{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T18:49:06Z","timestamp":1776883746621,"version":"3.51.2"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:00:00Z","timestamp":1753401600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:00:00Z","timestamp":1753401600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62462010"],"award-info":[{"award-number":["62462010"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62102111"],"award-info":[{"award-number":["62102111"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Guizhou Provincial Science and Technology Plan","award":["QianKe He Zhongda Zhuanxiang Zi[2024]003"],"award-info":[{"award-number":["QianKe He Zhongda Zhuanxiang Zi[2024]003"]}]},{"DOI":"10.13039\/501100018555","name":"Science and Technology Program of Guizhou Province","doi-asserted-by":"publisher","award":["Qian Ke He Jichu-ZK[2023] Zhongdian 011"],"award-info":[{"award-number":["Qian Ke He Jichu-ZK[2023] Zhongdian 011"]}],"id":[{"id":"10.13039\/501100018555","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Big Data Security and Network Security Innovation Team of Guizhou Provincial High Education Institution","award":["[2023]052"],"award-info":[{"award-number":["[2023]052"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J. King Saud Univ. Comput. Inf. Sci."],"published-print":{"date-parts":[[2025,8]]},"DOI":"10.1007\/s44443-025-00149-5","type":"journal-article","created":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T15:40:37Z","timestamp":1753458037000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Towards saturation attack detection in SDN: a multi-edge representation learning-based method"],"prefix":"10.1007","volume":"37","author":[{"given":"Zhangli","family":"Ji","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0880-675X","authenticated-orcid":false,"given":"Yunhe","family":"Cui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yinyan","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1329-4058","authenticated-orcid":false,"given":"Guowei","family":"Shen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chun","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,7,25]]},"reference":[{"key":"149_CR1","doi-asserted-by":"publisher","unstructured":"Benson T, Akella A, Maltz DA (2010) Network traffic characteristics of data centers in the wild. In: Proceedings of the 10th ACM SIGCOMM conference on Internet measurement, pp 267\u2013280. https:\/\/doi.org\/10.1145\/1879141.1879175","DOI":"10.1145\/1879141.1879175"},{"key":"149_CR2","unstructured":"Biondi P (2003) Scapy \u2014 scapy.net. https:\/\/scapy.net\/"},{"issue":"6","key":"149_CR3","doi-asserted-by":"publisher","first-page":"3855","DOI":"10.1109\/TDSC.2021.3108782","volume":"19","author":"Y Cao","year":"2021","unstructured":"Cao Y, Jiang H, Deng Y et al (2021) Detecting and mitigating ddos attacks in sdn using spatial-temporal graph convolutional network. IEEE Trans Depend Secure Comput 19(6):3855\u20133872. https:\/\/doi.org\/10.1109\/TDSC.2021.3108782","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"149_CR4","doi-asserted-by":"publisher","first-page":"11003","DOI":"10.1016\/j.knosys.2022.110030","volume":"258","author":"E Caville","year":"2022","unstructured":"Caville E, Lo WW, Layeghy S et al (2022) Anomal-e: a self-supervised network intrusion detection system based on graph neural networks. Knowl-Based Syst 258:11003. https:\/\/doi.org\/10.1016\/j.knosys.2022.110030","journal-title":"Knowl-Based Syst"},{"issue":"6","key":"149_CR5","first-page":"210","volume":"40","author":"X Chen","year":"2019","unstructured":"Chen X, Hua Q, Zhu Y et al (2019) Research on low-rate ddos attack of sdn network in cloud environment. Tongxin Xuebao 40(6):210\u2013222","journal-title":"Tongxin Xuebao"},{"key":"149_CR6","unstructured":"Foundation ON (2012) Software-defined networking: the new norm for networks. Tech. rep., open networking foundation. https:\/\/opennetworking.org\/sdn-resources\/whitepapers\/software-defined-networking-the-new-norm-for-networks\/"},{"key":"149_CR7","doi-asserted-by":"publisher","first-page":"10353","DOI":"10.1016\/j.jisa.2023.103532","volume":"76","author":"M