{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T17:55:49Z","timestamp":1780595749541,"version":"3.54.1"},"reference-count":36,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2019,4,25]],"date-time":"2019-04-25T00:00:00Z","timestamp":1556150400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Wireless Netw"],"published-print":{"date-parts":[[2019,7]]},"DOI":"10.1007\/s11276-019-01991-y","type":"journal-article","created":{"date-parts":[[2019,4,25]],"date-time":"2019-04-25T16:05:16Z","timestamp":1556208316000},"page":"2751-2768","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":42,"title":["Lightweight solutions to counter DDoS attacks in software defined networking"],"prefix":"10.1007","volume":"25","author":[{"given":"Mauro","family":"Conti","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0051-1551","authenticated-orcid":false,"given":"Chhagan","family":"Lal","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Reza","family":"Mohammadi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Umashankar","family":"Rawat","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,4,25]]},"reference":[{"issue":"1","key":"1991_CR1","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/JPROC.2014.2371999","volume":"103","author":"D Kreutz","year":"2015","unstructured":"Kreutz, D., Ramos, F. M. V., Ver\u00edssimo, P. E., Rothenberg, C. E., Azodolmolky, S., & Uhlig, S. (2015). Software-defined networking: A comprehensive survey. Proceedings of the IEEE, 103(1), 14\u201376.","journal-title":"Proceedings of the IEEE"},{"issue":"8","key":"1991_CR2","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.4978","volume":"31","author":"M Conti","year":"2018","unstructured":"Conti, M., Kaliyar, P., & Lal C. (2018). CENSOR: Cloud-enabled secure IoT architecture over SDN paradigm. Concurrency and Computation: Practice and Experience, 31(8), e4978.","journal-title":"Concurrency and Computation: Practice and Experience"},{"issue":"11","key":"1991_CR3","doi-asserted-by":"publisher","first-page":"2457","DOI":"10.1109\/JSAC.2017.2760459","volume":"35","author":"J Du","year":"2017","unstructured":"Du, J., Gelenbe, E., Jiang, C., Zhang, H., & Ren, Y. (2017). Contract design for traffic offloading and resource allocation in heterogeneous ultra-dense networks. IEEE Journal on Selected Areas in Communications, 35(11), 2457\u20132467.","journal-title":"IEEE Journal on Selected Areas in Communications"},{"issue":"1","key":"1991_CR4","doi-asserted-by":"publisher","first-page":"602","DOI":"10.1109\/COMST.2015.2487361","volume":"18","author":"Q Yan","year":"2016","unstructured":"Yan, Q., Yu, F. R., Gong, Q., & Li, J. (2016). Software-defined networking (SDN) and distributed denial of service (DDoS) attacks in cloud computing environments: A survey, some research issues, and challenges. IEEE Communications Surveys & Tutorials, 18(1), 602\u2013622.","journal-title":"IEEE Communications Surveys & Tutorials"},{"issue":"1","key":"1991_CR5","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1109\/MCOM.2015.7010546","volume":"53","author":"JA Wickboldt","year":"2015","unstructured":"Wickboldt, J. A., Jesus, W. P. D., Isolani, P. H., Both, C. B., Rochol, J., & Granville, L. Z. (2015). Software-defined networking: Management requirements and challenges. IEEE Communications Magazine, 53(1), 278\u2013285.","journal-title":"IEEE Communications Magazine"},{"issue":"2","key":"1991_CR6","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1145\/1355734.1355746","volume":"38","author":"N McKeown","year":"2008","unstructured":"McKeown, N., Anderson, T., Balakrishnan, H., Parulkar, G., Peterson, L., Rexford, J., et al. (2008). Openflow: Enabling innovation in campus networks. SIGCOMM Computer Communication Review, 38(2), 69\u201374.","journal-title":"SIGCOMM Computer Communication Review"},{"issue":"6","key":"1991_CR7","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1109\/MNET.2016.1600109NM","volume":"30","author":"P Zhang","year":"2016","unstructured":"Zhang, P., Wang, H., Hu, C., & Lin, C. (2016). On denial of service attacks in software defined networks. IEEE Network, 30(6), 28\u201333.","journal-title":"IEEE Network"},{"key":"1991_CR8","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1109\/TNSM.2017.2701549","volume":"14","author":"R Mohammadi","year":"2017","unstructured":"Mohammadi, R., Javidan, R., & Conti, M. (2017). Slicots: An sdn-based lightweight countermeasure for tcp syn flooding attacks. IEEE Transactions on Network and Service Management, 14, 487\u2013497.","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"1991_CR9","doi-asserted-by":"crossref","unstructured":"Wang, R., Jia, Z., & Ju, L. (2015). An entropy-based distributed DDoS detection