{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T10:00:14Z","timestamp":1773655214097,"version":"3.50.1"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"20","license":[{"start":{"date-parts":[[2018,8,16]],"date-time":"2018-08-16T00:00:00Z","timestamp":1534377600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100012166","name":"973 Program","doi-asserted-by":"crossref","award":["2013CB329100"],"award-info":[{"award-number":["2013CB329100"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"crossref","award":["2015JBM008"],"award-info":[{"award-number":["2015JBM008"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Soft Comput"],"published-print":{"date-parts":[[2018,10]]},"DOI":"10.1007\/s00500-018-3407-3","type":"journal-article","created":{"date-parts":[[2018,8,16]],"date-time":"2018-08-16T07:25:36Z","timestamp":1534404336000},"page":"6797-6809","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":34,"title":["Defending against Packet-In messages flooding attack under SDN context"],"prefix":"10.1007","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8641-4057","authenticated-orcid":false,"given":"Deyun","family":"Gao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zehui","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ying","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chuan Heng","family":"Foh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ting","family":"Zhi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Han-Chieh","family":"Chao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,8,16]]},"reference":[{"key":"3407_CR1","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1109\/MCOM.2015.7081073","volume":"53","author":"A Akhunzada","year":"2015","unstructured":"Akhunzada A, Ahmed E, Gani A (2015) Securing software defined networks: taxonomy, requirements, and open issues. IEEE Commun Mag 53:36\u201344","journal-title":"IEEE Commun Mag"},{"key":"3407_CR2","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1145\/1402946.1402967","volume":"38","author":"M Al-Fares","year":"2008","unstructured":"Al-Fares M, Loukissas A, Vahdat A (2008) A scalable, commodity data center network architecture. ACM SIGCOMM Comput Commun Rev 38:63\u201374","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"3407_CR3","doi-asserted-by":"crossref","unstructured":"Benson T, Akella A, Maltz D-A (2010) Network traffic characteristics of data centers in the wild. In: ACM SIGCOMM conference on internet measurement, pp 267\u2013280","DOI":"10.1145\/1879141.1879175"},{"key":"3407_CR4","doi-asserted-by":"crossref","unstructured":"Borgnat P, Dewaele G, Fukuda K (2009) Seven years and one day: Sketching the evolution of internet traffic. In: IEEE INFOCOM. pp 711\u2013719","DOI":"10.1109\/INFCOM.2009.5061979"},{"key":"3407_CR5","doi-asserted-by":"crossref","unstructured":"Braga R, Mota E, Passito A (2010) Lightweight DDoS flooding attack detection using NOX\/OpenFlow. In: IEEE conference on local computer networks, pp 408\u2013415","DOI":"10.1109\/LCN.2010.5735752"},{"key":"3407_CR6","unstructured":"D-ITG [Online]. Available: \n                    http:\/\/traffic.comics.unina.it\/software\/ITG\/\n                    \n                  . Accessed 2017"},{"key":"3407_CR7","doi-asserted-by":"crossref","unstructured":"Dong P, Du X, Zhang H (2016) A detection method for a novel DDoS attack against SDN controllers by vast new low-traffic flows. In: IEEE international conference on communications. pp 1\u20136","DOI":"10.1109\/ICC.2016.7510992"},{"key":"3407_CR8","doi-asserted-by":"crossref","unstructured":"Feng Y, Guo R, Wang D (2009) Research on the active DDoS filtering algorithm based on IP flow. In: International conference on natural computation. pp 628\u2013632","DOI":"10.1109\/ICNC.2009.550"},{"key":"3407_CR9","unstructured":"Handigol N, Heller B, Jeyakumar V (2014) I know what your packet did last hop: using packet histories to troubleshoot networks. In: Usenix conference on networked systems design and implementation. pp 71\u201385"},{"key":"3407_CR10","doi-asserted-by":"crossref","unstructured":"Hong S, Xu L, Wang H (2015) Poisoning network visibility in software-defined networks: new attacks and countermeasures. In: Network and distributed system security symposium, pp 1\u201315","DOI":"10.14722\/ndss.2015.23283"},{"key":"3407_CR11","unstructured":"Intrusion detection attacks database [Online]. Available: \n                    http:\/\/www.ll.mit.edu\/ideval\/docs\/attackDB\/\n                    \n                  . Accessed 2017"},{"key":"3407_CR12","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/2534169.2486019","volume":"43","author":"S Jain","year":"2013","unstructured":"Jain S, Kumar