{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T23:49:54Z","timestamp":1778802594095,"version":"3.51.4"},"reference-count":44,"publisher":"MDPI AG","issue":"18","license":[{"start":{"date-parts":[[2022,9,14]],"date-time":"2022-09-14T00:00:00Z","timestamp":1663113600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Traditional security mechanisms find difficulties in dealing with intelligent assaults in cyber-physical systems (CPSs) despite modern information and communication technologies. Furthermore, resource consumption in software-defined networks (SDNs) in industrial organizations is usually on a larger scale, and the present routing algorithms fail to address this issue. In this paper, we present a real-time delay attack detection and isolation scheme for fault-tolerant software-defined industrial networks. The primary goal of the delay attack is to lower the resilience of our previously proposed scheme, SDN-resilience manager (SDN-RM). The attacker compromises the OpenFlow switch and launches an attack by delaying the link layer discovery protocol (LLDP) packets. As a result, the performance of SDN-RM is degraded and the success rate decreases significantly. In this work, we developed a machine learning (ML)-based attack detection and isolation mechanism, which extends our previous work, SDN-RM. Predicting and labeling malicious switches in an SDN-enabled network is a challenge that can be successfully addressed by integrating ML with network resilience solutions. Therefore, we propose a delay-based attack detection and isolation scheme (DA-DIS), which avoids malicious switches from entering the routes by combining an ML mechanism along with a route-handoff mechanism. DA-DIS increases network resilience by increasing success rate and network throughput.<\/jats:p>","DOI":"10.3390\/s22186958","type":"journal-article","created":{"date-parts":[[2022,9,14]],"date-time":"2022-09-14T23:16:36Z","timestamp":1663197396000},"page":"6958","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["ML-Based Delay Attack Detection and Isolation for Fault-Tolerant Software-Defined Industrial Networks"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4833-825X","authenticated-orcid":false,"given":"Sagar","family":"Ramani","sequence":"first","affiliation":[{"name":"Department of Computer Engineering, Gujarat Technological University, Ahmedabad 382424, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3285-7346","authenticated-orcid":false,"given":"Rutvij H.","family":"Jhaveri","sequence":"additional","affiliation":[{"name":"Department of Computer Science & Engineering, Pandit Deendayal Energy University, Gandhinagar 382007, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,9,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"661","DOI":"10.1007\/s10586-018-2874-8","article-title":"SD-CPS: Software-defined cyber-physical systems. Taming the challenges of CPS with workflows at the edge","volume":"22","author":"Kathiravelu","year":"2019","journal-title":"Clust. Comput."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Yan, S., Gu, Z., Park, J.H., Xie, X., and Dou, C. (2022). Probability-density-dependent load frequency control of power systems with random delays and cyber-attacks via circuital implementation. IEEE Trans. Smart Grid.","DOI":"10.1109\/TSG.2022.3178976"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"735142","DOI":"10.1155\/2014\/735142","article-title":"SDN: Evolution and opportunities in the development IoT applications","volume":"10","author":"Caraguay","year":"2014","journal-title":"Int. J. Distrib. Netw."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Jhaveri, R.H., Tan, R., Easwaran, A., and Ramani, S.V. (2019, January 18\u201321). Managing industrial communications delays with software-defined networking. Proceedings of the 2019 IEEE 25th International Conference on Embedded and Real-Time Computing Systems and Applications (RTCSA), Hangzhou, China.","DOI":"10.1109\/RTCSA.2019.8864557"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Maleh, Y., Qasmaoui, Y., El Gholami, K., Sadqi, Y., and Mounir, S. (2022). A comprehensive survey on SDN security: Threats, mitigations, and future directions. J. Reliab. Intell. Environ., 1\u201339.","DOI":"10.1007\/s40860-022-00171-8"},{"key":"ref_6","first-page":"102613","article-title":"Energy Efficient Fault Tolerance Techniques in Green Cloud Computing: A Systematic Survey and Taxonomy","volume":"53","author":"Bharany","year":"2022","journal-title":"Sustain. Energy Technol. Assess."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1016\/j.comnet.2015.09.012","article-title":"Resilience support in software-defined networking: A survey","volume":"92","author":"Smith","year":"2015","journal-title":"Comput. Netw."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Ramani, S.V., and Jhaveri, R.H. (2022). SDN Framework for Mitigating Time-based Delay Attack. J. Circuits Syst. Comput., 2250264.","DOI":"10.1142\/S0218126622502644"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"e3895","DOI":"10.1002\/ett.3895","article-title":"Detection and defense against network isolation attacks in software defined networks","volume":"32","author":"Yu","year":"2021","journal-title":"Trans. Emerg. Telecommun."