurcut, A. D. (2022). A flow-based anomaly detection approach with feature selection method against DDoS attacks in SDNs. IEEE Transactions on Cognitive Communications and Networking, 8(4), 1862–1880. https://doi.org/10.1109/TCCN.2022.3186331
Fathima, A., Devi, G. S., & Faizaanuddin, M. (2023). Improving distributed denial of service attack detection using supervised machine learning. Measurement: Sensors, 30, 100911. https://doi.org/10.1016/j.measen.2023.100911
Ferdiansyah, Antoni, D., Valdo, M., Mikko, Mukmin, C., & Ependi, U. (2024). Machine learning models for DDoS detection in software-defined networking: A comparative analysis. Journal of Information Systems and Informatics, 6(3), 1790–1803. https://doi.org/10.51519/journalisi.v6i3.864
Liu, Z., Wang, Y., Feng, F., Liu, Y., Li, Z., & Shan, Y. (2023). A DDoS detection method based on feature engineering and machine learning in software-defined networks. Sensors, 23(13), 6176. https://doi.org/10.3390/s23136176
Mahar, I. A., Aziz, K., Chakrabarti, P., Ahmed, N., Ladan, M., & Javed, Y. (2026). A hybrid machine learning approach for detecting DDoS attacks in software-defined networks. Scientific Reports, 16, 6533. https://doi.org/10.1038/s41598-026-35458-w
Mehmood, S., Amin, R., Mustafa, J., Hussain, M., Alsubaei, F. S., & Zakaria, M. D. (2025). Distributed Denial of Services (DDoS) attack detection in SDN using optimizer-equipped CNN-MLP. PLOS ONE, 20(1), e0312425. https://doi.org/10.1371/journal.pone.0312425
Prayogi, A., Pane, M. A. S., Dian, R., Siregar, R. M., Sugianto, R. A., & Simbolon, H. F. S. (2024). Penggunaan Random Forest dan analisis perilaku untuk prediksi serangan DDoS dalam lingkungan cloud computing. Techno.Com, 23(3), 668–678. https://doi.org/10.62411/tc.v23i3.11317
Salsabilah, S. P., Mita, A. Al, Zachwan Irsyad, M., & Sakti, E. M. S. (2024). Implementasi Penggunaan Kali linux dengan Teknik Ddos dalam Uji coba Keamanan Website. 25(1), 98–106.
Sangodoyin, A. O., Akinsolu, M. O., Pillai, P., & Grout, V. (2021). Detection and classification of DDoS flooding attacks on software-defined networks: A case study for the application of machine learning. IEEE Access, 9, 122495–122508. https://doi.org/10.1109/ACCESS.2021.3109490
Sari, L., Faiz, M. N., & Muhammad, A. W. (2025). Perbandingan pendekatan machine learning dalam deteksi serangan DDoS jaringan komputer. Infotekmesin, 16(1), 153–159. https://doi.org/10.35970/infotekmesin.v16i1.2556
Sawah, M. S., Elmannai, H., El-Bary, A. A., Lotfy, K., & Sheta, O. E. (2025). Distributed denial of service (DDoS) classification based on random forest model with backward elimination algorithm and grid search algorithm. Scientific Reports, 15, 19063. https://doi.org/10.1038/s41598-025-03868-x
Wang, S., Balarezo, J. F., Chavez, K. G., Al-Hourani, A., Kandeepan, S., Asghar, M. R., & Russello, G. (2022). Detecting flooding DDoS attacks in software defined networks using supervised learning techniques. Engineering Science and Technology, an International Journal, 35, 101176. https://doi.org/10.1016/j.jestch.2022.101176
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Bridge : Jurnal Publikasi Sistem Informasi dan Telekomunikasi

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.




