Flow-Based Intrusion Detection on Software-Defined Networks: A Multivariate Time Series Anomaly Detection Approach

preprint OA: closed CC-BY-4.0
AI-generated summary by claude@2026-07, 2026-07-17

This study presents the SAnDet architecture, using RNN and EncDecAD models on multivariate time series flow data to detect network intrusions, with EncDecAD outperforming RNN.

One-sentence paraphrase of the abstract; not a substitute for reading it. No clinical advice. How this works

Abstract

Abstract In this study, the SAnDet architecture, which can do anomaly-based intrusion detection by taking advantage of the capabilities offered by the SDN architecture, is presented and implemented as a controller application. A detailed description of this system which consists of three main modules which are statistics collector, anomaly detector, and anomaly prevention is given. More specifically, Replicator Neural Networks (RNN) which is a special variant of the autoencoder, and the EncDecAD method which is a special type of LSTM network that can produce successful results, especially in given data series, are used to identify unknown attacks using flow features collected from OpenFlow switches. In experiments, flow-based features extracted from network traffic data including different types of attacks, are given as input into models as time series. The results of the methods are calculated using the ROC and AUC metrics. Experimental results show that EncDecAD outperforms RNN. Moreover, it is demonstrated that this study has several benefits over previously conducted research.
Full text 12,871 characters · extracted from preprint-html · click to expand
Flow-Based Intrusion Detection on Software-Defined Networks: A Multivariate Time Series Anomaly Detection Approach | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Flow-Based Intrusion Detection on Software-Defined Networks: A Multivariate Time Series Anomaly Detection Approach Sultan ZAVRAK, Murat İskefiyeli This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-1141416/v3 This work is licensed under a CC BY 4.0 License Status: Published Journal Publication published 05 Mar, 2023 Read the published version in Neural Computing and Applications → Version 3 posted You are reading this latest preprint version Show more versions Abstract In this study, the SAnDet architecture, which can do anomaly-based intrusion detection by taking advantage of the capabilities offered by the SDN architecture, is presented and implemented as a controller application. A detailed description of this system which consists of three main modules which are statistics collector, anomaly detector, and anomaly prevention is given. More specifically, Replicator Neural Networks (RNN) which is a special variant of the autoencoder, and the EncDecAD method which is a special type of LSTM network that can produce successful results, especially in given data series, are used to identify unknown attacks using flow features collected from OpenFlow switches. In experiments, flow-based features extracted from network traffic data including different types of attacks, are given as input into models as time series. The results of the methods are calculated using the ROC and AUC metrics. Experimental results show that EncDecAD outperforms RNN. Moreover, it is demonstrated that this study has several benefits over previously conducted research. Intrusion detection anomaly detection deep learning semi-supervised learning software-defined networks time series anomaly detection Full Text Cite Share Download PDF Status: Published Journal Publication published 05 Mar, 2023 Read the published version in Neural Computing and Applications → Version 3 posted You are reading this latest preprint version Show more versions Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-1141416","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":101623453,"identity":"23f4c2b4-73aa-40e2-8191-92ae5a1df18e","order_by":0,"name":"Sultan ZAVRAK","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABCElEQVRIiWNgGAWjYFAC5gY4i+EDG5TJg1cLYyNMDzPjDCQtEkRpYeYhRov8jMT2Bz931Mkb3D782Nim7LA9f3sD44O3bQx15g3YtRjcSGxs7D3DZrjhXJpxcs65w8wSZw4wG85tY5CQOYBDi0RiYwNvGw/jzB4G48O5bYfZDCQS2KR5gVpwuQzosMbGv20S9jN72D8ftmw7zGMg/4D9Nz4tDECHNfO2GST28/AYJzO2HZYwkGBgY8anxeDMw8bZsm0JyUAtxYY959INJM4kNkvOOSchOQOXw9qTD3x821Zn28bDvlniR5k1MMQOH/zwpsyGH0/EYADGBga8MTkKRsEoGAWjgCAAADyhUlsTZXPTAAAAAElFTkSuQmCC","orcid":"https://orcid.org/0000-0001-6950-8927","institution":"Duzce University: Duzce Universitesi","correspondingAuthor":true,"submittingAuthor":false,"prefix":"","firstName":"Sultan","middleName":"","lastName":"ZAVRAK","suffix":""},{"id":101623454,"identity":"aa7b502b-c9e9-427c-a9f7-686681d5ab3a","order_by":1,"name":"Murat İskefiyeli","email":"","orcid":"","institution":"Sakarya University: Sakarya