{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T00:09:31Z","timestamp":1784851771209,"version":"3.55.0"},"reference-count":50,"publisher":"MDPI AG","issue":"14","license":[{"start":{"date-parts":[[2021,7,20]],"date-time":"2021-07-20T00:00:00Z","timestamp":1626739200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Horizon 2020","award":["857159"],"award-info":[{"award-number":["857159"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The ever-increasing number of internet-connected devices, along with the continuous evolution of cyber-attacks, in terms of volume and ingenuity, has led to a widened cyber-threat landscape, rendering infrastructures prone to malicious attacks. Towards addressing systems\u2019 vulnerabilities and alleviating the impact of these threats, this paper presents a machine learning based situational awareness framework that detects existing and newly introduced network-enabled entities, utilizing the real-time awareness feature provided by the SDN paradigm, assesses them against known vulnerabilities, and assigns them to a connectivity-appropriate network slice. The assessed entities are continuously monitored by an ML-based IDS, which is trained with an enhanced dataset. Our endeavor aims to demonstrate that a neural network, trained with heterogeneous data stemming from the operational environment (common vulnerability enumeration IDs that correlate attacks with existing vulnerabilities), can achieve more accurate prediction rates than a conventional one, thus addressing some aspects of the situational awareness paradigm. The proposed framework was evaluated within a real-life environment and the results revealed an increase of more than 4% in the overall prediction accuracy.<\/jats:p>","DOI":"10.3390\/s21144939","type":"journal-article","created":{"date-parts":[[2021,7,20]],"date-time":"2021-07-20T11:26:10Z","timestamp":1626780370000},"page":"4939","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":46,"title":["Towards a Machine Learning Based Situational Awareness Framework for Cybersecurity: An SDN Implementation"],"prefix":"10.3390","volume":"21","author":[{"given":"Yannis","family":"Nikoloudakis","sequence":"first","affiliation":[{"name":"Department of Information & Communications Systems Engineering, University of the Aegean, Neo Karlovasi, 83200 Samos, Greece"},{"name":"Electrical and Computer Engineering Department, Hellenic Mediterranean University, Herakleion, 71410 Crete, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1041-9206","authenticated-orcid":false,"given":"Ioannis","family":"Kefaloukos","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, Hellenic Mediterranean University, Herakleion, 71410 Crete, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stylianos","family":"Klados","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, Hellenic Mediterranean University, Herakleion, 71410 Crete, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Spyros","family":"Panagiotakis","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, Hellenic Mediterranean University, Herakleion, 71410 Crete, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Evangelos","family":"Pallis","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, Hellenic Mediterranean University, Herakleion, 71410 Crete, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Charalabos","family":"Skianis","sequence":"additional","affiliation":[{"name":"Department of Information & Communications Systems Engineering, University of the Aegean, Neo Karlovasi, 83200 Samos, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0959-598X","authenticated-orcid":false,"given":"Evangelos K.","family":"Markakis","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, Hellenic Mediterranean University, Herakleion, 71410 Crete, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,7,20]]},"reference":[{"key":"ref_1","unstructured":"(2021, July 16). ENISA Threat Landscape 2020\u2014Data Breach. Available online: https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-2020-data-breach."},{"key":"ref_2","unstructured":"(2021, July 16). ENISA Threat Landscape 2020\u2014Information Leakage. Available online: https:\/\/www.enisa.europa.eu\/publications\/information-leakage."