A, Mandal S (2013) B4: experience with a globally-deployed software defined wan. ACM SIGCOMM Comput Commun Rev 43:3\u201314","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"3407_CR13","doi-asserted-by":"crossref","unstructured":"Jamjoom H, Williams D, Sharma U (2014) Don\u2019t call them middleboxes, call them middlepipes. In: The workshop on hot topics in software defined networking. pp 19\u201324","DOI":"10.1145\/2620728.2620760"},{"key":"3407_CR14","doi-asserted-by":"publisher","first-page":"1955","DOI":"10.1109\/COMST.2014.2320094","volume":"16","author":"Y Jarraya","year":"2014","unstructured":"Jarraya Y, Madi T, Debbabi M (2014) A survey and a layered taxonomy of software-defined networking. IEEE Commun Surv Tutor 16:1955\u20131980","journal-title":"IEEE Commun Surv Tutor"},{"key":"3407_CR15","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1109\/MCOM.2013.6461195","volume":"51","author":"H Kim","year":"2013","unstructured":"Kim H, Feamster N (2013) Improving network management with software defined networking. IEEE Commun Mag 51:114\u2013119","journal-title":"IEEE Commun Mag"},{"key":"3407_CR16","doi-asserted-by":"crossref","unstructured":"Kluti R, Kotronis V, Smith P (2013) OpenFlow: a security analysis. In: IEEE international conference on network protocols, pp 1\u20136","DOI":"10.1109\/ICNP.2013.6733671"},{"key":"3407_CR17","doi-asserted-by":"crossref","unstructured":"Kotani D, Okabe Y (2014) A packet-in message filtering mechanism for protection of control plane in openflow networks. In: Tenth ACM\/IEEE symposium on architectures for networking and communications systems. pp 29\u201340","DOI":"10.1145\/2658260.2658276"},{"key":"3407_CR18","first-page":"10","volume":"103","author":"D Kreutz","year":"2014","unstructured":"Kreutz D, Ramos F-M-V, Esteves\u00a0Verissimo P (2014) Software-defined networking: a comprehensive survey. Proc IEEE 103:10\u201313","journal-title":"Proc IEEE"},{"key":"3407_CR19","unstructured":"Li J, Mirkovic J, Wang M (2002) SAVE: source address validity enforcement protocol. In: Joint conference of the IEEE computer and communications societies. pp 1557\u20131566"},{"key":"3407_CR20","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1145\/1355734.1355746","volume":"38","author":"N Mckeown","year":"2008","unstructured":"Mckeown N, Anderson T, Balakrishnan H (2008) OpenFlow: enabling innovation in campus networks. ACM SIGCOMM Comput Commun Rev 38:69\u201374","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"3407_CR21","unstructured":"Mininet [Online]. Available: \n                    http:\/\/mininet.org\/\n                    \n                  . Accessed 2017"},{"key":"3407_CR22","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1145\/997150.997156","volume":"34","author":"J Mirkovic","year":"2004","unstructured":"Mirkovic J, Reiher P (2004) A taxonomy of DDoS attack and DDoS defense mechanisms. ACM SIGCOMM Comput Commun Rev 34:39\u201353","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"3407_CR23","unstructured":"Mousavi S-M, St-Hilaire M (2015) Early detection of DDoS attacks against SDN controllers. In: International conference on computing, networking and communications. pp 77\u201381"},{"key":"3407_CR24","unstructured":"Open Networking Foundation [Online]. Available: \n                    https:\/\/www.opennetworking.org\/\n                    \n                  . Accessed 2017"},{"key":"3407_CR25","doi-asserted-by":"publisher","first-page":"370","DOI":"10.1109\/91.413225","volume":"3","author":"N-R Pal","year":"1995","unstructured":"Pal N-R, Bezdek J-C (1995) On cluster validity for the fuzzy c-means model. IEEE Trans Fuzzy Syst 3:370\u2013379","journal-title":"IEEE Trans Fuzzy Syst"},{"key":"3407_CR26","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/964723.383061","volume":"31","author":"K Park","year":"2001","unstructured":"Park K, Lee H (2001) On the effectiveness of route-based packet filtering for distributed DoS attack prevention in power-law internets. ACM SIGCOMM Comput Commun Rev 31:15\u201326","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"3407_CR27","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/1216370.1216373","volume":"39","author":"T Peng","year":"2007","unstructured":"Peng T, Leckie C, Ramamohanarao K (2007) Survey of network-based defense mechanisms countering the DoS and DDoS problems. ACM Comput Surv 39:3","journal-title":"ACM Comput Surv"},{"key":"3407_CR28","unstructured":"POX [Online]. Available: \n                    http:\/\/www.noxrepo.org\/pox\/about-pox\/\n                    \n                  . Accessed 2017"},{"key":"3407_CR29","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1109\/MCOM.2013.6553676","volume":"51","author":"S