{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T00:05:26Z","timestamp":1766275526550,"version":"3.48.0"},"reference-count":24,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T00:00:00Z","timestamp":1766275200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T00:00:00Z","timestamp":1766275200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFB3107605"],"award-info":[{"award-number":["2023YFB3107605"]}]},{"name":"Major Key Project of PCL","award":["PCL2023A05"],"award-info":[{"award-number":["PCL2023A05"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>In cloud-edge collaboration scenarios, attackers pose significant security risks by compromising computational nodes and using them to infiltrate other nodes and networks. Ensuring the security of cloud-edge collaboration is crucial for protecting sensitive data, preventing disruptions to critical services, and safeguarding infrastructure in increasingly interconnected and digitized societies. Traditional passive defense mechanisms are often inadequate in dealing with the complex and dynamic nature of modern network threats. In recent years, Moving Target Defense (MTD) has become an important research direction, disrupting adversaries\u2019 reconnaissance and exploitation phases by dynamically shuffling the attack surface. However, existing MTD strategies have some shortcomings, such as single-dimensional movement strategies, poor flexibility and a lack of historical information analysis. To overcome these challenges, we propose a reinforcement learning-based approach for host address and port hopping (RLAPH). First, the approach strengthens system security through coordinated decision-making across IP address and port, leveraging both historical data and current information to make accurate and adaptive decisions. Second, a reward function is carefully designed to balance the trade-off between system overhead and security. Finally, validation experiments conducted in a simulated environment show that the proposed method effectively enhances defense performance while minimizing system overhead, highlighting its robustness and applicability.<\/jats:p>","DOI":"10.1186\/s42400-025-00392-3","type":"journal-article","created":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T00:02:13Z","timestamp":1766275333000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Rlaph: a lightweight and dynamic proactive defense method in cloud-edge collaboration"],"prefix":"10.1186","volume":"8","author":[{"given":"Yingbo","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4456-7987","authenticated-orcid":false,"given":"Jie","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Faqun","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Qian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinghai","family":"Wei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoyong","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,12,21]]},"reference":[{"issue":"4","key":"392_CR1","doi-asserted-by":"publisher","first-page":"1098","DOI":"10.1109\/TNSM.2017.2724239","volume":"14","author":"S Achleitner","year":"2017","unstructured":"Achleitner S, La Porta TF, McDaniel P, Sugrim S, Krishnamurthy SV, Chadha R (2017) Deceiving network reconnaissance using sdn-based virtual topologies. IEEE Trans Netw Serv Manag 14(4):1098\u20131112","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"392_CR2","doi-asserted-by":"publisher","first-page":"26","DOI":"10.4236\/jcc.2024.122003","volume":"12","author":"S Ahmadi","year":"2024","unstructured":"Ahmadi S (2024) Security implications of edge computing in cloud networks. J Comput Commun 12:26\u201346","journal-title":"J Comput Commun"},{"issue":"3","key":"392_CR3","doi-asserted-by":"publisher","first-page":"41","DOI":"10.3390\/computers11030041","volume":"11","author":"H Alavizadeh","year":"2022","unstructured":"Alavizadeh H, Alavizadeh H, Jang-Jaccard J (2022) Deep q-learning based reinforcement learning approach for network intrusion detection. Computers 11(3):41","journal-title":"Computers"},{"key":"392_CR4","doi-asserted-by":"crossref","unstructured":"Bartock M, Cichonski J, Souppaya M, Witte G, Scarfone K (2016) Guide for cybersecurity event recovery","DOI":"10.6028\/NIST.SP.800-184"},{"key":"392_CR5","unstructured":"Brockman G (2016) Openai gym. arXiv preprint arXiv:1606.01540"},{"issue":"13","key":"392_CR6","doi-asserted-by":"publisher","first-page":"1471","DOI":"10.1016\/j.comcom.2013.05.005","volume":"36","author":"LM Chen","year":"2013","unstructured":"Chen LM, Chen MC, Liao W, Sun YS (2013) A scalable network forensics mechanism for stealthy self-propagating attacks. Comput Commun 36(13):1471\u20131484","journal-title":"Comput Commun"},{"key":"392_CR7","doi-asserted-by":"crossref","unstructured":"Dang F, Wu K, Li S, Liu H, Song Y, Zhang X (2023) Dynamic moving target defense strategy based on adaptive port hopping in sdn. In: international conference on computer network security and software engineering (CNSSE 2023), vol. 12714, pp. 464\u2013479. SPIE","DOI":"10.1117\/12.2683442"},{"issue":"3","key":"392_CR8","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/s10922-023-09746-z","volume":"31","author":"FS Dantas Silva","year":"2023","unstructured":"Dantas Silva FS, Neto EP, Nunes RS, Souza CH, Neto AJ, Pascoal T (2023) Securing software-defined networks through adaptive moving target defense capabilities. J Netw Syst Manag 31(3):61","journal-title":"J Netw Syst Manag"},{"issue":"9","key":"392_CR9","doi-asserted-by":"publisher","first-page":"7366","DOI":"10.1016\/j.jksuci.2022.03.013","volume":"34","author":"BB Elallid","year":"2022","unstructured":"Elallid BB, Benamar N, Hafid AS, Rachidi T, Mrani N (2022) A comprehensive survey on the application of deep and reinforcement learning approaches in autonomous driving. J King Saud Univ-Comput