[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118328-en":3,"doc-seo-118328-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":20,"language":21,"language_code":22,"site_id":23,"html_lang":22,"table_of_contents":24,"faqs":25,"seo_title":26,"seo_description":14,"update_tm":27,"read_time":28},118328,5909887254083,"Miles","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","An Evaluation of Machine Learning Methods for Classifying Bot Traffic in Software Defined Networks - study","Internet security relies increasingly on detecting cyberattacks to preserve network services. Machine learning can support this goal, yet deployment is difficult in non-centralized environments where no single node has a full network view. Software Defined Networks (SDNs) provide centralized visibility, enabling models to recognize malicious behavior patterns. This work evaluates multiple classifiers on the InSDN dataset of sniffed packets from a virtual SDN, including models trained with fewer features, measuring both classification capability and runtime.","An Evaluation of Machine Learning Methods for Classifying Bot Trafﬁc in Software Deﬁned  \nNetworks  \nJoshua van Staden 1 and Dane Brown2  \nComputer Science, Rhodes University  \nGrahamstown, South Africa  \n[1](1 g14v2805@campus.ru.ac.za)[ g14v2805@campus.ru.ac.za](1 g14v2805@campus.ru.ac.za), [2](2 d.brown@ru.ac.za)[ d.brown@ru.ac.za](2 d.brown@ru.ac.za)  \nAbstract—Internet security is an ever-expanding ﬁeld. Cyberattacks occur very frequently, and so detecting them is an important aspect of preserving services. Machine learning offers a helpful tool with which to detect cyber attacks. However, it is impossible to deploy a machine-learning algorithm to detect attacks in a non-centralized network. Software Deﬁned Networks (SDNs) offer a centralized view of a network, allowing machine learning algorithms to detect malicious activity within a network.  \nThe InSDN dataset is a recently-released dataset that contains a set of sniffed packets within a virtual SDN. These sniffed packets correspond to various attacks, including DDoS attacks, Probing and Password-Guessing, among others. This study aims to evaluate various machine learning models against this new dataset. Speciﬁcally, we aim to evaluate their classiﬁcation ability and runtimes when trained on fewer features. The machine learning models tested include a Neural Network, Support Vector Machine, Random Forest, Multilayer Perceptron, Logistic Regression and K-Nearest Neighbours.  \nCluster-based algorithms such as the K-Nearest Neighbour and Random Forest proved to be the best performers. Linearbased algorithms such as the Multilayer Perceptron performed the worst. This suggests a good level of clustering in the top few features with little space for linear separability. The reduction of features signiﬁcantly reduced training time, particularly in the better-performing models.  \nIndex Terms—Machine Learning, Software Deﬁned Networks, Security  \nI. INTRODUCTION  \nBots are typically seen as a problem in various services, speciﬁcally in social networks. These bots come about from compromised machines, which form part of a zombie botnet. These bots can then perform any number of illegal activities based on instructions sent to them by the owner of the bot. With multiple bots in a botnet, coordinated attacks can be done to, for example, execute a Distributed Denial-of-Service (DDoS) on a server.  \nThese bot-coordinated attacks are difﬁcult to detect at the router level, as the router can only see its speciﬁc portion of the network. Software Deﬁned Networks (SDNs) offer a global, centralized view of the network. This provides an opportunity for Machine Learning models to identify the pattern of a DDoS attack and block the relevant IP addresses.  \nThis study was funded by National Research Foundation (120654) . This work was undertaken in the Distributed Multimedia CoE at Rhodes University.  \nThis study offers a comparison of various forms of machine learning for identifying malicious bot activity on a network. We aim to examine the machine learning algorithms best suited for classiﬁcation of malicious activity with very limited data. Our hope is that this will give insight into these forms of activity and pave the way for more efﬁcient forms of machine learning for malicious activity classiﬁcation.  \nSection II provides an overview of the literature surrounding this topic. In Section III, we discuss each form of classiﬁcation using machine learning. Section IV explores a recentlyreleased dataset, InSDN, identifying various bot-related malicious activities. Section V describes the experiment design for evaluating the machine learning models. Finally, Section VI applies these machine learning algorithms to bot-related activities and evaluates each algorithm for its ability to classify malicious coordinated activity.  \nII. RELATED WORK  \nWu [et. al](et. al). [1] provide a comparison of various forms of unsupervised learning to detect bots using trafﬁc analysis. The authors used dataset","cbCailSGo9zElWs5","https://ap.wps.com/l/cbCailSGo9zElWs5","pdf",674545,1,"English","en",105,"# Introduction\n## Bots and botnet coordinated attacks\n## Role of SDNs in detection\n# Related Work\n## Unsupervised bot detection via traffic analysis\n## DDoS detection comparisons across ML models\n## Random Forest ransomware detection over SDNs\n## Botnet detection for P2P architectures\n# Dataset and Experiment Design\n## InSDN dataset and bot-related activities","[{\"question\":\"Why are SDNs important for classifying bot traffic using machine learning?\",\"answer\":\"SDNs provide a global, centralized view of network traffic, which is difficult to achieve at the router level. This centralized perspective helps machine learning models detect and block malicious activity patterns.\"},{\"question\":\"What is the InSDN dataset used in this study?\",\"answer\":\"InSDN is a recently released dataset containing sniffed packets from a virtual SDN. The packets correspond to multiple attack types, including DDoS and probing/password-guessing activity.\"},{\"question\":\"Which machine learning models performed best and worst in the evaluation?\",\"answer\":\"The study reports that cluster-based methods such as K-Nearest Neighbours and Random Forest performed best. Linear-based methods such as Multilayer Perceptron performed worst, indicating limited linear separability among top features.\"}]","An Evaluation of Machine Learning Methods for Classifying Bot Traffic in Software Defined Networks - study | PDF",1785683081,3,{"code":4,"msg":30,"data":31},"ok",{"site_id":23,"language":22,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"an-evaluation-of-machine-learning-methods-for-classifying-bot-traffic-in-software-defined-networks-study","",{"@graph":35,"@context":84},[36,52,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,49],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":28},"https://docshare.wps.com/document/research-report/",{"item":50,"name":13,"@type":42,"position":51},"https://docshare.wps.com/document/an-evaluation-of-machine-learning-methods-for-classifying-bot-traffic-in-software-defined-networks-study/118328/",4,{"url":50,"name":13,"@type":53,"author":54,"headline":13,"publisher":56,"fileFormat":59,"inLanguage":22,"description":14,"dateModified":60,"datePublished":61,"encodingFormat":59,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":55},"Person",{"url":40,"name":57,"@type":58},"DocShare","Organization","application/pdf","2026-09-04","2026-08-02",true,{"@type":64,"interactionType":65,"userInteractionCount":20},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"Why are SDNs important for classifying bot traffic using machine learning?","Question",{"text":74,"@type":75},"SDNs provide a global, centralized view of network traffic, which is difficult to achieve at the router level. This centralized perspective helps machine learning models detect and block malicious activity patterns.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"What is the InSDN dataset used in this study?",{"text":79,"@type":75},"InSDN is a recently released dataset containing sniffed packets from a virtual SDN. The packets correspond to multiple attack types, including DDoS and probing/password-guessing activity.",{"name":81,"@type":72,"acceptedAnswer":82},"Which machine learning models performed best and worst in the evaluation?",{"text":83,"@type":75},"The study reports that cluster-based methods such as K-Nearest Neighbours and Random Forest performed best. Linear-based methods such as Multilayer Perceptron performed worst, indicating limited linear separability among top features.","https://schema.org",{"og:url":50,"og:type":86,"og:title":13,"og:site_name":57,"og:description":14},"article",{"robots":88,"canonical":50},"index,follow",{"doc_id":7,"site_id":23},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":51,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":105,"slug":137},19,"General","general"]