{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T00:45:04Z","timestamp":1777682704075,"version":"3.51.4"},"reference-count":27,"publisher":"SAGE Publications","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JHS"],"published-print":{"date-parts":[[2015,11,25]]},"DOI":"10.3233\/jhs-150526","type":"journal-article","created":{"date-parts":[[2015,11,27]],"date-time":"2015-11-27T08:37:18Z","timestamp":1448613438000},"page":"285-298","source":"Crossref","is-referenced-by-count":5,"title":["Defending DDoS attacks in software defined networking based on improved Shiryaev\u2013Roberts detection algorithm"],"prefix":"10.1177","volume":"21","author":[{"given":"Wang","family":"Xiulei","sequence":"first","affiliation":[{"name":"College of Command Information System, PLA University of Science and Technology, Nanjing, China. E-mails:\u00a0xiuleiwang1988@126.com,\u00a0mingchen@126.com,\u00a0Zhangguomin@126.com"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chen","family":"Ming","sequence":"additional","affiliation":[{"name":"College of Command Information System, PLA University of Science and Technology, Nanjing, China. E-mails:\u00a0xiuleiwang1988@126.com,\u00a0mingchen@126.com,\u00a0Zhangguomin@126.com"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Xianglin","sequence":"additional","affiliation":[{"name":"PLA University of Science and Technology, Nanjing, China. E-mail:\u00a0wei_xianglin@163.com"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhang","family":"Guomin","sequence":"additional","affiliation":[{"name":"College of Command Information System, PLA University of Science and Technology, Nanjing, China. E-mails:\u00a0xiuleiwang1988@126.com,\u00a0mingchen@126.com,\u00a0Zhangguomin@126.com"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","reference":[{"key":"10.3233\/JHS-150526_ref1","doi-asserted-by":"crossref","unstructured":"[1]R.\u00a0Braga, E.\u00a0Mota and A.\u00a0Passito, Lightweight DDoS flooding attack detection using NOX\/OpenFlow, in: Proceedings of the 35th Conference on Local Computer Networks (LCN), IEEE Press, Denver, 2010, pp.\u00a0408\u2013415.","DOI":"10.1109\/LCN.2010.5735752"},{"key":"10.3233\/JHS-150526_ref2","doi-asserted-by":"crossref","unstructured":"[2]M.\u00a0Casado, M.J.\u00a0Freedman, J.\u00a0Pettit, J.\u00a0Luo, N.\u00a0Gude, N.\u00a0Mckeown and S.\u00a0Shenker, Rethinking enterprise network control, in: IEEE\/ACM Transactions on Networking 17.4, 2009.","DOI":"10.1109\/TNET.2009.2026415"},{"key":"10.3233\/JHS-150526_ref3","doi-asserted-by":"crossref","unstructured":"[3]M.\u00a0Ghobadi, S.H.\u00a0Yeganeh and Y.\u00a0Ganjali, Rethinking end-to-end congestion control in software-defined networks, in: Hotnets\u201912, Seattle, WA, USA, 19\u201330 October 2012, 2012.","DOI":"10.1145\/2390231.2390242"},{"key":"10.3233\/JHS-150526_ref4","unstructured":"[4]N.\u00a0Handigol, S.\u00a0Seetharaman, M.\u00a0Flajslik, N.\u00a0Mckeown and R.\u00a0Johari, Plug-n-Serve: Load-balancing web traffic using OpenFlow, in: Proceedings of the SIGCOMM 2009 (Demo), ACM Press, Barcelona, 2009."},{"key":"10.3233\/JHS-150526_ref5","doi-asserted-by":"crossref","unstructured":"[5]V.\u00a0Jacobson, D.K.\u00a0Smetters, J.D.\u00a0Thornton, M.F.\u00a0Plass, N.H.\u00a0Briggs and R.L.\u00a0Braynard, Networking named content, in: CoNext, Rome, Italy, 2009.","DOI":"10.1145\/1658939.1658941"},{"key":"10.3233\/JHS-150526_ref6","doi-asserted-by":"crossref","unstructured":"[6]S.\u00a0Jain, A.\u00a0Kumar, S.\u00a0Mandal, J.\u00a0Ong, L.\u00a0Poutievski, A.\u00a0Singh, S.\u00a0Venkata, J.\u00a0Wanderer, J.\u00a0Zhou, M.\u00a0Zhu, J.\u00a0Zolla, U.