Inf Sci 34(9):7366\u20137390","journal-title":"J King Saud Univ-Comput Inf Sci"},{"key":"392_CR10","doi-asserted-by":"crossref","unstructured":"Khan MJ, Ahmed SH, Sukthankar G (2022) Transformer-based value function decomposition for cooperative multi-agent reinforcement learning in starcraft. In: proceedings of the AAAI conference on artificial intelligence and interactive digital entertainment, vol. 18, pp. 113\u2013119","DOI":"10.1609\/aiide.v18i1.21954"},{"key":"392_CR11","doi-asserted-by":"crossref","unstructured":"Leng S, Guo Y, Zhang L, Hao F, Cao X, Li F, Kou W (2024) Online and collaboratively mitigating multi-vector ddos attacks for cloud-edge computing. In: ICC 2024-IEEE international conference on communications, pp. 1394\u20131399. IEEE","DOI":"10.1109\/ICC51166.2024.10623052"},{"key":"392_CR12","doi-asserted-by":"crossref","unstructured":"Liu R (2023) Nmap network scan performance optimisation. In: fourth international conference on signal processing and computer science (SPCS 2023), vol. 12970, pp. 835\u2013839. SPIE","DOI":"10.1117\/12.3012568"},{"key":"392_CR13","first-page":"24401","volume":"36","author":"G Liu","year":"2023","unstructured":"Liu G, Lai L (2023) Efficient adversarial attacks on online multi-agent reinforcement learning. Adv Neural Inf Process Syst 36:24401\u201324433","journal-title":"Adv Neural Inf Process Syst"},{"key":"392_CR14","unstructured":"Paszke A, Gross S, Massa F, Lerer A, Bradbury J, Chanan G, Killeen T, Lin Z, Gimelshein N, Antiga L et al (2019) Pytorch: An imperative style, high-performance deep learning library. Adv Neural Inf Process Syst 32"},{"key":"392_CR15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103462","volume":"134","author":"MA Ribeiro","year":"2023","unstructured":"Ribeiro MA, Fonseca MSP, Santi J (2023) Detecting and mitigating ddos attacks with moving target defense approach based on automated flow classification in sdn networks. Comput & Secur 134:103462","journal-title":"Comput & Secur"},{"key":"392_CR16","unstructured":"Schulman J, Moritz P, Levine S, Jordan M, Abbeel P (2015) High-dimensional continuous control using generalized advantage estimation. arXiv preprint arXiv:1506.02438"},{"key":"392_CR17","doi-asserted-by":"crossref","unstructured":"Sharma DP, Kim DS, Yoon S, Lim H, Cho J-H, Moore TJ (2018) Frvm: Flexible random virtual ip multiplexing in software-defined networks. In: 2018 17th IEEE international conference on trust, security and privacy in computing and communications\/12th IEEE international conference on big data science and engineering (TrustCom\/BigDataSE), pp. 579\u2013587. IEEE","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00088"},{"key":"392_CR18","doi-asserted-by":"crossref","unstructured":"Shi F, Zhou Z, Yang W, Li S, Liu Q, Bao X (2023) Ahip: an adaptive ip hopping method for moving target defense to thwart network attacks. In: 2023 26th international conference on computer supported cooperative work in design (CSCWD), pp. 1300\u20131305. IEEE","DOI":"10.1109\/CSCWD57460.2023.10152746"},{"issue":"9","key":"392_CR19","doi-asserted-by":"publisher","first-page":"5367","DOI":"10.3390\/app13095367","volume":"13","author":"R Sun","year":"2023","unstructured":"Sun R, Zhu Y, Fei J, Chen X (2023) A survey on moving target defense: intelligently affordable, optimized and self-adaptive. Appl Sci 13(9):5367","journal-title":"Appl Sci"},{"key":"392_CR20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101742","volume":"92","author":"M Torquato","year":"2020","unstructured":"Torquato M, Vieira M (2020) Moving target defense in cloud computing: a systematic mapping study. Comput & Secur 92:101742","journal-title":"Comput & Secur"},{"issue":"6","key":"392_CR21","first-page":"44","volume":"7","author":"H Weizhen","year":"2021","unstructured":"Weizhen H, Fucai C, Jie N, Jinglei T, Shumin H, Guozhen C (2021) Research progress on dynamic hopping technology for network layer. Chin J Netw & Inf Secur 7(6):44","journal-title":"Chin J Netw & Inf Secur"},{"key":"392_CR22","doi-asserted-by":"publisher","first-page":"70700","DOI":"10.1109\/ACCESS.2021.3076599","volume":"9","author":"S Yoon","year":"2021","unstructured":"Yoon S, Cho J-H, Kim DS, Moore TJ, Free-Nelson F, Lim H (2021) Desolater: deep reinforcement learning-based resource allocation and moving target defense deployment framework. IEEE Access 9:70700\u201370714","journal-title":"IEEE Access"},{"key":"392_CR23","doi-asserted-by":"crossref","unstructured":"Zhang T, Xu C, Shen J, Kuang X, Grieco LA (2023) How to disturb network reconnaissance: a moving target defense approach based on deep reinforcement learning. IEEE transactions on information forensics and security","DOI":"10.1109\/TIFS.2023.3314219"},{"key":"392_CR24","unstructured":"Zha D, Xie J, Ma W, Zhang S, Lian X, Hu X, Liu J (2021) Douzero: mastering doudizhu with self-play deep reinforcement learning. In: international conference on machine learning, pp. 12333\u201312344. PMLR"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00392-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00392-3","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00392-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T00:02:17Z","timestamp":1766275337000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00392-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,21]]},"references-count":24,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["392"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00392-3","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,21]]},"assertion":[{"value":"11 December 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 March 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 December 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"All authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"94"}}