{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,18]],"date-time":"2026-02-18T15:06:11Z","timestamp":1771427171356,"version":"3.50.1"},"reference-count":30,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computers and Electrical Engineering"],"published-print":{"date-parts":[[2026,4]]},"DOI":"10.1016\/j.compeleceng.2025.110929","type":"journal-article","created":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T17:15:21Z","timestamp":1769620521000},"page":"110929","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["DiMCA: A novel P4-powered framework using machine learning for adaptive defense against combined DDoS and ARP spoofing attacks in SD-IoT networks"],"prefix":"10.1016","volume":"132","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-6717-7552","authenticated-orcid":false,"given":"Manal","family":"Gafar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Saied M.","family":"Abd El-atty","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6157-6578","authenticated-orcid":false,"given":"Mohamed S","family":"Arafa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.compeleceng.2025.110929_bib0001","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104310","article-title":"Current research on Internet of Things (IoT) security protocols: a survey","author":"Mishra","year":"2025","journal-title":"Comput Secur"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0002","doi-asserted-by":"crossref","first-page":"28934","DOI":"10.1109\/ACCESS.2023.3260256","article-title":"FMDADM: a multi-layer DDoS attack detection and mitigation framework using machine learning for stateful SDN-based IoT networks","volume":"11","author":"Khedr","year":"2023","journal-title":"Ieee Access"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0003","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104349","article-title":"CO-STOP: a robust P4-powered adaptive framework for comprehensive detection and mitigation of coordinated and multi-faceted attacks in SD-IoT networks","volume":"151","author":"El-Sayed","year":"2025","journal-title":"Comput Secur"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0004","article-title":"Real-time monitoring model of DDoS attacks using distance thresholds in Edge cooperation networks","volume":"89","author":"Li","year":"2025","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0005","series-title":"Assessing sdn controller vulnerabilities: a survey on attack typologies, detection mechanisms, controller selection, and dataset application in machine learning","first-page":"1","author":"Arevalo-Herrera","year":"2025"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0006","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2024.109484","article-title":"MP-GUARD: a novel multi-pronged intrusion detection and mitigation framework for scalable SD-IoT networks using cooperative monitoring, ensemble learning, and new P4-extracted feature set","volume":"118","author":"El-Sayed","year":"2024","journal-title":"Comput Electr Eng"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0007","article-title":"Multi-objective discrete extremal optimization of variable-length blocks-based CNN by joint NAS and HPO for intrusion detection in IIoT","author":"Lu","year":"2025","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0008","article-title":"BPSO-AHDL-IDS: binary particle swarm optimization-based automated hybrid deep learning model for intrusion detection of internet of things","author":"Lu","year":"2025","journal-title":"IEEE Trans Autom Sci Eng"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0009","doi-asserted-by":"crossref","first-page":"3552","DOI":"10.3390\/math11163552","article-title":"P4-HLDMC: a novel framework for DDoS and ARP attack detection and mitigation in SD-IoT networks using machine learning, stateful P4, and distributed multi-controller architecture","volume":"11","author":"Khedr","year":"2023","journal-title":"Mathematics"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0010","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2025.3535943","article-title":"Comprehensive analysis of ddos anomaly detection in software-defined networks","author":"Hirsi","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0011","doi-asserted-by":"crossref","first-page":"727","DOI":"10.1007\/s10115-024-02219-y","article-title":"ARP spoofing detection using machine learning classifiers: an experimental study","volume":"67","author":"Majumder","year":"2025","journal-title":"Knowl Inf Syst"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0012","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2024.101432","article-title":"LBTMA: an integrated P4-enabled framework for optimized traffic management in SD-IoT networks","volume":"28","author":"El-Sayed","year":"2024","journal-title":"Internet Things"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0013","doi-asserted-by":"crossref","first-page":"2697","DOI":"10.3390\/s22072697","article-title":"Adaptive machine learning based distributed denial-of-services attacks detection and mitigation system for SDN-enabled IoT","volume":"22","author":"Aslam","year":"2022","journal-title":"Sensors"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0014","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2022.105059","article-title":"A feedforward\u2013convolutional neural network to detect low-rate dos in iot","volume":"114","author":"Ilango","year":"2022","journal-title":"Eng Appl Artif Intell"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0015","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2022.108034","article-title":"DDoS