LDoS Attack Detection in Software-Defined Networks Using Liquid Neural Networks

Authors

  • Kommera Mahesh Reddy,Mrs. J.Shilpa Author

DOI:

https://doi.org/10.62643/

Abstract

Software-Defined Networking (SDN) has transformed modern network infrastructures by separating the control plane from the data plane, providing centralized network management, enhanced flexibility, and dynamic programmability. Despite these advantages, the centralized nature of SDN environments introduces new security challenges, particularly against sophisticated Distributed Denial of Service (DDoS) variants. Among these threats, Low-rate Distributed Denial of Service (LDDoS) attacks are especially difficult to detect because they generate short bursts of malicious traffic while maintaining low average bandwidth usage, allowing them to evade conventional intrusion detection systems. These attacks exploit network and transport layer behaviors to degrade service quality without producing the traffic volumes typically associated with traditional DDoS attacks. Existing detection techniques often struggle to accurately identify such attacks due to their similarity to normal traffic fluctuations and their highly dynamic temporal characteristics. To address this challenge, this research proposes an intelligent LDDoS detection framework that combines Liquid Neural Networks (LNNs) with the Ryu Software-Defined Networking controller to enable continuous and real-time attack identification. Unlike traditional machine learning and deep learning models that rely on fixed internal representations, Liquid Neural Networks utilize adaptive continuous-time dynamics that allow the model to respond effectively to changing network conditions and evolving attack behaviors. The proposed system continuously collects and analyzes OpenFlow statistics from network devices, extracting a comprehensive set of flow-level features related to traffic volume, packet behavior, timing characteristics, and communication patterns. These features are processed by the LNN model, which dynamically updates its internal state to capture complex temporal dependencies within network traffic streams. An adaptive learning mechanism further enables the framework to learn from new observations while preserving previously acquired knowledge, ensuring long-term effectiveness against emerging attack strategies. Extensive experiments conducted on benchmark intrusion detection datasets and synthetically generated LDDoS traffic scenarios demonstrate the effectiveness of the proposed approach. The results indicate superior detection performance compared with several widely used machine learning and deep learning techniques, achieving high classification accuracy, low false alarm rates, and extremely fast response times suitable for real-time deployment. Furthermore, the system can identify malicious activity within only a few attack cycles, allowing network administrators to initiate mitigation measures before significant service degradation occurs. By integrating Liquid Neural Networks directly into an SDN controller environment, the proposed framework provides a scalable, adaptive, and efficient cybersecurity solution for protecting modern programmable networks against advanced low-rate denial-of-service attacks.

Downloads

Published

23-06-2026

How to Cite

LDoS Attack Detection in Software-Defined Networks Using Liquid Neural Networks. (2026). International Journal of Engineering Research and Science & Technology, 22(2(1), 3092-3102. https://doi.org/10.62643/