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1016\/j.jnca.2018.05.012","article-title":"An openNCP-based solution for secure ehealth data exchange","volume":"116","author":"Staffa","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Spanos, G., Giannoutakis, K.M., Votis, K., Viano, B., Augusto-Gonzalez, J., Aivatoglou, G., and Tzovaras, D. (2020, January 24\u201326). A Lightweight Cyber-Security Defense Framework for Smart Homes. Proceedings of the 2020 International Conference on INnovations in Intelligent SysTems and Applications (INISTA), Novi Sad, Serbia.","DOI":"10.1109\/INISTA49547.2020.9194689"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/MCOM.2019.1800506","article-title":"Acceleration at the edge for supporting smes security: The FORTIKA paradigm","volume":"57","author":"Markakis","year":"2019","journal-title":"IEEE Commun. Mag."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Sutton, R., Ludwiniak, R., Pitropakis, N., Chrysoulas, N., and Dagiuklas, T. (2021, January 19\u201321). Towards an SDN Assisted IDS. Proceedings of the 2021 11th IFIP International Conference on New Technologies, Mobility and Security (NTMS), Paris, France.","DOI":"10.1109\/NTMS49979.2021.9432651"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1518\/001872095779049543","article-title":"Toward a theory of situation awareness in dynamic systems","volume":"37","author":"Endsley","year":"1995","journal-title":"Hum. Factors"},{"key":"ref_8","first-page":"24","article-title":"Multisensor Data Fusion for Next Generation Distributed Intrusion Detection Systems","volume":"28","author":"Bass","year":"1999","journal-title":"Irish Natl. Symp."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1145\/332051.332079","article-title":"Intrusion detection systems and multisensor data fusion","volume":"43","author":"Bass","year":"2000","journal-title":"Commun. ACM"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Tsolakis, A., Moschos, I., Votis, K., Ioannidis, D., Dimitrios, T., Pandey, P., Katsikas, S., Kotsakis, E., and Garcia-Castro, R. (2018, January 3\u20135). A secured and trusted demand response system based on blockchain technologies. Proceedings of the 2018 Innovations in Intelligent Systems and Applications (INISTA), Thessaloniki, Greece.","DOI":"10.1109\/INISTA.2018.8466303"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Pitropakis, N., Panaousis, E., Giannakoulias, A., Kalpakis, G., Rodriguez, R.D., and Sarigiannidis, P. (2018). An Enhanced Cyber Attack Attribution Framework. International Conference on Trust and Privacy in Digital Business, Springer.","DOI":"10.1007\/978-3-319-98385-1_15"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Markakis, E., Nikoloudakis, Y., Pallis, E., and Manso, M. (2019, January 15\u201318). Security assessment as a service cross-layered system for the adoption of digital, personalised and trusted healthcare. Proceedings of the 2019 IEEE 5th World Forum on Internet of Things (WF-IoT), Limerick, Ireland.","DOI":"10.1109\/WF-IoT.2019.8767249"},{"key":"ref_13","unstructured":"(2021, July 16). First.org. CVSS V3.1. Available online: https:\/\/www.first.org\/cvss\/."},{"key":"ref_14","unstructured":"NIST (2021, February 13). Cybersecurity Framework, Available online: https:\/\/www.nist.gov\/news-events\/news\/2018\/04\/nist-releases-version-11-its-popular-cybersecurity-framework."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Lee, S., Yoon, C., Lee, C., Shin, S., Yegneswaran, V., and Porras, P. (March, January 26). DELTA: A security assessment framework for software-defined networks. Proceedings of the 2014 Network and Distributed System Security Symposium 2017, San Diego, CA, USA.","DOI":"10.14722\/ndss.2017.23457"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1216","DOI":"10.1007\/s12083-019-0716-y","article-title":"Vulnerability assessment as a service for fog-centric ICT ecosystems: A healthcare use case","volume":"12","author":"Nikoloudakis","year":"2019","journal-title":"Peer Peer Netw. Appl."