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"3752","DOI":"10.1109\/TCYB.2020.2975530","article-title":"Evolutionary divide-and-conquer algorithm for virus spreading control over networks","volume":"51","author":"Zhao","year":"2020","journal-title":"IEEE Trans. Cybern."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Sarker, I.H., Abushark, Y.B., Alsolami, F., and Khan, A.I. (2020). Intrudtree: A machine learning based cyber security intrusion detection model. Symmetry, 12.","DOI":"10.20944\/preprints202004.0481.v1"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Ali, J., and Roh, B.H. (2022). An Effective Approach for Controller Placement in Software-Defined Internet-of-Things (SD-IoT). Sensors, 22.","DOI":"10.3390\/s22082992"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"277","DOI":"10.1007\/s11390-018-1819-2","article-title":"LLMP: Exploiting LLDP for Latency Measurement in Software-Defined Data Center Networks","volume":"33","author":"Li","year":"2018","journal-title":"J. Comput. Sci. Technol."},{"key":"ref_14","unstructured":"Open Networking Foundation (2015). OpenFlow Switch Specification, Open Networking Foundation."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Azodolmolky, S., Wieder, P., and Yahyapour, R. (2013, January 10\u201311). Performance Evaluation of a Scalable Software-Defined Networking Deployment. Proceedings of the 2nd European Workshop on Software Defined Networks, Berlin, Germany.","DOI":"10.1109\/EWSDN.2013.18"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Kim, Y.-J., He, K., Thottan, M., and Deshpande, J.G. (2014, January 3\u20136). Virtualized and self-configurable utility communications enabled by software-defined networks. In Proceedings of 5th IEEE International Conference on Smart Grid Communications (SmartGridComm), Venice, Italy.","DOI":"10.1109\/SmartGridComm.2014.7007682"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Goodney, A., Kumar, S., Ravi, A., and Cho, Y.H. (2013, January 21\u201324). Efficient PMU networking with software defined networks. Proceedings of the 4th IEEE International Conference on Smart Grid Communications (SmartGridComm), Vancouver, BC, Canada.","DOI":"10.1109\/SmartGridComm.2013.6687987"},{"key":"ref_18","unstructured":"Zhang, J., Seet, B.-C., Lie, T.-T., and Foh, C.H. (2013, January 10\u201313). Opportunities for software-defined networking in smart grid. Proceedings of the International Conference on Information, Communications and Signal Processing (ICICS), Tainan, Taiwan."},{"key":"ref_19","first-page":"849","article-title":"Quality of service improvement with optimal software-defined networking controller and control plane clustering","volume":"67","author":"Ali","year":"2021","journal-title":"Comput. Mater. Contin"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"88990","DOI":"10.1109\/ACCESS.2020.2993556","article-title":"An effective hierarchical control plane for software-defined networks leveraging TOPSIS for end-to-end QoS class-mapping","volume":"8","author":"Ali","year":"2020","journal-title":"IEEE Access"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"3129","DOI":"10.1109\/TNSE.2021.3104499","article-title":"Fault-Resilience for Bandwidth Management in Industrial Software-Defined Networks","volume":"8","author":"Jhaveri","year":"2021","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Shaghaghi, A., Kaafar, M.A., Buyya, R., and Jha, S. (2020). Software-defined network (SDN) data plane security: Issues, solutions, and future directions. Handbook of Computer Networks and Cyber Security, Springer.","DOI":"10.1007\/978-3-030-22277-2_14"},{"key":"ref_23","first-page":"8","article-title":"Sphinx: Detecting security attacks in software-defined networks","volume":"15","author":"Dhawan","year":"2015","journal-title":"Ndss"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Shaghaghi, A., Kaafar, M.A., and Jha, S. (2017, January 2\u20136). Wedgetail: An intrusion prevention system for the data plane of software defined networks. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates.","DOI":"10.1145\/3052973.3053039"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"8298","DOI":"10.3934\/mbe.2021411","article-title":"Securing industrial communication with software-defined networking","volume":"18","author":"Savaliya","year":"2021","journal-title":"Math. Biosci. Eng."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Kamisi\u0144ski, A., and Fung, C. (2015, January 12). Flowmon: Detecting malicious switches in software-defined networks. Proceedings of the 2015 Workshop on Automated Decision Making for Active Cyber Defense, Denver, CO, USA.","DOI":"10.1145\/2809826.2809833"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1016\/j.comnet.2017.02.009","article-title":"Fault tolerance in TCAM-limited software defined networks","volume":"116","author":"Mohan","year":"2017","journal-title":"Comput. Netw."