Universitesi","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Murat","middleName":"","lastName":"İskefiyeli","suffix":""}],"badges":[],"createdAt":"2021-12-04 21:14:48","currentVersionCode":3,"declarations":"","doi":"10.21203/rs.3.rs-1141416/v3","doiUrl":"https://doi.org/10.21203/rs.3.rs-1141416/v3","draftVersion":[],"editorialEvents":[{"content":"https://doi.org/10.1007/s00521-023-08376-5","type":"published","date":"2023-03-05T19:04:18+00:00"}],"editorialNote":"","failedWorkflow":false,"files":[{"id":21525021,"identity":"d10d97b2-5750-4809-ac01-ed10434cc5cc","added_by":"auto","created_at":"2022-05-16 16:58:22","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":728930,"visible":true,"origin":"","legend":"","description":"","filename":"ncaaphd3.bolumarticlev12v8.pdf","url":"https://assets-eu.researchsquare.com/files/rs-1141416/v3_covered.pdf"}],"financialInterests":"","formattedTitle":"\u003cp\u003eFlow-Based Intrusion Detection on Software-Defined Networks: A Multivariate Time Series Anomaly Detection Approach\u003c/p\u003e","fulltext":[{"header":"Full Text","content":"This preprint is available for \u003ca href='/article/rs-1141416/latest.pdf' target='_blank'\u003edownload as a PDF\u003c/a\u003e."}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":true,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Intrusion detection, anomaly detection, deep learning, semi-supervised learning, software-defined networks, time series anomaly detection","lastPublishedDoi":"10.21203/rs.3.rs-1141416/v3","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-1141416/v3","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eIn this study, the SAnDet architecture, which can do anomaly-based intrusion detection by taking advantage of the capabilities offered by the SDN architecture, is presented and implemented as a controller application. A detailed description of this system which consists of three main modules which are statistics collector, anomaly detector, and anomaly prevention is given. More specifically, Replicator Neural Networks (RNN) which is a special variant of the autoencoder, and the EncDecAD method which is a special type of LSTM network that can produce successful results, especially in given data series, are used to identify unknown attacks using flow features collected from OpenFlow switches. In experiments, flow-based features extracted from network traffic data including different types of attacks, are given as input into models as time series. The results of the methods are calculated using the ROC and AUC metrics. Experimental results show that EncDecAD outperforms RNN. Moreover, it is demonstrated that this study has several benefits over previously conducted research.\u003c/p\u003e","manuscriptTitle":"Flow-Based Intrusion Detection on Software-Defined Networks: A Multivariate Time Series Anomaly Detection Approach","msid":"","msnumber":"","nonDraftVersions":[{"code":"","date":"2023-01-26 21:19:30","doi":"","editorialEvents":[],"status":"private","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}},{"code":"","date":"2022-10-20 17:59:08","doi":"","editorialEvents":[],"status":"private","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}},{"code":3,"date":"2022-05-16 16:58:14","doi":"10.21203/rs.3.rs-1141416/v3","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}},{"code":2,"date":"2022-04-26 16:38:33","doi":"10.21203/rs.3.rs-1141416/v2","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}},{"code":1,"date":"2022-04-19 15:32:41","doi":"10.21203/rs.3.rs-1141416/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"4efd1404-da1c-409a-af80-e6f8fedf5214","owner":[],"postedDate":"May 16th, 2022","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2023-10-16T19:12:01+00:00","versionOfRecord":{"articleIdentity":"rs-1141416","link":"https://doi.org/10.1007/s00521-023-08376-5","journal":{"identity":"neural-computing-and-applications","isVorOnly":false,"title":"Neural Computing and Applications"},"publishedOn":"2023-03-05 19:04:18","publishedOnDateReadable":"March 5th, 2023"},"versionCreatedAt":"2022-05-16 16:58:14","video":"","vorDoi":"10.1007/s00521-023-08376-5","vorDoiUrl":"https://doi.org/10.1007/s00521-023-08376-5","workflowStages":[]},"version":"v3","identity":"rs-1141416","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-1141416","identity":"rs-1141416","version":["v3"]},"buildId":"FbvkV6FR0MCFSLy54lSbu","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. The paper's references may be in our DB but unresolved to ``paper_id`` (resolution happens at ingest when the cited DOI matches a row we already have). Run the cross-source citation reconcile pass to retry.

Source provenance

europepmc
last seen: 2026-05-19T01:45:01.086888+00:00
unpaywall
last seen: 2026-05-29T02:00:03.542394+00:00
License: CC-BY-4.0