\u00a0H\u00f6lzle, S.\u00a0Stuart and A.\u00a0Vahdat, B4: Experience with a global-deployed software define WAN, in: SIGCOMM\u201913, Hong Kong, China, 12\u201316 August 2013, 2013.","DOI":"10.1145\/2486001.2486019"},{"key":"10.3233\/JHS-150526_ref7","doi-asserted-by":"crossref","unstructured":"[7]R.\u00a0Kl\u00f6ti, V.\u00a0Kotronis and P.\u00a0Smith, OpenFlow: Security analysis, in: The 21st IEEE International Conference on Network Protocol, 7\u201310 October 2013, 2013.","DOI":"10.1109\/ICNP.2013.6733671"},{"key":"10.3233\/JHS-150526_ref8","doi-asserted-by":"crossref","unstructured":"[8]D.\u00a0Kreutz, F.M.\u00a0Ramos and P.\u00a0Verissimo, Towards secure and dependable software-defined networks, in: HotSDN\u201913, Hong Kong, China, 16 August 2013, 2013.","DOI":"10.1145\/2491185.2491199"},{"key":"10.3233\/JHS-150526_ref9","doi-asserted-by":"crossref","unstructured":"[9]J.\u00a0Li, S.\u00a0Berg, M.\u00a0Zhang, P.\u00a0Reiher and T.\u00a0Wei, DrawBridge \u2013 Software-defined DDoS resistant traffic engineering, in: SIGCOM\u201914, Chicago, IL, USA, 17\u201322 August 2014, 2014.","DOI":"10.1145\/2619239.2631469"},{"key":"10.3233\/JHS-150526_ref10","doi-asserted-by":"crossref","unstructured":"[10]S.\u00a0Lim, J.\u00a0Ha, H.\u00a0Kim, Y.\u00a0Kim and S.\u00a0Yang, A SDN-oriented DDoS blocking scheme for botnet-based attacks, in: ICUFN, 2014.","DOI":"10.1109\/ICUFN.2014.6876752"},{"issue":"6","key":"10.3233\/JHS-150526_ref11","doi-asserted-by":"crossref","first-page":"1897","DOI":"10.1214\/aoms\/1177693055","article-title":"Procedures for reacting to a change in distribution","volume":"42","author":"Lorden","year":"1971","journal-title":"Annals of Mathematical Statistics"},{"issue":"2","key":"10.3233\/JHS-150526_ref13","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1145\/1355734.1355746","article-title":"OpenFlow: Enabling innovation in campus networks","volume":"38","author":"McKeown","year":"2008","journal-title":"ACM SIGOCMM Computer Communication Review"},{"key":"10.3233\/JHS-150526_ref14","doi-asserted-by":"crossref","unstructured":"[14]S.A.\u00a0Mehdi, J.\u00a0Khalid and S.A.\u00a0Khayam, Rethinking traffic anomaly detection using software defined networking, in: Recent Advance in Intrusion Detection, Lecture Notes in Computer Science, Vol.\u00a06961, 2011, pp.\u00a0161\u2013180.","DOI":"10.1007\/978-3-642-23644-0_9"},{"key":"10.3233\/JHS-150526_ref16","doi-asserted-by":"crossref","unstructured":"[16]V.M.\u00a0Morgenstern, B.R.\u00a0Upadhyaya and M.\u00a0Benedetti, Signal anomaly detection using modified CUSUM method, in: Proceedings of the 27th IEEE Conference on Decision and Control, 1988, pp.\u00a02340\u20132341.","DOI":"10.1109\/CDC.1988.194756"},{"key":"10.3233\/JHS-150526_ref20","doi-asserted-by":"crossref","unstructured":"[20]F.\u00a0Palmieri, VPN scalability over high performance backbones evaluating MPLS VPN against traditional approaches, in: Proceedings of the IEEE Symposium on Computers and Communications, 2003, pp.\u00a0975\u2013981.","DOI":"10.1109\/ISCC.2003.1214243"},{"issue":"7","key":"10.3233\/JHS-150526_ref21","doi-asserted-by":"crossref","first-page":"737","DOI":"10.1016\/j.cose.2010.05.002","article-title":"Network anomaly detection through nonlinear analysis","volume":"29","author":"Palmieri","year":"2010","journal-title":"Computers and Security"},{"issue":"1","key":"10.3233\/JHS-150526_ref22","doi-asserted-by":"crossref","first-page":"206","DOI":"10.1214\/aos\/1176346587","article-title":"Optimal detection of a change in distribution","volume":"3","author":"Pollak","year":"1985","journal-title":"The Annals of