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Loi, F., Sivanathan, A., Gharakheili, H.H., Radford, A., and Sivaraman, V. (2017, January 22\u201324). Systematically evaluating security and privacy for consumer iot devices. Proceedings of the 2017 Workshop on Computing Within Limits 2017, Santa Barbara, CA, USA.","DOI":"10.1145\/3139937.3139938"},{"key":"ref_18","first-page":"53","article-title":"Barrier free internet access: Evaluating the cyber security risk posed by the adoption of bring your own devices to e-learning network infrastructure","volume":"176","author":"Tchao","year":"2017","journal-title":"Int. J. Comput. Appl."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Miettinen, M., Marchal, S., Hafeez, I., Frassetto, T., Asokan, N., Sadeghi, A.-R., and Tarkoma, S. (2017, January 5\u20138). IoT sentinel demo: Automated device-type identification for security enforcement in IoT. Proceedings of the 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), Atlanta, GA, USA.","DOI":"10.1109\/ICDCS.2017.284"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Li, H., Wei, F., and Hu, H. (2019, January 27). Enabling dynamic network access control with anomaly-based IDS and SDN. Proceedings of the 2019 ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization\u2014SDN-NFVSec \u201919, Richardson, TX, USA.","DOI":"10.1145\/3309194.3309199"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Liu, X.-W., Wang, H.-Q., Liang, Y., and Lai, J.-B. (2007;, January 19\u201322). Heterogeneous multi-sensor data fusion with multi-class support vector machines: Creating network security situation awareness. Proceedings of the 2007 International Conference on Machine Learning and Cybernetics, Hong Kong, China.","DOI":"10.1109\/ICMLC.2007.4370604"},{"key":"ref_22","unstructured":"Liu, X., Wang, H., Lai, J., Liang, Y., and Yang, C. (2007, January 21\u201325). Multiclass support vector machines theory and its data fusion application in network security situation awareness. Proceedings of the 2007 International Conference on Wireless Communications, Networking and Mobile Computing, Shanghai, China."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Thaseen, S., and Kumar, C.A. (2013, January 21\u201322). An analysis of supervised tree based classifiers for intrusion detection system. Proceedings of the 2013 International Conference on Pattern Recognition, Informatics and Mobile Engineering, Salem, India.","DOI":"10.1109\/ICPRIME.2013.6496489"},{"key":"ref_24","unstructured":"Zhang, H., Yu, X., Ren, P., Luo, C., and Min, G. (2019). Deep adversarial learning in intrusion detection: A data augmentation enhanced framework. arXiv."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"110034","DOI":"10.1063\/1.5122494","article-title":"Characteristics categorization dataset KDD Cup\u201999","volume":"2142","author":"Srivastava","year":"2019","journal-title":"AIP Conf. Proc."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Mathews, M., Halvorsen, P., Joshi, A., and Finin, T. (2012, January 14\u201317). A collaborative approach to situational awareness for cybersecurity. Proceedings of the 8th International Conference on Collaborative Computing: Networking, Applications and Worksharing 2012, Pittsburgh, PA, USA.","DOI":"10.4108\/icst.collaboratecom.2012.250794"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Zhang, J., and Zhang, B. (2019, January 18\u201320). Visual analysis of cybersecurity situational awareness. Proceedings of the 2019 IEEE 10th International Conference on Software Engineering and Service Science (ICSESS), Beijing, China.","DOI":"10.1109\/ICSESS47205.2019.9040716"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Park, H.K., Kim, M.S., Park, M., and Lee, K. (2017, January 23\u201325). Cyber situational awareness enhancement with regular expressions and an evaluation methodology. Proceedings of the MILCOM 2017\u20132017 IEEE Military Communications Conference (MILCOM), Baltimore, MD, USA.","DOI":"10.1109\/MILCOM.2017.8170859"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Doynikova, E., and Kotenko, I. (2017, January 6\u20138). CVSS-based probabilistic risk assessment for cyber situational awareness and countermeasure selection. Proceedings of the 2017 25th Euromicro International Conference on Parallel, Distributed and Network-based Processing (PDP), St. Petersburg, Russia.","DOI":"10.1109\/PDP.2017.44"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"1401","DOI":"10.1007\/s11277-017-5202-3","article-title":"Research on network security situation assessment and quantification method based on analytic hierarchy process","volume":"102","author":"Wang","year":"2018","journal-title":"Wirel. Pers. Commun."