Gao","year":"2023","unstructured":"Gao M, Wu L, Li Q et al (2023) Anomaly traffic detection in iot security using graph neural networks. J Inf Secur Appl 76:10353. https:\/\/doi.org\/10.1016\/j.jisa.2023.103532","journal-title":"J Inf Secur Appl"},{"key":"149_CR8","doi-asserted-by":"publisher","first-page":"10366","DOI":"10.1016\/j.cose.2023.103661","volume":"138","author":"V Hnamte","year":"2024","unstructured":"Hnamte V, Najar AA, Nhung-Nguyen H et al (2024) Ddos attack detection and mitigation using deep neural network in sdn environment. Comput Secur 138:10366. https:\/\/doi.org\/10.1016\/j.cose.2023.103661","journal-title":"Comput Secur"},{"issue":"4","key":"149_CR9","doi-asserted-by":"publisher","first-page":"2181","DOI":"10.1109\/COMST.2014.2326417","volume":"16","author":"F Hu","year":"2014","unstructured":"Hu F, Hao Q, Bao K (2014) A survey on software-defined network and openflow: from concept to implementation. IEEE Commun Surv Tutor 16(4):2181\u2013220. https:\/\/doi.org\/10.1109\/COMST.2014.2326417","journal-title":"IEEE Commun Surv Tutor"},{"issue":"10","key":"149_CR10","doi-asserted-by":"publisher","first-page":"2358","DOI":"10.1109\/JSAC.2018.2869997","volume":"36","author":"K Kalkan","year":"2018","unstructured":"Kalkan K, Altay L, G\u00fcr G et al (2018) Jess: joint entropy-based ddos defense scheme in sdn. IEEE J Sel Areas Commun 36(10):2358\u2013237. https:\/\/doi.org\/10.1109\/JSAC.2018.2869997","journal-title":"IEEE J Sel Areas Commun"},{"key":"149_CR11","unstructured":"Kipf TN, Welling M (2016) Semi-supervised classification with graph convolutional networks. arXiv:1609.02907"},{"issue":"9","key":"149_CR12","doi-asserted-by":"publisher","first-page":"1765","DOI":"10.1109\/JSAC.2011.111002","volume":"29","author":"S Knight","year":"2011","unstructured":"Knight S, Nguyen HX, Falkner N et al (2011) The internet topology zoo. IEEE J Sel Areas Commun 29(9):1765\u20131775. https:\/\/doi.org\/10.1109\/JSAC.2011.111002","journal-title":"IEEE J Sel Areas Commun"},{"key":"149_CR13","doi-asserted-by":"publisher","unstructured":"Kong D, Wu C, Shen Y, et\u00a0al (2022) Tableguard: a novel security mechanism against flow table overflow attacks in sdn. In: GLOBECOM 2022-2022 IEEE global communications conference, IEEE, pp 4167\u20134172. https:\/\/doi.org\/10.1109\/GLOBECOM48099.2022.10001437","DOI":"10.1109\/GLOBECOM48099.2022.10001437"},{"key":"149_CR14","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102597","author":"Z Liu","year":"2021","unstructured":"Liu Z, Fang Y, Huang C et al (2021) Graphxss: an efficient xss payload detection approach based on graph convolutional network. Comput Secur. https:\/\/doi.org\/10.1016\/j.cose.2021.102597","journal-title":"Comput Secur"},{"key":"149_CR15","doi-asserted-by":"publisher","unstructured":"Lo WW, Layeghy S, Sarhan M, et\u00a0al (2022) E-graphsage: a graph neural network based intrusion detection system for iot. In: NOMS 2022-2022 IEEE\/IFIP network operations and management symposium, IEEE, pp 1\u20139. https:\/\/doi.org\/10.1109\/NOMS54207.2022.9789878","DOI":"10.1109\/NOMS54207.2022.9789878"},{"issue":"2","key":"149_CR16","first-page":"252","volume":"9","author":"M Madathi","year":"2022","unstructured":"Madathi M, Harini R, Monikaa R et al (2022) Detection of ddos attack in sdn environment using knn algorithm. IJRAR-Int J Res Anal Rev (IJRAR) 9(2):252\u2013257","journal-title":"IJRAR-Int J Res Anal Rev (IJRAR)"},{"issue":"2","key":"149_CR17","first-page":"30","volume":"17","author":"N McKeown","year":"2009","unstructured":"McKeown N (2009) Software-defined networking. INFOCOM Keynote Talk 17(2):30\u201332","journal-title":"Software-defined networking. INFOCOM Keynote Talk"},{"key":"149_CR18","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2024.3446178","author":"A Mudgal","year":"2024","unstructured":"Mudgal A, Verma A, Singh M et al (2024) Flora: flow table low-rate overflow reconnaissance and detection in sdn. IEEE Trans Netw Serv Manag. https:\/\/doi.org\/10.1109\/TNSM.2024.3446178","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"149_CR19","doi-asserted-by":"publisher","unstructured":"Nagaraj