Towards Trustworthy Software-Defined Network Security: An Explainable and Computationally Efficient Machine Learning Framework for Intrusion Detection
DOI:
https://doi.org/10.56979/1102/2026/1523Keywords:
Software-Defined Networking (SDN), Intrusion Detection System (IDS), Machine Learning, Explainable Artificial Intelligence (XAI), Computational ComplexityAbstract
Software-defined networking (SDN) offers flexibility and scalability but also introduces new cybersecurity challenges. We propose a scalable and transparent intrusion detection system (IDS) for SDNs using machine learning models that balance accuracy and computational efficiency. Our results show that the decision tree model achieves 99.6% accuracy with minimal missed attacks and lower computational costs compared with random forests. The training time increased with the dataset size, but the prediction time remained stable, even with 24,000 samples. Our simulation results showed that the training complexity of Random Forest increases with the number of samples, whereas the calculation time for inference is comparatively low–a finding that makes Random Forest particularly suitable for real-time detections in Software-Defined Networking (SDN) environments. By using the SHAP-based explainability analysis, we explain the most important traffic characteristics, such as the length of the packets and the destination port, which are used to decide the decision process of the model. This methodological approach ensures high recall detection without compromising performance, thus providing a high-performance and efficient solution for SDN security.
Downloads
Published
How to Cite
Issue
Section
License
This is an open Access Article published by Research Center of Computing & Biomedical Informatics (RCBI), Lahore, Pakistan under CCBY 4.0 International License