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1007\/978-3-642-83555-1_5","article-title":"What is the analytic hierarchy process?","volume":"Volume 15","author":"Saaty","year":"1988","journal-title":"Mathematical Models for Decision Support"},{"key":"ref_32","first-page":"83","article-title":"Decision making with the analytic hierarchy process","volume":"1","author":"Saaty","year":"2008","journal-title":"Int. J. Serv. Sci."},{"key":"ref_33","first-page":"85","article-title":"Simple view of the dempster-shafer theory of evidence and its implication for the rule of combination","volume":"7","author":"Zadeh","year":"1986","journal-title":"AI Mag."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Irsik, T., and Celeda, P. (2020, January 20\u201324). Cyber situation awareness via IP flow monitoring. Proceedings of the NOMS 2020\u20142020 IEEE\/IFIP Network Operations and Management Symposium, Budapest, Hungary.","DOI":"10.1109\/NOMS47738.2020.9110327"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Jirsik, T., and Celeda, P. (2018, January 23\u201327). Toward real-time network-wide cyber situational awareness. Proceedings of the NOMS 2018\u20142018 IEEE\/IFIP Network Operations and Management Symposium, Taipei, Taiwan.","DOI":"10.1109\/NOMS.2018.8406166"},{"key":"ref_36","unstructured":"(2021, July 16). Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of Flow Information. Available online: http:\/\/www.ietf.org\/rfc\/rfc7011.txt."},{"key":"ref_37","unstructured":"(2021, July 16). NIST\u2019s Cybersecurity Lifecycle, Available online: https:\/\/www.nist.gov\/cyberframework\/online-learning\/five-functions."},{"key":"ref_38","unstructured":"(2021, July 16). Common Vulnerability Scoring System version 3.1: Specification Document. Available online: https:\/\/www.first.org\/cvss\/specification-document."},{"key":"ref_39","unstructured":"(2021, July 16). CVSS v3.0 Calculator. Available online: https:\/\/www.first.org\/cvss\/calculator\/3.0."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the ICISSP 2018, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_41","unstructured":"Brownlee, J. (2018). Better deep learning: Train faster, reduce overfitting, and make better predictions. Machine Learning Mastery, O\u2019Reilly."},{"key":"ref_42","unstructured":"Brownlee, J. (2018). Master machine learning algorithms: Discover How They Work and Implement Them from Scratch. Machine Learning Mastery, O\u2019Reilly."},{"key":"ref_43","unstructured":"Brownlee, J. (2018). Supervised and unsupervised machine learning algorithms. Machine Learning Mastery, O\u2019Reilly."},{"key":"ref_44","unstructured":"Brownlee, J. (2018). Deep learning with python: Develop deep learning models on theano and tensorflow using keras. Machine Learning Mastery, O\u2019Reilly."},{"key":"ref_45","unstructured":"(2021, July 16). TensorFlow Serving Models. Available online: https:\/\/www.tensorflow.org\/tfx\/guide\/serving."},{"key":"ref_46","unstructured":"(2021, July 16). CVE-2014-3120, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2014-3120."},{"key":"ref_47","unstructured":"(2021, July 16). CVE-2015-8249, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-8249."},{"key":"ref_48","unstructured":"(2021, July 16). CVE-2016-1209, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-1209."},{"key":"ref_49","unstructured":"(2021, July 16). CVE-2001-0553, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2001-0553."},{"key":"ref_50","unstructured":"(2021, July 16). CVE-2007-6750, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2007-6750."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/14\/4939\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:32:21Z","timestamp":1760164341000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/14\/4939"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,20]]},"references-count":50,"journal-issue":{"issue":"14","published-online":{"date-parts":[[2021,7]]}},"alternative-id":["s21144939"],"URL":"https:\/\/doi.org\/10.3390\/s21144939","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,20]]}}}