K, Starke A, McNair J (2021) Glass: a graph learning approach for software defined network based smart grid ddos security. In: ICC 2021-IEEE international conference on communications, IEEE, pp 1\u20136. https:\/\/doi.org\/10.1109\/ICC42927.2021.9500999","DOI":"10.1109\/ICC42927.2021.9500999"},{"key":"149_CR20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103716","volume":"139","author":"AA Najar","year":"2024","unstructured":"Najar AA, Naik SM (2024) Cyber-secure sdn: a cnn-based approach for efficient detection and mitigation of ddos attacks. Comput Secur 139:103716. https:\/\/doi.org\/10.1016\/j.cose.2024.103716","journal-title":"Comput Secur"},{"issue":"4","key":"149_CR21","doi-asserted-by":"publisher","first-page":"1048","DOI":"10.1109\/tccn.2021.3102971","volume":"7","author":"TG Nguyen","year":"2021","unstructured":"Nguyen TG, Phan TV, Hoang DT et al (2021) Federated deep reinforcement learning for traffic monitoring in sdn-based iot networks. IEEE Trans Cognit Commun Netw 7(4):1048\u20131065. https:\/\/doi.org\/10.1109\/tccn.2021.3102971","journal-title":"IEEE Trans Cognit Commun Netw"},{"issue":"3","key":"149_CR22","doi-asserted-by":"publisher","first-page":"1617","DOI":"10.1109\/SURV.2014.012214.00180","volume":"16","author":"BAA Nunes","year":"2014","unstructured":"Nunes BAA, Mendonca M, Nguyen XN et al (2014) A survey of software-defined networking: Past, present, and future of programmable networks. IEEE Commun Surv Tutor 16(3):1617\u20131634. https:\/\/doi.org\/10.1109\/SURV.2014.012214.00180","journal-title":"IEEE Commun Surv Tutor"},{"key":"149_CR23","doi-asserted-by":"publisher","unstructured":"Phan TV, Gias TR, Islam ST, et\u00a0al (2019) Q-mind: defeating stealthy dos attacks in sdn with a machine-learning based defense framework. In: 2019 IEEE global communications conference (GLOBECOM), IEEE, pp 1\u20136. https:\/\/doi.org\/10.1109\/GLOBECOM38437.2019.9013585","DOI":"10.1109\/GLOBECOM38437.2019.9013585"},{"key":"149_CR24","doi-asserted-by":"publisher","unstructured":"Qian Y, You W, Qian K (2016) Openflow flow table overflow attacks and countermeasures. In: 2016 European conference on networks and communications (EuCNC), IEEE, pp 205\u2013209. https:\/\/doi.org\/10.1109\/EuCNC.2016.7561033","DOI":"10.1109\/EuCNC.2016.7561033"},{"issue":"4","key":"149_CR25","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0299846","volume":"19","author":"L Ran","year":"2024","unstructured":"Ran L, Cui Y, Zhao J et al (2024) Titan: combining a bidirectional forwarding graph and gcn to detect saturation attack targeted at sdn. Plos One 19(4):e029984. https:\/\/doi.org\/10.1371\/journal.pone.0299846","journal-title":"Plos One"},{"key":"149_CR26","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1016\/j.comcom.2021.01.018","volume":"169","author":"PP Ray","year":"2021","unstructured":"Ray PP, Kumar N (2021) Sdn\/nfv architectures for edge-cloud oriented iot: a systematic review. Comput Commun 169:129\u2013153. https:\/\/doi.org\/10.1016\/j.comcom.2021.01.018","journal-title":"Comput Commun"},{"key":"149_CR27","doi-asserted-by":"publisher","unstructured":"Schlichtkrull M, Kipf TN, Bloem P, et\u00a0al (2018) Modeling relational data with graph convolutional networks. In: The semantic web: 15th international conference, ESWC 2018, Heraklion, Crete, Greece, June 3\u20137, 2018, proceedings 15, Springer, pp 593\u2013607. https:\/\/doi.org\/10.1007\/978-3-319-93417-4_38","DOI":"10.1007\/978-3-319-93417-4_38"},{"issue":"7","key":"149_CR28","doi-asserted-by":"publisher","first-page":"1544","DOI":"10.7544\/ISSN1000-1239.2021.20200480","volume":"58","author":"X Shengxu","year":"2021","unstructured":"Shengxu X, Changyou X, Guomin Z et al (2021) Survey of openflow switch flow table overflow mitigation techniques. J Comput Res Dev 58(7):1544\u20131562. https:\/\/doi.org\/10.7544\/ISSN1000-1239.2021.20200480","journal-title":"J Comput Res Dev"},{"key":"149_CR29","doi-asserted-by":"publisher","unstructured":"Sudar KM, Deepalakshmi P (2022) Flow-based detection and mitigation of low-rate ddos attack in sdn environment using machine learning techniques. In: IoT and analytics for sensor networks: