{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T20:33:07Z","timestamp":1782937987307,"version":"3.54.5"},"reference-count":44,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62171291"],"award-info":[{"award-number":["62171291"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.eswa.2026.132179","type":"journal-article","created":{"date-parts":[[2026,3,22]],"date-time":"2026-03-22T15:50:50Z","timestamp":1774194650000},"page":"132179","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":1,"special_numbering":"C","title":["Proactive DDoS detection and mitigation in decentralized Software-Defined Networking via Port-Level monitoring and Zero-Training large language models"],"prefix":"10.1016","volume":"319","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-7888-0836","authenticated-orcid":false,"given":"Mohammed N.","family":"Swileh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7937-5870","authenticated-orcid":false,"given":"Shengli","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"2","key":"10.1016\/j.eswa.2026.132179_b0005","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/MCOM.2013.6461195","article-title":"Improving network management with software defined networking","volume":"51","author":"Kim","year":"2013","journal-title":"IEEE Communications magazine"},{"key":"10.1016\/j.eswa.2026.132179_b0010","doi-asserted-by":"crossref","first-page":"89","DOI":"10.1016\/j.jnca.2019.01.019","article-title":"The application of Software Defined Networking on securing computer networks: A survey","volume":"131","author":"Sahay","year":"2019","journal-title":"Journal of Network and Computer Applications"},{"key":"10.1016\/j.eswa.2026.132179_b0015","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2022.107706","article-title":"A survey on DoS\/DDoS mitigation techniques in SDNs: Classification, comparison, solutions, testing tools and datasets","volume":"99","author":"Alhijawi","year":"2022","journal-title":"Computers and Electrical Engineering"},{"issue":"1","key":"10.1016\/j.eswa.2026.132179_b0020","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1007\/s10922-020-09575-4","article-title":"Scalability, consistency, reliability and security in SDN controllers: A survey of diverse SDN controllers","volume":"29","author":"Ahmad","year":"2021","journal-title":"Journal of Network and Systems Management"},{"key":"10.1016\/j.eswa.2026.132179_b0025","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1016\/j.jnca.2017.03.004","article-title":"Multi-domain Software Defined Networking: Research status and challenges","volume":"87","author":"Wibowo","year":"2017","journal-title":"Journal of Network and Computer Applications"},{"key":"10.1016\/j.eswa.2026.132179_b0030","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103351","article-title":"ITC: Intrusion tolerant controller for multicontroller SDN architecture","volume":"132","author":"Sanoussi","year":"2023","journal-title":"Computers & Security"},{"issue":"3","key":"10.1016\/j.eswa.2026.132179_b0035","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3190617","article-title":"A taxonomy of software-defined networking (SDN)-enabled cloud computing","volume":"51","author":"Son","year":"2018","journal-title":"ACM computing surveys (CSUR)"},{"key":"10.1016\/j.eswa.2026.132179_b0040","doi-asserted-by":"crossref","DOI":"10.1016\/j.cosrev.2020.100279","article-title":"Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions","volume":"37","author":"Singh","year":"2020","journal-title":"Computer Science Review"},{"issue":"1","key":"10.1016\/j.eswa.2026.132179_b0045","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/JPROC.2014.2371999","article-title":"Software-defined networking: A comprehensive survey","volume":"103","author":"Kreutz","year":"2014","journal-title":"Proceedings of the IEEE"},{"key":"10.1016\/j.eswa.2026.132179_b0050","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103652","article-title":"DDOS attack detection in SDN: Method of attacks, detection techniques, challenges and research gaps","volume":"139","author":"Wabi","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132179_b0055","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2024.104043","article-title":"Controller load optimization strategies in software-defined networking: A survey","volume":"233","author":"Liu","year":"2025","journal-title":"Journal of Network and Computer Applications"},{"key":"10.1016\/j.eswa.2026.132179_b0060","doi-asserted-by":"crossref","first-page":"279","DOI":"10.1016\/j.comnet.2016.11.017","article-title":"A survey: Control plane scalability issues and approaches in software-defined networking (SDN)","volume":"112","author":"Karakus","year":"2017","journal-title":"Computer Networks"},{"issue":"12","key":"10.1016\/j.eswa.2026.132179_b0065","doi-asserted-by":"crossref","first-page":"5875","DOI":"10.1007\/s12652-020-02099-4","article-title":"MitM detection and defense mechanism CBNA-RF based on machine learning for large-scale SDN