Towards Trustworthy Software-Defined Network Security: An Explainable and Computationally Efficient Machine Learning Framework for Intrusion Detection

Authors

  • Suhail Ashfaq Butt Department of Computer Science, National College of Business Administration and Economics, Lahore, 54000,Pakistan & Department of Information Sciences, Division of Science and Technology, University of Education, Lahore, 54000, Pakistan.
  • Shakir M. Usman Center for Cognitive Intelligence and AI Systems, College of Sciences and Human Studies, Prince Mohammad Bin Fahd University, Saudi Arabia.
  • Muhammad Ahsan Raza Department of Information Sciences, University of Education, Lahore, Multan Campus 60000, Pakistan.
  • Qasem M. Kharma Software Engineering Department, Hourani Center for Applied Scientific Research, Al-Ahliyya Amman University, Amman, Jordan.
  • Sagheer Abbas Department of Computer Science, Prince Mohammad Bin Fahd University, Alkhobar, 31952, KSA.
  • Taher M. Ghazal Department of Networks and Cybersecurity, Hourani Center for Applied Scientific Research, Al-Ahliyya Amman University, Amman, Jordan & Faculty of Computing and IT, Sohar University, Oman & Center for Cyber Security, Faculty of Information Science and Technology, Universiti Kebangsaan Malaysia (UKM), 43600 Bangi, Selangor, Malaysia.

DOI:

https://doi.org/10.56979/1102/2026/1523

Keywords:

Software-Defined Networking (SDN), Intrusion Detection System (IDS), Machine Learning, Explainable Artificial Intelligence (XAI), Computational Complexity

Abstract

Software-defined networking (SDN) offers flexibility and scalability but also introduces new cybersecurity challenges. We propose a scalable and transparent intrusion detection system (IDS) for SDNs using machine learning models that balance accuracy and computational efficiency. Our results show that the decision tree model achieves 99.6% accuracy with minimal missed attacks and lower computational costs compared with random forests. The training time increased with the dataset size, but the prediction time remained stable, even with 24,000 samples. Our simulation results showed that the training complexity of Random Forest increases with the number of samples, whereas the calculation time for inference is comparatively low–a finding that makes Random Forest particularly suitable for real-time detections in Software-Defined Networking (SDN) environments. By using the SHAP-based explainability analysis, we explain the most important traffic characteristics, such as the length of the packets and the destination port, which are used to decide the decision process of the model. This methodological approach ensures high recall detection without compromising performance, thus providing a high-performance and efficient solution for SDN security.

Downloads

Published

2026-09-01

How to Cite

Suhail Ashfaq Butt, Shakir M. Usman, Muhammad Ahsan Raza, Qasem M. Kharma, Sagheer Abbas, & Taher M. Ghazal. (2026). Towards Trustworthy Software-Defined Network Security: An Explainable and Computationally Efficient Machine Learning Framework for Intrusion Detection. Journal of Computing & Biomedical Informatics, 11(02). https://doi.org/10.56979/1102/2026/1523