mechanism in software-defined networking. In 2015 IEEE Trustcom\/BigDataSE\/ISPA (pp. 310\u2013317). Helsinki.","DOI":"10.1109\/Trustcom.2015.389"},{"issue":"9","key":"1991_CR10","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1109\/MCOM.2017.1600970","volume":"55","author":"K Kalkan","year":"2017","unstructured":"Kalkan, K., Gur, G., & Alagoz, F. (2017). Defense mechanisms against ddos attacks in sdn environment. IEEE Communications Magazine, 55(9), 175\u2013179.","journal-title":"IEEE Communications Magazine"},{"issue":"7","key":"1991_CR11","doi-asserted-by":"publisher","first-page":"1838","DOI":"10.1109\/TIFS.2018.2805600","volume":"13","author":"J Zheng","year":"2018","unstructured":"Zheng, J., Li, Q., Gu, G., Cao, J., Yau, D. K. Y., & Wu, J. (2018). Realtime ddos defense using cots sdn switches via adaptive correlation analysis. IEEE Transactions on Information Forensics and Security, 13(7), 1838\u20131853.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"1991_CR12","doi-asserted-by":"crossref","unstructured":"Kang, M.\u00a0S., Lee, S.\u00a0B., & Gligor, V.\u00a0D. (2013). The crossfire attack. In 2013 IEEE symposium on security and privacy (pp. 127\u2013141).","DOI":"10.1109\/SP.2013.19"},{"key":"1991_CR13","doi-asserted-by":"crossref","unstructured":"Mohammadi, R., Javidan, R., Keshtgary, M., Conti, M., & Lal, C. (2017). Practical extensions to countermeasure dos attacks in software defined networking. In 2017 IEEE conference on network function virtualization and software defined networks (NFV-SDN) (pp. 1\u20136).","DOI":"10.1109\/NFV-SDN.2017.8169839"},{"key":"1991_CR14","unstructured":"Fran\u00e7ois, J., Dolberg, L., Festor, O., & Engel, T. (2014). Network security through software defined networking: A survey. In Proceedings of the conference on principles, systems and applications of IP telecommunications, ser. IPTComm \u201914. ACM (pp. 6:1\u20136:8)."},{"key":"1991_CR15","unstructured":"Fayaz, S.\u00a0K., Tobioka, Y., Sekar, V., & Bailey, M. (2015). Bohatei: Flexible and elastic ddos defense. In 24th USENIX security symposium (USENIX Security 15) (pp. 817\u2013832). Washington, DC: USENIX Association."},{"key":"1991_CR16","doi-asserted-by":"crossref","unstructured":"Rebecchi, F., Boite, J., Nardin, P., Bouet, M., & Conan, V. (2017). Traffic monitoring and ddos detection using stateful sdn. In 2017 IEEE conference on network softwarization (NetSoft) (pp. 1\u20132).","DOI":"10.1109\/NETSOFT.2017.8004256"},{"key":"1991_CR17","doi-asserted-by":"crossref","unstructured":"Chen, C., Chen, Y., Lu, W., Tsai, S., & Yang, M. (2017). Detecting amplification attacks with software defined networking. In 2017 IEEE conference on dependable and secure computing (pp. 195\u2013201).","DOI":"10.1109\/DESEC.2017.8073807"},{"key":"1991_CR18","volume-title":"Information technology\u2014New generations","author":"H D\u2019Cruze","year":"2018","unstructured":"D\u2019Cruze, H., Wang, P., Sbeit, R\u00a0. O., & Ray, A. (2018). A software-defined networking (SDN) approach to mitigating DDoS attacks. In S. Latifi (Ed.), Information technology\u2014New generations. Cham: Springer."},{"key":"1991_CR19","doi-asserted-by":"crossref","unstructured":"Dhawan, M., Poddar, R., Mahajan, K., & Mann, V. (2015). Sphinx: Detecting security attacks in software-defined networks. In NDSS.","DOI":"10.14722\/ndss.2015.23064"},{"key":"1991_CR20","unstructured":"Felipe, A., Piedrahita, M., Rueda, S., Mattos, D.\u00a0M.\u00a0F., Carlos, O., & Duarte, M.\u00a0B. (2015). Flowfence: A denial of service defense system for software defined networking. In Global information infrastructure and networking symposium (GIIS)."},{"key":"1991_CR21","doi-asserted-by":"crossref","unstructured":"Shin, S., Yegneswaran, V., Porras, P., & Gu, G. (2013). Avant-guard: Scalable and vigilant switch flow management in software-defined networks. In Proceedings of the 2013 ACM SIGSAC conference on computer & communications security, ser. CCS \u201913.","DOI":"10.1145\/2508859.2516684"},{"key":"1991_CR22","unstructured":"Sungmin, L.\u00a0Hong, Xu, H., Wang, G., & Gu (2015). Poisoning network visibility in software-defined networks: New attacks and countermeasures. In NDSS."