context","volume":"11","author":"Sebbar","year":"2020","journal-title":"Journal of Ambient Intelligence and Humanized Computing"},{"key":"10.1016\/j.eswa.2026.132179_b0070","series-title":"In Proceedings of the ACM SIGCOMM 2024 Conference","first-page":"938","article-title":"August). a decentralized sdn architecture for the wan","author":"Krentsel","year":"2024"},{"issue":"9","key":"10.1016\/j.eswa.2026.132179_b0075","doi-asserted-by":"crossref","first-page":"4441","DOI":"10.3390\/s23094441","article-title":"A systematic literature review on machine learning and deep learning approaches for detecting DDoS attacks in software-defined networking","volume":"23","author":"Bahashwan","year":"2023","journal-title":"Sensors"},{"issue":"5","key":"10.1016\/j.eswa.2026.132179_b0080","doi-asserted-by":"crossref","first-page":"3183","DOI":"10.3390\/app13053183","article-title":"Machine learning techniques to detect a DDoS attack in SDN: A systematic review","volume":"13","author":"Ali","year":"2023","journal-title":"Applied Sciences"},{"issue":"7","key":"10.1016\/j.eswa.2026.132179_b0085","doi-asserted-by":"crossref","first-page":"154","DOI":"10.3390\/ai6070154","article-title":"Unseen Attack Detection in Software-Defined Networking using a BERT-Based Large Language Model","volume":"6","author":"Swileh","year":"2025","journal-title":"AI"},{"key":"10.1016\/j.eswa.2026.132179_b0090","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103716","article-title":"Cyber-secure SDN: A CNN-based approach for efficient detection and mitigation of DDoS attacks","volume":"139","author":"Najar","year":"2024","journal-title":"Computers & Security"},{"issue":"1","key":"10.1016\/j.eswa.2026.132179_b0095","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1186\/s13677-024-00625-9","article-title":"An integrated SDN framework for early detection of DDoS attacks in cloud computing","volume":"13","author":"Songa","year":"2024","journal-title":"Journal of Cloud Computing"},{"key":"10.1016\/j.eswa.2026.132179_b0100","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103661","article-title":"DDoS attack detection and mitigation using deep neural network in SDN environment","volume":"138","author":"Hnamte","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132179_b0105","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103588","article-title":"A deep learning technique to detect distributed denial of service attacks in software-defined networks","volume":"137","author":"Gadallah","year":"2024","journal-title":"Computers & Security"},{"issue":"10","key":"10.1016\/j.eswa.2026.132179_b0110","doi-asserted-by":"crossref","first-page":"8491","DOI":"10.1109\/JIOT.2022.3196942","article-title":"An efficient hybrid-dnn for ddos detection and classification in software-defined iiot networks","volume":"10","author":"Zainudin","year":"2022","journal-title":"IEEE Internet of Things Journal"},{"issue":"4","key":"10.1016\/j.eswa.2026.132179_b0115","doi-asserted-by":"crossref","first-page":"4268","DOI":"10.1007\/s10489-022-03565-6","article-title":"A framework to detect DDoS attack in Ryu controller based software defined networks using feature extraction and classification","volume":"53","author":"Chouhan","year":"2023","journal-title":"Applied Intelligence"},{"key":"10.1016\/j.eswa.2026.132179_b0120","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2021.103108","article-title":"Automated DDOS attack detection in software defined networking","volume":"187","author":"Ahuja","year":"2021","journal-title":"Journal of Network and Computer Applications"},{"issue":"3","key":"10.1016\/j.eswa.2026.132179_b0125","doi-asserted-by":"crossref","first-page":"1035","DOI":"10.3390\/su12031035","article-title":"Detecting DDoS attacks in software-defined networks through feature selection methods and machine learning models","volume":"12","author":"Polat","year":"2020","journal-title":"Sustainability"},{"issue":"1","key":"10.1016\/j.eswa.2026.132179_b0130","article-title":"A DDoS attack detection method based on SVM in software defined network","volume":"2018","author":"Ye","year":"2018","journal-title":"Security and communication networks"},{"issue":"3","key":"10.1016\/j.eswa.2026.132179_b0135","doi-asserted-by":"crossref","first-page":"1040","DOI":"10.3390\/s24031040","article-title":"Multi-stage learning framework using convolutional neural network and decision tree-based classification for detection of DDoS pandemic attacks in SDN-based SCADA systems","volume":"24","author":"Polat","year":"2024","journal-title":"Sensors"},{"key":"10.1016\/j.eswa.2026.132179_b0140","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2020.114520","article-title":"Detection of DDoS attacks with feed forward based deep neural network model","volume":"169","author":"Cil","year":"2021","journal-title":"Expert Systems with Applications"},{"issue":"1","key":"10.1016\/j.eswa.2026.132179_b0145","article-title":"Advanced support vector machine\u2010(ASVM\u2010) based detection for distributed