{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T10:16:47Z","timestamp":1758709007427,"version":"3.40.3"},"publisher-location":"Cham","reference-count":25,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030003524"},{"type":"electronic","value":"9783030003531"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-00353-1_29","type":"book-chapter","created":{"date-parts":[[2018,9,12]],"date-time":"2018-09-12T14:13:10Z","timestamp":1536761590000},"page":"323-335","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Improving Early Attack Detection in Networks with sFlow and SDN"],"prefix":"10.1007","author":[{"given":"Alexander","family":"Leal","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juan Felipe","family":"Botero","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eduardo","family":"Jacob","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,9,13]]},"reference":[{"key":"29_CR1","unstructured":"What is iPerf\/iPerf3? (2003). https:\/\/iperf.fr\/"},{"key":"29_CR2","unstructured":"OpenvSwitch (2009). http:\/\/www.openvswitch.org"},{"key":"29_CR3","unstructured":"Floodlight Controller (2012). http:\/\/www.projectfloodlight.org"},{"key":"29_CR4","unstructured":"Mininet: An instant virtual network on your laptop (2012). http:\/\/mininet.org"},{"key":"29_CR5","unstructured":"POX controller (2012). https:\/\/github.com\/noxrepo\/pox\/"},{"key":"29_CR6","unstructured":"Ryu controller (2012). https:\/\/osrg.github.io\/ryu\/"},{"key":"29_CR7","unstructured":"Large flow (2013). http:\/\/blog.sflow.com\/2013\/06\/large-flow-detection-script.html"},{"key":"29_CR8","unstructured":"OpenDaylight controller (2013). https:\/\/www.opendaylight.org"},{"key":"29_CR9","unstructured":"Writing sFlow applications (2015). https:\/\/sflow-rt.com\/writing_applications.php"},{"key":"29_CR10","unstructured":"Allied Telesis: how to \u2014 use sFlow in a network (2013). https:\/\/www.alliedtelesis.com\/sites\/default\/files\/aw-_use_sflow_in_a_network_revb1.pdf"},{"key":"29_CR11","doi-asserted-by":"crossref","unstructured":"Buragohain, C., Medhi, N.: FlowTrApp: an SDN based architecture for DDoS attack detection and mitigation in data centers. In: 2016 3rd International Conference on Signal Processing and Integrated Networks (SPIN), pp. 519\u2013524. IEEE (2016)","DOI":"10.1109\/SPIN.2016.7566750"},{"key":"29_CR12","doi-asserted-by":"crossref","unstructured":"Dharma, N.G., Muthohar, M.F., Prayuda, J.A., Priagung, K., Choi, D.: Time-based DDoS detection and mitigation for SDN controller. In: Network Operations and Management Symposium (APNOMS), pp. 550\u2013553. IEEE (2015)","DOI":"10.1109\/APNOMS.2015.7275389"},{"key":"29_CR13","doi-asserted-by":"crossref","unstructured":"Giotis, K., Androulidakis, G., Maglaris, V.: Leveraging SDN for efficient anomaly detection and mitigation on legacy networks. In: 2014 Third European Workshop on Software Defined Networks (EWSDN), pp. 85\u201390. IEEE (2014)","DOI":"10.1109\/EWSDN.2014.24"},{"key":"29_CR14","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1016\/j.bjp.2013.10.014","volume":"62","author":"K Giotis","year":"2014","unstructured":"Giotis, K., Argyropoulos, C., Androulidakis, G., Kalogeras, D., Maglaris, V.: Combining OpenFlow and sFlow for an effective and scalable anomaly detection and mitigation mechanism on SDN environments. Comput. Netw. 62, 122\u2013136 (2014)","journal-title":"Comput. Netw."},{"issue":"3","key":"29_CR15","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1145\/1384609.1384625","volume":"38","author":"N Gude","year":"2008","unstructured":"Gude, N., et al.: NOX: towards an operating system for networks. ACM SIGCOMM Comput. Commun. Rev. 38(3), 105\u2013110 (2008)","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"29_CR16","unstructured":"Hsiao-Chung, L., Ping, W.: Implementation of an SDN-based security defense mechanism against DDoS attacks. In: DEStech Transactions on Economics, Business and Management (ICEME-EBM) (2016)"},{"key":"29_CR17","unstructured":"Lyon, G.: Nmap: The Network Mapper (1997). https:\/\/nmap.org\/"},{"issue":"2","key":"29_CR18","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1145\/1355734.1355746","volume":"38","author":"N McKeown","year":"2008","unstructured":"McKeown, N., et al.: OpenFlow: enabling innovation in campus networks. ACM SIGCOMM Comput. Commun. Rev. 38(2), 69\u201374 (2008)","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"issue":"8","key":"29_CR19","doi-asserted-by":"publisher","first-page":"988","DOI":"10.9717\/kmms.2014.17.8.988","volume":"17","author":"M Nugraha","year":"2014","unstructured":"Nugraha, M., Paramita, I., Musa, A., Choi, D., Cho, B.: Utilizing openFlow and sFlow to detect and mitigate SYN flooding attack. J. Korea Multimed. Soc. 17(8), 988\u2013994 (2014)","journal-title":"J. Korea Multimed. Soc."},{"key":"29_CR20","unstructured":"Open Networking Foundation: Software-Defined Networking (SDN) Definition (2018). https:\/\/www.opennetworking.org\/sdn-resources\/sdn-definition"},{"key":"29_CR21","doi-asserted-by":"publisher","unstructured":"Panchen, S., McKee, N., Phaal, P.: InMon corporations sFlow: a method for monitoring traffic in switched and routed networks. RFC 3176, September 2001. https:\/\/doi.org\/10.17487\/rfc3176 , https:\/\/rfc-editor.org\/rfc\/rfc3176.txt","DOI":"10.17487\/rfc3176"},{"key":"29_CR22","unstructured":"Phaal, P., Lavine, M.: sFlow protocol specification version 5 (2004)"},{"key":"29_CR23","unstructured":"Sanai, D.: Detection of promiscuous nodes using ARP packets (2001). http:\/\/www.securityfriday.com\/promiscuous_detection_01.pdf"},{"issue":"5","key":"29_CR24","first-page":"390","volume":"15","author":"M Uma","year":"2013","unstructured":"Uma, M., Padmavathi, G.: A survey on various cyber attacks and their classification. IJ Netw. Secur. 15(5), 390\u2013396 (2013)","journal-title":"IJ Netw. Secur."},{"key":"29_CR25","doi-asserted-by":"crossref","unstructured":"Zaalouk, A., Khondoker, R., Marx, R.: An orchestrator-based architecture for enhancing network-security using network monitoring and SDN control functions. In: Network Operations and Management Symposium (NOMS), pp. 1\u20139. IEEE (2014)","DOI":"10.1109\/NOMS.2014.6838409"}],"container-title":["Communications in Computer and Information Science","Applied Computer Sciences in Engineering"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-00353-1_29","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,12,18]],"date-time":"2018-12-18T20:58:56Z","timestamp":1545166736000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-00353-1_29"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030003524","9783030003531"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-00353-1_29","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2018]]}}}