{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:11:22Z","timestamp":1760242282593,"version":"build-2065373602"},"reference-count":38,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2017,3,9]],"date-time":"2017-03-09T00:00:00Z","timestamp":1489017600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>With the rapid development of virtual machine technology and cloud computing, distributed denial of service (DDoS) attacks, or some peak traffic, poses a great threat to the security of the network. In this paper, a novel topology link control technique and mitigation attacks in real-time environments is proposed. Firstly, a non-invasive method of deploying virtual sensors in the nodes is built, which uses the resource manager of each monitored node as a sensor. Secondly, a general topology-controlling approach of resisting the tolerant invasion is proposed. In the proposed approach, a prediction model is constructed by using copula functions for predicting the peak of a resource through another resource. The result of prediction determines whether or not to initiate the active defense. Finally, a minority game with incomplete strategy is employed to suppress attack flows and improve the permeability of the normal flows. The simulation results show that the proposed approach is very effective in protecting nodes.<\/jats:p>","DOI":"10.3390\/s17030553","type":"journal-article","created":{"date-parts":[[2017,3,9]],"date-time":"2017-03-09T11:12:17Z","timestamp":1489057937000},"page":"553","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["A Novel Topology Link-Controlling Approach for Active Defense of Nodes in Networks"],"prefix":"10.3390","volume":"17","author":[{"given":"Jun","family":"Li","sequence":"first","affiliation":[{"name":"School of Automation, Huazhong University of Science and Technology, Wuhan 430070, China"},{"name":"Department of Computer Science, Hubei University of Technology, Wuhan 430070, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"HanPing","family":"Hu","sequence":"additional","affiliation":[{"name":"School of Automation, Huazhong University of Science and Technology, Wuhan 430070, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiao","family":"Ke","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, University of North Texas, Denton, TX 76203, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Naixue","family":"Xiong","sequence":"additional","affiliation":[{"name":"Department of Mathematics and Computer Science, Northeastern State University, Tahlequah, OK 74464, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2017,3,9]]},"reference":[{"key":"ref_1","unstructured":"CDNetworks 2015 DDoS Attack Trends and Outlook for 2016. Available online: http:\/\/www.cdnetworks.com.sg\/cdnetworks-publishes-2015-ddos-attack-trends-and-outlook-for-2016\/."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1659","DOI":"10.1016\/j.eswa.2007.01.040","article-title":"DDoS attack detection method using cluster analysis","volume":"34","author":"Lee","year":"2008","journal-title":"Expert Syst. Appl."},{"key":"ref_3","first-page":"8","article-title":"A comprehensive approach to discriminate DDoS attacks from flash events","volume":"26","author":"Sachdeva","year":"2016","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/S1353-4858(12)70075-2","article-title":"Simple ways to dodge the DDoS bullet","volume":"8","author":"Malecki","year":"2012","journal-title":"Netw. Secur."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"3417","DOI":"10.1016\/j.comnet.2012.07.003","article-title":"Flow level detection and filtering of low-rate DDoS","volume":"56","author":"Zhang","year":"2012","journal-title":"Comput. Netw."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"95","DOI":"10.1016\/j.pisc.2015.11.016","article-title":"Whispering through DDoS attack","volume":"7","author":"Mehic","year":"2016","journal-title":"Perspect. Sci."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"782","DOI":"10.1016\/j.cose.2012.06.002","article-title":"Real time DDoS detection using fuzzy estimators","volume":"31","author":"Shiaeles","year":"2012","journal-title":"Comput. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"501","DOI":"10.1016\/j.camwa.2011.08.020","article-title":"Detection of DDoS attacks using optimized traffic matrix","volume":"63","author":"Lee","year":"2012","journal-title":"Comput. Math. Appl."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"213","DOI":"10.1016\/j.cose.2005.11.007","article-title":"Change trend of averaged Hurst parameter of traffic under DDOS flood attacks","volume":"25","author":"Li","year":"2006","journal-title":"Comput. Secur."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"9620","DOI":"10.1016\/j.eswa.2015.07.027","article-title":"STONE: A streaming DDoS defense framework","volume":"42","author":"Gulisano","year":"2015","journal-title":"Expert Syst. Appl."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1016\/j.procs.2016.02.012","article-title":"DDOS Attack Aware DSR Routing Protocol in WSN","volume":"78","author":"Upadhyay","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1016\/S1353-4858(15)30092-1","article-title":"The growth and evolution of DDoS","volume":"2015","year":"2015","journal-title":"Netw. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1016\/j.comcom.2012.09.010","article-title":"Detection of distributed denial of service attacks using an ensemble of adaptive and hybrid neuro-fuzzy systems","volume":"36","author":"Selvakumar","year":"2013","journal-title":"Comput. Commun."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.patrec.2014.07.019","article-title":"An empirical evaluation of information metrics for low-rate and high-rate DDoS attack detection","volume":"51","author":"Bhuyan","year":"2015","journal-title":"Pattern Recognit. Lett."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1016\/j.comcom.2015.06.012","article-title":"Detecting DDoS attacks against data center with correlation analysis","volume":"67","author":"Xiao","year":"2015","journal-title":"Comput. Commun."