denial of service (DDoS) attack on software defined networking (SDN)","volume":"2019","author":"Myint Oo","year":"2019","journal-title":"Journal of Computer Networks and Communications"},{"key":"10.1016\/j.eswa.2026.132179_b0150","article-title":"Federated learning based DDoS attacks detection in large scale software-defined network","author":"Fotse","year":"2024","journal-title":"IEEE Transactions on Computers"},{"key":"10.1016\/j.eswa.2026.132179_b0155","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110251","article-title":"Multi-domain collaborative two-level DDoS detection via hybrid deep learning","volume":"242","author":"Feng","year":"2024","journal-title":"Computer Networks"},{"key":"10.1016\/j.eswa.2026.132179_b0160","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.109642","article-title":"Collaborative prediction and detection of DDoS attacks in edge computing: A deep learning-based approach with distributed SDN","volume":"225","author":"Zhou","year":"2023","journal-title":"Computer Networks"},{"key":"10.1016\/j.eswa.2026.132179_b0165","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.117500","article-title":"Recognition of DDoS attacks on SD-VANET based on combination of hyperparameter optimization and feature selection","volume":"203","author":"T\u00fcrko\u011flu","year":"2022","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132179_b0170","series-title":"In 2025 21th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob)","first-page":"1","article-title":"October). Lightweight Fine-Tuning of LLMS for Explainable Intrusion Detection in SDN","author":"Lodh","year":"2025"},{"key":"10.1016\/j.eswa.2026.132179_b0175","series-title":"October). Application of large language models to ddos attack detection","first-page":"83","author":"Guastalla","year":"2023"},{"issue":"1","key":"10.1016\/j.eswa.2026.132179_b0180","doi-asserted-by":"crossref","first-page":"623","DOI":"10.1109\/COMST.2015.2453114","article-title":"A survey of security in software defined networks","volume":"18","author":"Scott-Hayward","year":"2015","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"10.1016\/j.eswa.2026.132179_b0185","unstructured":"Dong, Q., Li, L., Dai, D., Zheng, C., Ma, J., Li, R., ... & Sui, Z. (2022). A survey on in-context learning. arXiv preprint arXiv:2301.00234. doi:10.48550\/arXiv.2301.00234."},{"key":"10.1016\/j.eswa.2026.132179_b0190","unstructured":"Liu, A., Feng, B., Xue, B., Wang, B., Wu, B., Lu, C., ... & Piao, Y. (2024). Deepseek-v3 technical report. arXiv preprint arXiv:2412.19437. doi:10.48550\/arXiv.2412.19437."},{"key":"10.1016\/j.eswa.2026.132179_b0195","unstructured":"Team, G., Kamath, A., Ferret, J., Pathak, S., Vieillard, N., Merhej, R., ... & Iqbal, S. (2025). Gemma 3 technical report. arXiv preprint arXiv:2503.19786. doi:10.48550\/arXiv.2503.19786."},{"key":"10.1016\/j.eswa.2026.132179_b0200","unstructured":"Yang, A., Yang, B., Hui, B., Zheng, B., Yu, B., Zhou, C., Li, C., Li, C., Liu, D., Huang, F., Dong, G., Wei, H., Lin, H., Tang, J., Wang, J., Yang, J., Tu, J., Zhang, J., Ma, J., . . . Fan, Z. (2024). QWEN2 Technical Report. arXiv preprint arxiv.2407.10671. doi:10.48550\/arxiv.2407.10671."},{"key":"10.1016\/j.eswa.2026.132179_b0205","unstructured":"Bai, J., Bai, S., Chu, Y., Cui, Z., Dang, K., Deng, X., ... & Zhu, T. (2023). Qwen technical report. arXiv preprint arXiv:2309.16609. doi:10.48550\/arXiv.2309.16609."},{"key":"10.1016\/j.eswa.2026.132179_b0210","unstructured":"A.Q. Jiang A. Sablayrolles A. Mensch C. Bamford D.S. Chaplot D. De Las Casas F. Bressand G. Lengyel G. Lample L. Saulnier L.R. Lavaud M. Lachaux P. Stock T.L. Scao T. Lavril T. Wang T. Lacroix W.E. Sayed Mistral 7B. arxiv.2310.06825 2023 doi:10.48550\/arxiv.2310.06825."},{"key":"10.1016\/j.eswa.2026.132179_b0215","unstructured":"H. Touvron T. Lavril G. Izacard X. Martinet M.A. Lachaux T. Lacroix G. Lample Llama: Open and efficient foundation language models. arXiv preprint 2023 10.48550\/arXiv.2302.13971 arXiv:2302.13971."},{"key":"10.1016\/j.eswa.2026.132179_b0220","unstructured":"Abdin, M., Aneja, J., Behl, H., Bubeck, S., Eldan, R., Gunasekar, S., ... & Zhang, Y. (2024). Phi-4 technical report. arXiv preprint arXiv:2412.08905. doi:10.48550\/arXiv.2412.08905."}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426010924?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426010924?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T02:51:36Z","timestamp":1780973496000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426010924"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":44,"alternative-id":["S0957417426010924"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132179","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Proactive DDoS detection and mitigation in decentralized Software-Defined Networking via Port-Level monitoring and Zero-Training large language models","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132179","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"132179"}}