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Jero, S., Bu, X., Nita-Rotaru, C., Okhravi, H., Skowyra, R., and Fahmy, S. (2017, January 18\u201320). Beads: Automated attack discovery in openflow-based sdn systems. Proceedings of the International Symposium on Research in Attacks Intrusions, and Defenses, Atlanta, GA, USA.","DOI":"10.1007\/978-3-319-66332-6_14"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"1029","DOI":"10.1109\/TIFS.2020.3013093","article-title":"Flow misleading: Worm-hole attack in software-defined networking via building in-band covert channel","volume":"16","author":"Hua","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"554","DOI":"10.1109\/TNET.2013.2253121","article-title":"Automatic Test Packet Generation","volume":"22","author":"Zeng","year":"2014","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Kim, T., Basescu, C., Jia, L., Lee, S.B., Hu, Y.-C., and Perrig, A. (2014, January 17\u201322). Lightweight Source Authentication and Path Validation. Proceedings of the ACM SIGCOMM, Chicago, IL, USA.","DOI":"10.1145\/2619239.2626323"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Zhou, T., Cai, Z., Xiao, B., Chen, Y., and Xu, M. (2017, January 5\u20138). Detecting rogue AP with the crowd wisdom. Proceedings of the 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), Atlanta, GA, USA.","DOI":"10.1109\/ICDCS.2017.31"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Kuo, E.C., Chang, M.S., and Kao, D.Y. (2018, January 11\u201314). User-side evil twin attack detection using time-delay statistics of TCP connection termination. Proceedings of the 2018 20th International Conference onAdvanced Communication Technology (ICACT), Chuncheon-si, Korea.","DOI":"10.23919\/ICACT.2018.8323699"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"920","DOI":"10.1109\/TCYB.2016.2533424","article-title":"An efficient method for traffic sign recognition based on extreme learning machine","volume":"47","author":"Huang","year":"2016","journal-title":"IEEE Trans Cybern."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1016\/j.neunet.2014.05.014","article-title":"Fast Gaussian kernel learning for classification tasks based on specially structured global optimization","volume":"57","author":"Zhong","year":"2014","journal-title":"Neural Netw."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"233","DOI":"10.1177\/1548512916683451","article-title":"Markov Chain Modeling of Cyber Threats","volume":"14","author":"Gore","year":"2017","journal-title":"J. Def. Model. Simul."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"1086","DOI":"10.1109\/TR.2015.2421391","article-title":"A survey of securing networks using software defined networking","volume":"64","author":"Ali","year":"2015","journal-title":"IEEE Trans. Reliab."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/JPROC.2014.2371999","article-title":"Software-defined networking: A comprehensive survey","volume":"103","author":"Kreutz","year":"2015","journal-title":"Proc. IEEE"},{"key":"ref_39","first-page":"623","article-title":"A survey of security in software defined networks","volume":"18","author":"Natarajan","year":"2015","journal-title":"IEEE Commun. Tutor."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Ghannam, R., and Chung, A. (2016, January 25\u201329). Handling malicious switches in software defined networks. Proceedings of the NOMS 2016-2016 IEEE\/IFIP Network Operations and Management Symposium, Istanbul, Turkey.","DOI":"10.1109\/NOMS.2016.7502995"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1016\/j.compind.2018.10.004","article-title":"Cyber resilience protection for industrial internet of things: A software-defined networking approach","volume":"104","author":"Babiceanu","year":"2019","journal-title":"Comput. Ind."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"1045","DOI":"10.1007\/s11277-020-07407-x","article-title":"Ft-sdn: A fault-tolerant distributed architecture for software defined network","volume":"114","author":"Das","year":"2020","journal-title":"Wirel. Pers. Commun."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"1530","DOI":"10.1155\/2021\/6662175","article-title":"Reaching Consensus with Byzantine Faulty Controllers in Software-Defined Networks","volume":"2021","author":"Cheng","year":"2021","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Kreutz, D., Ramos, F.M., and Verissimo, P. (2013, January 16). Towards secure and dependable software-defined networks. Proceedings of the Second ACM SIGCOMM workshop on Hot topics in Software Defined Networking, Hong Kong, China.","DOI":"10.1145\/2491185.2491199"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/18\/6958\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:31:31Z","timestamp":1760142691000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/18\/6958"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,14]]},"references-count":44,"journal-issue":{"issue":"18","published-online":{"date-parts":[[2022,9]]}},"alternative-id":["s22186958"],"URL":"https:\/\/doi.org\/10.3390\/s22186958","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,9,14]]}}}