TELKOMNIKA (Telecommunication Computing Electronics and Control)
Vol 23, No 3: June 2025

Implementation of ICMP flood detection and mitigation system based on software-defined network and sFlow-RT

Rikie Kartadie (Universitas Teknologi Digital Indonesia)
Adi Kusjani (Universitas Teknologi Digital Indonesia)
Rangga Warsito (Amikom Yogyakarta)
Yudhi Kusnanto (Universitas Teknologi Digital Indonesia)
Lucia Nugraheni Harnaningrum (Universitas Teknologi Digital Indonesia)



Article Info

Publish Date
01 Jun 2025

Abstract

This study evaluates internet control message protocol (ICMP) flood detection and mitigation in software-defined networks (SDN) using an SDN architecture with sFlow-RT for real-time traffic monitoring. OpenFlow switches and sFlow agents detect malicious patterns, following the prepare, plan, design, implement, operate, optimize (PPDIOO) methodology. Unlike prior approaches, this system leverages SDN programmability and sFlow-RT’s real-time analytics to reduce ICMP packets from 311,130.2 to 99 and latency by 80%, outperforming traditional methods in speed and responsiveness. It ensures network availability, with practical benefits for large-scale networks like internet service providers (ISPs). However, sFlow sampling rates may affect accuracy in high-speed networks, and a single OpenDaylight (ODL) controller limits generalizability. Future work should test alternative controllers and extend to other DDoS types like user datagram protocol (UDP) floods in diverse topologies.

Copyrights © 2025






Journal Info

Abbrev

TELKOMNIKA

Publisher

Subject

Computer Science & IT

Description

Submitted papers are evaluated by anonymous referees by single blind peer review for contribution, originality, relevance, and presentation. The Editor shall inform you of the results of the review as soon as possible, hopefully in 10 weeks. Please notice that because of the great number of ...