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1016\/j.cose.2014.04.008","article-title":"Uniform DoS traceback","volume":"45","author":"Alenezi","year":"2014","journal-title":"Comput. Secur."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"385","DOI":"10.1016\/j.neucom.2015.04.101","article-title":"Detection of known and unknown DDoS attacks using Artificial Neural Networks","volume":"172","author":"Saied","year":"2016","journal-title":"Neurocomputing"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"507","DOI":"10.1016\/j.procs.2012.06.065","article-title":"A Four-StepTechnique forTackling DDoS Attacks","volume":"10","author":"Beitollahi","year":"2012","journal-title":"Procedia Comput. Sci."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1016\/j.procs.2011.07.022","article-title":"Collaborative Peer to Peer Defense Mechanism for DDoS Attacks","volume":"5","author":"Tariq","year":"2011","journal-title":"Procedia Comput. Sci."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1838","DOI":"10.1016\/j.future.2012.12.011","article-title":"A confidence-based filtering method for DDoS attack defense in cloud environment","volume":"29","author":"Dou","year":"2013","journal-title":"Future Gen. Comput. Syst."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1016\/j.future.2014.03.003","article-title":"DDoS defense system for web services in a cloud environment","volume":"37","author":"Vissers","year":"2014","journal-title":"Future Gen. Comput. Syst."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1016\/j.cose.2013.03.014","article-title":"A game theoretic defence framework against DoS\/DDoS Cyber Attacks","volume":"38","author":"Spyridopoulos","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_23","first-page":"1347","article-title":"Active defense strategy selection based on non-zero-sum attack-defense game model","volume":"33","author":"Chen","year":"2013","journal-title":"J. Comput. Appl."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1016\/j.cose.2014.03.010","article-title":"Analysis on the acceptance of Global Trust Management for unwanted traffic control based on game theory","volume":"47","author":"Shen","year":"2014","journal-title":"Comput. Secur."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1016\/j.comcom.2014.09.002","article-title":"Mitigating congestion based DoS attacks with an enhanced AQM technique","volume":"56","author":"Bedi","year":"2015","journal-title":"Comput. Commun."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"3594","DOI":"10.1016\/j.physa.2008.02.023","article-title":"Prediction of stock markets by the evolutionary mix-game model","volume":"387","author":"Chen","year":"2008","journal-title":"Phys. A"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"483","DOI":"10.1016\/j.physa.2003.10.009","article-title":"Minority game with peer pressure","volume":"332","author":"Chau","year":"2004","journal-title":"Physica A"},{"key":"ref_28","first-page":"148","article-title":"Fair and efficient network congestion control algorithm based on minority game with local information","volume":"35","author":"Wang","year":"2014","journal-title":"J. Commun."},{"key":"ref_29","unstructured":"Internet Engineering Task Force (IETF) Computing TCP's Retransmission Timer. Available online: http:\/\/ietfreport.isoc.org\/idref\/rfc6298\/."},{"key":"ref_30","first-page":"449","article-title":"Random variables, joint distributions, and copulas","volume":"9","author":"Sklar","year":"1973","journal-title":"Kybernetika"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1034","DOI":"10.1080\/01621459.1993.10476372","article-title":"Statistical inference procedures for bivariate Archimedean copulas","volume":"88","author":"Genest","year":"1993","journal-title":"J. Am. Stat. Assoc. Theory Methods"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1016\/j.engappai.2014.02.009","article-title":"Neural network ensembles based on copula methods and Distributed Multiobjective Central Force Optimization algorithm","volume":"32","author":"Chao","year":"2014","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_33","unstructured":"Nelsen, R. (2006). An Introduction to Copulas, Springer."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1016\/j.anbehav.2015.08.020","article-title":"A Male birch catkin bugs vary copula duration to invest more in matings with novel females","volume":"109","author":"Reinhold","year":"2015","journal-title":"Anim. Behav."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"661","DOI":"10.1007\/s00477-009-0353-8","article-title":"Copula-based geostatistical modeling of continuous and discrete data including covariates","volume":"24","author":"Kazianka","year":"2010","journal-title":"Stoch. Environ. Res. Risk Assess."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"407","DOI":"10.1016\/S0378-4371(97)00419-6","article-title":"Emergence of cooperation and organization in an evolutionary game","volume":"246","author":"Challet","year":"1997","journal-title":"Physica A"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"645","DOI":"10.1016\/j.physa.2007.02.014","article-title":"The minority game with incomplete strategies","volume":"379","author":"Yang","year":"2007","journal-title":"Physica A"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"124","DOI":"10.1016\/S0378-4371(02)01893-9","article-title":"A laboratory experiment on the minority game","volume":"324","author":"Bottazzi","year":"2003","journal-title":"Physica A"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/17\/3\/553\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T18:30:08Z","timestamp":1760207408000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/17\/3\/553"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,3,9]]},"references-count":38,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2017,3]]}},"alternative-id":["s17030553"],"URL":"https:\/\/doi.org\/10.3390\/s17030553","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2017,3,9]]}}}