Sezer","year":"2013","unstructured":"Sezer S, Scott-Hayward S, Chouhan P-K (2013) Are we ready for SDN? Implementation challenges for software-defined networks. IEEE Commun Mag 51:36\u201343","journal-title":"IEEE Commun Mag"},{"key":"3407_CR30","doi-asserted-by":"crossref","unstructured":"Shin S, Yegneswaran V, Porras P (2013) AVANT-GUARD: scalable and vigilant switch flow management in software-defined networks. In: ACM Sigsac conference on computer and communications security, pp 413\u2013424","DOI":"10.1145\/2508859.2516684"},{"key":"3407_CR31","doi-asserted-by":"publisher","first-page":"378","DOI":"10.1016\/j.comnet.2012.07.021","volume":"57","author":"S Silva","year":"2013","unstructured":"Silva S, Rgio S-C, Silva R-M-P (2013) Botnets: a survey, computer networks. Int J Comput Telecommun Netw 57:378\u2013403","journal-title":"Int J Comput Telecommun Netw"},{"key":"3407_CR32","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1109\/TC.2016.2560839","volume":"66","author":"E Viegas","year":"2017","unstructured":"Viegas E, Santin A, Fanca A (2017) Towards an energy-efficient anomaly-based intrusion detection engine for embedded systems. IEEE Trans Comput 66:163\u2013177","journal-title":"IEEE Trans Comput"},{"key":"3407_CR33","doi-asserted-by":"crossref","unstructured":"Wang H, Xu L, Gu G (2015) FloodGuard: a DoS attack prevention extension in software-defined networks. In: IEEE international conference on dependable systems and networks, pp 239\u2013250","DOI":"10.1109\/DSN.2015.27"},{"key":"3407_CR34","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1109\/COMST.2014.2330903","volume":"17","author":"W Xia","year":"2015","unstructured":"Xia W, Wen Y, Foh C-H (2015) A survey on software-defined networking. Commun Surv Tutor IEEE 17:27\u201351","journal-title":"Commun Surv Tutor IEEE"},{"key":"3407_CR35","doi-asserted-by":"crossref","unstructured":"Xu T, Gao D, Dong P (2017) Defending against new-flow attack in SDN-based internet of things, In: IEEE Access, p 99","DOI":"10.1109\/ACCESS.2017.2666270"},{"key":"3407_CR36","doi-asserted-by":"crossref","unstructured":"Xu Y, Liu Y (2016) DDoS attack detection under SDN context. In: IEEE INFOCOM. pp 1\u20139","DOI":"10.1109\/INFOCOM.2016.7524500"},{"key":"3407_CR37","doi-asserted-by":"publisher","first-page":"602","DOI":"10.1109\/COMST.2015.2487361","volume":"18","author":"Q Yan","year":"2016","unstructured":"Yan Q, Yu F-R, Gong Q (2016) Software-defined networking (SDN) and distributed denial of service (DDoS) attacks in cloud computing environments: a survey, some research issues, and challenges. IEEE Commun Surv Tutor 18:602\u2013622","journal-title":"IEEE Commun Surv Tutor"},{"key":"3407_CR38","doi-asserted-by":"publisher","first-page":"2245","DOI":"10.1109\/TPDS.2013.181","volume":"25","author":"S Yu","year":"2014","unstructured":"Yu S, Tian Y, Guo S (2014) Can we beat DDoS attacks in clouds. IEEE Trans Parallel Distrib Syst 25:2245\u20132254","journal-title":"IEEE Trans Parallel Distrib Syst"},{"key":"3407_CR39","doi-asserted-by":"publisher","first-page":"2046","DOI":"10.1109\/SURV.2013.031413.00127","volume":"15","author":"S-T Zargar","year":"2013","unstructured":"Zargar S-T, Joshi J, Tipper D (2013) A survey of defense mechanisms against distributed denial of service (DDoS) flooding attacks. IEEE Commun Surv Tutor 15:2046\u20132069","journal-title":"IEEE Commun Surv Tutor"},{"key":"3407_CR40","doi-asserted-by":"crossref","unstructured":"Zheng K, Wang X, Li L (2014) Joint power optimization of data center network and servers with correlation analysis. In: IEEE INFOCOM. pp 2598\u20132606","DOI":"10.1109\/INFOCOM.2014.6848207"}],"container-title":["Soft Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00500-018-3407-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00500-018-3407-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00500-018-3407-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,15]],"date-time":"2019-08-15T19:13:08Z","timestamp":1565896388000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00500-018-3407-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,8,16]]},"references-count":40,"journal-issue":{"issue":"20","published-print":{"date-parts":[[2018,10]]}},"alternative-id":["3407"],"URL":"https:\/\/doi.org\/10.1007\/s00500-018-3407-3","relation":{},"ISSN":["1432-7643","1433-7479"],"issn-type":[{"value":"1432-7643","type":"print"},{"value":"1433-7479","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,8,16]]},"assertion":[{"value":"16 August 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"The authors declared that they have no conflicts of interest to this work.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}