proceedings of ICWSNUCA 2021, Springer, pp 193\u2013205. https:\/\/doi.org\/10.1007\/978-981-16-2919-8_18","DOI":"10.1007\/978-981-16-2919-8_18"},{"issue":"4","key":"149_CR30","doi-asserted-by":"publisher","first-page":"5073","DOI":"10.1109\/TNSM.2023.3270339","volume":"20","author":"D Tang","year":"2023","unstructured":"Tang D, Gao C, Liang W et al (2023) Ftmaster: a detection and mitigation system of low-rate flow table overflow attacks via sdn. IEEE Trans Netw Serv Manag 20(4):5073\u20135084. https:\/\/doi.org\/10.1109\/TNSM.2023.3270339","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"149_CR31","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2023.103597","volume":"213","author":"D Tang","year":"2023","unstructured":"Tang D, Zhang D, Qin Z et al (2023) Sfto-guard: real-time detection and mitigation system for slow-rate flow table overflow attacks. J Netw Comput Appl 213:103597. https:\/\/doi.org\/10.1016\/j.jnca.2023.103597","journal-title":"J Netw Comput Appl"},{"key":"149_CR32","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2023.103722","volume":"219","author":"K Wang","year":"2023","unstructured":"Wang K, Cui Y, Qian Q et al (2023) Usage: uncertain flow graph and spatio-temporal graph convolutional network-based saturation attack detection method. J Netw Comput Appl 219:103722. https:\/\/doi.org\/10.1016\/j.jnca.2023.103722","journal-title":"J Netw Comput Appl"},{"key":"149_CR33","unstructured":"Wang M, Zheng D, Chen Z, et\u00a0al (2019) Gatconv ; dgl 2.5 documentation. https:\/\/www.dgl.ai\/dgl_docs\/generated\/dgl.nn.pytorch.conv.GATConv.html#dgl.nn.pytorch.conv.GATConv"},{"key":"149_CR34","doi-asserted-by":"publisher","unstructured":"Wang R, Jia Z, Ju L (2015) An entropy-based distributed ddos detection mechanism in software-defined networking. In: 2015 IEEE Trustcom\/BigDataSE\/ISPA, IEEE, pp 310\u2013317. https:\/\/doi.org\/10.1109\/Trustcom.2015.389","DOI":"10.1109\/Trustcom.2015.389"},{"issue":"2","key":"149_CR35","doi-asserted-by":"publisher","first-page":"957","DOI":"10.1109\/COMST.2021.3067807","volume":"23","author":"S Wijethilaka","year":"2021","unstructured":"Wijethilaka S, Liyanage M (2021) Survey on network slicing for internet of things realization in 5g networks. IEEE Commun Surv Tutor 23(2):957\u201399. https:\/\/doi.org\/10.1109\/COMST.2021.3067807","journal-title":"IEEE Commun Surv Tutor"},{"key":"149_CR36","doi-asserted-by":"publisher","unstructured":"Zhang M, Bi J, Bai J, et\u00a0al (2017) Ftguard: a priority-aware strategy against the flow table overflow attack in sdn. In: Proceedings of the SIGCOMM posters and demos. p 141\u2013143. https:\/\/doi.org\/10.1145\/3123878.3132015","DOI":"10.1145\/3123878.3132015"},{"key":"149_CR37","doi-asserted-by":"publisher","unstructured":"Zheng J, Li D (2019) Gcn-tc: combining trace graph with statistical features for network traffic classification. In: ICC 2019-2019 IEEE international conference on communications (ICC), IEEE, pp 1\u20136. https:\/\/doi.org\/10.1109\/ICC.2019.8761115","DOI":"10.1109\/ICC.2019.8761115"}],"container-title":["Journal of King Saud University Computer and Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44443-025-00149-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s44443-025-00149-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44443-025-00149-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,28]],"date-time":"2025-08-28T11:42:53Z","timestamp":1756381373000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s44443-025-00149-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,25]]},"references-count":37,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2025,8]]}},"alternative-id":["149"],"URL":"https:\/\/doi.org\/10.1007\/s44443-025-00149-5","relation":{},"ISSN":["1319-1578","2213-1248"],"issn-type":[{"value":"1319-1578","type":"print"},{"value":"2213-1248","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,25]]},"assertion":[{"value":"16 April 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 June 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 July 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interests"}}],"article-number":"138"}}