},{"issue":"2","key":"1991_CR23","doi-asserted-by":"publisher","first-page":"1206","DOI":"10.1109\/TNET.2016.2626287","volume":"25","author":"M Ambrosin","year":"2017","unstructured":"Ambrosin, M., Conti, M., Gaspari, F. D., & Poovendran, R. (2017). Lineswitch: Tackling control plane saturation attacks in software-defined networking. IEEE\/ACM Transactions on Networking, 25(2), 1206\u20131219.","journal-title":"IEEE\/ACM Transactions on Networking"},{"key":"1991_CR24","doi-asserted-by":"crossref","unstructured":"Wang, H., Xu, L., & Gu, G. (2015). Floodguard: A dos attack prevention extension in software-defined networks. In Proceedings of the 2015 45th annual IEEE\/IFIP international conference on dependable systems and networks, ser. DSN \u201915.","DOI":"10.1109\/DSN.2015.27"},{"key":"1991_CR25","doi-asserted-by":"crossref","unstructured":"Chin, T., Mountrouidou, X., Li, X., & Xiong, K. (2015). Selective packet inspection to detect dos flooding using software defined networking (sdn). In 2015 IEEE 35th international conference on distributed computing systems workshops (pp. 95\u201399).","DOI":"10.1109\/ICDCSW.2015.27"},{"key":"1991_CR26","doi-asserted-by":"crossref","unstructured":"Park, Y., Chang, S.\u00a0Y., & Krishnamurthy, L.\u00a0M. (2016). Watermarking for detecting freeloader misbehavior in software-defined networks. In 2016 International conference on computing, networking and communications (ICNC) (pp. 1\u20136).","DOI":"10.1109\/ICCNC.2016.7440628"},{"key":"1991_CR27","unstructured":"Liu, J., Lai, Y., & Zhang, S. (2017). Fl-guard: A detection and defense system for DDoS attack in sdn. In Proceedings of the 2017 international conference on cryptography, security and privacy, ser. ICCSP \u201917 (pp. 107\u2013111) ACM. [Online]. Available: \n                    http:\/\/doi.acm.org\/10.1145\/3058060.3058074\n                    \n                  ."},{"issue":"6","key":"1991_CR28","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1109\/CC.2017.7961368","volume":"14","author":"T Wang","year":"2017","unstructured":"Wang, T., & Chen, H. (2017). Sguard: A lightweight sdn safe-guard architecture for dos attacks. China Communications, 14(6), 113\u2013125.","journal-title":"China Communications"},{"key":"1991_CR29","first-page":"309","volume-title":"Sequence number-based MAC address spoof detection","author":"F Guo","year":"2006","unstructured":"Guo, F., & Chiueh, T-c. (2006). Sequence number-based MAC address spoof detection (pp. 309\u2013329). Berlin: Springer."},{"issue":"4","key":"1991_CR30","doi-asserted-by":"publisher","first-page":"1545","DOI":"10.1109\/TNSM.2018.2861741","volume":"15","author":"P Kumar","year":"2018","unstructured":"Kumar, P., Tripathi, M., Nehra, A., Conti, M., & Lal, C. (2018). SAFETY: Early detection and mitigation of TCP SYN flood utilizing entropy in SDN. IEEE Transactions on Network and Service Management, 15(4), 1545\u20131559.","journal-title":"IEEE Transactions on Network and Service Management"},{"issue":"1","key":"1991_CR31","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1109\/TPDS.2013.36","volume":"25","author":"H Zhu","year":"2014","unstructured":"Zhu, H., Du, S., Gao, Z., Dong, M., & Cao, Z. (2014). A probabilistic misbehavior detection scheme toward efficient trust establishment in delay-tolerant networks. IEEE Transactions on Parallel and Distributed Systems, 25(1), 22\u201332.","journal-title":"IEEE Transactions on Parallel and Distributed Systems"},{"key":"1991_CR32","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1016\/j.cose.2012.09.013","volume":"32","author":"S Wang","year":"2013","unstructured":"Wang, S., Zhang, Z., & Kadobayashi, Y. (2013). Exploring attack graph for cost-benefit security hardening: A probabilistic approach. Computer Security, 32, 158\u2013169.","journal-title":"Computer Security"},{"key":"1991_CR33","unstructured":"http:\/\/www.mininet.org\/\n                    \n                  ."},{"key":"1991_CR34","unstructured":"http:\/\/www.opendaylight.org\n                    \n                  ."},{"key":"1991_CR35","unstructured":"Openflow.org. openflow switching reference system. \n                    http:\/\/www.openflow.org\/wp\/downloads\/\n                    \n                  ."},{"key":"1991_CR36","unstructured":"http:\/\/www.hping.org\n                    \n                  ."}],"container-title":["Wireless Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11276-019-01991-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11276-019-01991-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11276-019-01991-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,23]],"date-time":"2020-04-23T23:30:47Z","timestamp":1587684647000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11276-019-01991-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,4,25]]},"references-count":36,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2019,7]]}},"alternative-id":["1991"],"URL":"https:\/\/doi.org\/10.1007\/s11276-019-01991-y","relation":{},"ISSN":["1022-0038","1572-8196"],"issn-type":[{"value":"1022-0038","type":"print"},{"value":"1572-8196","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,4,25]]},"assertion":[{"value":"25 April 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}