attack detection in Internet of Things using recurrent neural network","volume":"101","author":"Yousuf","year":"2022","journal-title":"Comput Electr Eng"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0016","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102604","article-title":"A hybrid method of entropy and SSAE-SVM based DDoS detection and mitigation mechanism in SDN","volume":"115","author":"Long","year":"2022","journal-title":"Comput Secur"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0017","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2024.103916","article-title":"Synchronizing real-time and high-precision LDoS defense of learning model-based in AIoT with programmable data plane, SDN","volume":"229","author":"Ma","year":"2024","journal-title":"J Netw Comput Appl"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0018","doi-asserted-by":"crossref","first-page":"49142","DOI":"10.1109\/ACCESS.2022.3172329","article-title":"D-ARP: an efficient scheme to detect and prevent ARP spoofing","volume":"10","author":"Morsy","year":"2022","journal-title":"IEEE Access"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0019","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2025.3563721","article-title":"Real-time detection and identification of ARP spoofing attacks in microgrids","author":"Katuri","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0020","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2025.3585463","article-title":"A comprehensive approach for detecting and handling MitM-ARP spoofing attacks","author":"Oei","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0021","doi-asserted-by":"crossref","DOI":"10.55524\/ijircst.2024.12.5.7","article-title":"Detecting and preventing arp spoofing attacks using real-time data analysis and machine learning","volume":"12","author":"Kumar","year":"2024","journal-title":"Int J Innov Res Comput Sci Technol"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0022","article-title":"Enhancing security in software-defined networks: an approach to efficient ARP spoofing attacks detection and mitigation","volume":"14","author":"Hnamte","year":"2024","journal-title":"Telemat Inform Rep"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0023","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2025.110226","article-title":"Dynamic multiphase DDoS attack identification and mitigation framework to secure SDN-based fog-empowered consumer IoT networks","volume":"123","author":"Chaudhary","year":"2025","journal-title":"Comput Electr Eng"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0024","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111078","article-title":"DDoSBlocker: enhancing SDN security with time-based address mapping and AI-driven approach","volume":"259","author":"Sinha","year":"2025","journal-title":"Comput Netw"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0025","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2025.110543","article-title":"Deception and cloud integration: a multi-layered approach for DDoS detection, mitigation, and attack surface minimization in SD-IoT networks","volume":"126","author":"El-Sayed","year":"2025","journal-title":"Comput Electr Eng"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0026","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2024.109769","article-title":"A novel DDoS detection method using multi-layer stacking in SDN environment","volume":"120","author":"Alasali","year":"2024","journal-title":"Comput Electr Eng"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0027","series-title":"Combining pattern classifiers: methods and algorithms","author":"Kuncheva","year":"2014"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0028","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1016\/j.inffus.2004.04.004","article-title":"Diversity creation methods: a survey and categorisation","volume":"6","author":"Brown","year":"2005","journal-title":"Inf fusion"},{"key":"10.1016\/j.compeleceng.2025.110929_bib0029","unstructured":"M. Gafar. (2025). DiMCA: distributed Multi-Contextual architecture for Secure SD-IoT. Available: https:\/\/github.com\/Manalamr\/DiMCA."},{"key":"10.1016\/j.compeleceng.2025.110929_bib0030","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1162\/neco.1992.4.1.1","article-title":"Neural networks and the bias\/variance dilemma","volume":"4","author":"Geman","year":"1992","journal-title":"Neural Comput"}],"container-title":["Computers and Electrical Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0045790625008729?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0045790625008729?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,2,18]],"date-time":"2026-02-18T14:08:11Z","timestamp":1771423691000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0045790625008729"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4]]},"references-count":30,"alternative-id":["S0045790625008729"],"URL":"https:\/\/doi.org\/10.1016\/j.compeleceng.2025.110929","relation":{},"ISSN":["0045-7906"],"issn-type":[{"value":"0045-7906","type":"print"}],"subject":[],"published":{"date-parts":[[2026,4]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"DiMCA: A novel P4-powered framework using machine learning for adaptive defense against combined DDoS and ARP spoofing attacks in SD-IoT networks","name":"articletitle","label":"Article Title"},{"value":"Computers and Electrical Engineering","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.compeleceng.2025.110929","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"110929"}}