Statistics"},{"issue":"2","key":"10.3233\/JHS-150526_ref23","doi-asserted-by":"crossref","first-page":"749","DOI":"10.1214\/aos\/1176350373","article-title":"Average run lengths of an optimal method of detecting a change in distribution","volume":"5","author":"Pollak","year":"1987","journal-title":"The Annals of Statistics"},{"key":"10.3233\/JHS-150526_ref24","first-page":"1729","article-title":"Optimality properties of the Shiryaev\u2013Roberts procedure","volume":"19","author":"Pollak","year":"2009","journal-title":"Statistica Sinica"},{"issue":"3","key":"10.3233\/JHS-150526_ref25","doi-asserted-by":"crossref","first-page":"411","DOI":"10.1080\/00401706.1966.10490374","article-title":"A comparison of some control chart procedures","volume":"8","author":"Robert","year":"1966","journal-title":"Technometrics"},{"key":"10.3233\/JHS-150526_ref26","doi-asserted-by":"crossref","unstructured":"[26]S.\u00a0Shin and G.\u00a0Gu, Attacking software-defined networks: A first feasibility study, in: HotSDN\u201913, 2013, pp.\u00a0165\u2013166.","DOI":"10.1145\/2491185.2491220"},{"key":"10.3233\/JHS-150526_ref27","first-page":"795","article-title":"The problem of the most rapid detection of a distribution in a stationary process","volume":"2","author":"Shiryaev","year":"1961","journal-title":"Soviet Math. Dokl."},{"issue":"1","key":"10.3233\/JHS-150526_ref28","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1109\/JSTSP.2012.2233713","article-title":"Efficient computer network anomaly detection by changepoint detection methods","volume":"7","author":"Tartakovsky","year":"2013","journal-title":"IEEE Journal of Selected Topics in Signal Processing"},{"key":"10.3233\/JHS-150526_ref29","unstructured":"[29]A.G.\u00a0Tartakovsky, B.L.\u00a0Rozovskii and K.\u00a0Shah, A nonparametric multichart CUSUM test for rapid intrusion detection, in: Proceedings of the 2005 Joint Statistical Meetings, Minneapolis, MN, August 2005, 2005."},{"issue":"2","key":"10.3233\/JHS-150526_ref31","doi-asserted-by":"crossref","first-page":"512","DOI":"10.1109\/TNET.2010.2070845","article-title":"Parametric methods for anomaly detection in aggregate traffic","volume":"19","author":"Thatte","year":"2011","journal-title":"IEEE\/ACM Transactions on Networking"},{"issue":"11","key":"10.3233\/JHS-150526_ref33","doi-asserted-by":"crossref","first-page":"5102","DOI":"10.1109\/TIT.2008.929964","article-title":"Optimality of CUSUM rule approximations in change-point detection problems: Application to nonlinear state-space systems","volume":"54","author":"Verdier","year":"2008","journal-title":"IEEE Transactions on Information Theory"},{"issue":"4","key":"10.3233\/JHS-150526_ref34","doi-asserted-by":"crossref","first-page":"557","DOI":"10.1109\/TR.2004.837705","article-title":"EWMA forecast of normal system activity for computer intrusion detection","volume":"53","author":"Ye","year":"2004","journal-title":"IEEE Transactions on Reliability"}],"container-title":["Journal of High Speed Networks"],"original-title":[],"link":[{"URL":"https:\/\/content.iospress.com\/download?id=10.3233\/JHS-150526","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T08:43:50Z","timestamp":1777452230000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/full\/10.3233\/JHS-150526"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,11,25]]},"references-count":27,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.3233\/jhs-150526","relation":{},"ISSN":["1875-8940","0926-6801"],"issn-type":[{"value":"1875-8940","type":"electronic"},{"value":"0926-6801","type":"print"}],"subject":[],"published":{"date-parts":[[2015,11,25]]}}}