Uakomba Uhongora, M. Thinyane, Yee Wei Law, J. Slay
2026.6.15European Conference on Information Warfare and Security, ECCWS
Abstract
Software-defined networking (SDN) has been proposed as a potential enabler of programmability, flexibility, and dynamic resource allocation in satellite network environments. Despite the benefits, SDN introduces cybersecurity risks to satellite networks, such as controller compromise, flow rule manipulation, and distributed denial-of-service (DDoS) attacks. To address these challenges, this paper explores intrusion detection mechanisms based on anomaly detection techniques in machine learning for detecting cyberattacks in software-defined satellite networks (SDSNs). To support experimentation with the different IDS approaches, an SDSN simulation platform was used to simulate a Walker-Delta satellite constellation for the Earth observation use case. This simulation enables experimentation with solutions that take into consideration the dynamic inter-satellite links (ISLs) and network topology, which most of the existing IDS solutions do not take into consideration. The IDS is implemented on a POX controller leveraging the southbound interface capabilities provided by OpenFlow. The paper reports on the different classification techniques investigated for the IDS, namely, Random Forest, Support Vector Machine, k-nearest neighbour (KNN), convolutional neural network (CNN) - Long Short-Term Memory (LSTM), and multidimensional Matrix Profile. While prior work has demonstrated the efficacy of machine learning and deep learning approaches for SDN, this work further validates the efficacy of the approaches in the context of dynamic topologies characteristic of satellite networks.
Citation format
UHONGORA, Uakomba, et al. Intrusion detection system for software-defined satellite networks. European Conference on Information Warfare and Security, ECCWS, 2026, 25(1): 800–809.