{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T16:25:35Z","timestamp":1784737535964,"version":"3.55.0"},"reference-count":26,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2023,4,7]],"date-time":"2023-04-07T00:00:00Z","timestamp":1680825600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Science and Technology Council (NSTC)","award":["110-2221-E- 006-016-"],"award-info":[{"award-number":["110-2221-E- 006-016-"]}]},{"name":"National Science and Technology Council (NSTC)","award":["111-2221-E-006-160-"],"award-info":[{"award-number":["111-2221-E-006-160-"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Software-defined networking (SDN) is a new network architecture that provides programmable networks, more efficient network management, and centralized control than traditional networks. The TCP SYN flooding attack is one of the most aggressive network attacks that can seriously degrade network performance. This paper proposes detection and mitigation modules against SYN flooding attacks in SDN. We combine those modules, which have evolved from the cuckoo hashing method and innovative whitelist, to get better performance compared to current methods Our approach reduces the traffic through the switch and improves detection accuracy, also the required register size is reduced by half for the same accuracy.<\/jats:p>","DOI":"10.3390\/s23083817","type":"journal-article","created":{"date-parts":[[2023,4,10]],"date-time":"2023-04-10T03:24:18Z","timestamp":1681097058000},"page":"3817","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Detection and Mitigation of SYN Flooding Attacks through SYN\/ACK Packets and Black\/White Lists"],"prefix":"10.3390","volume":"23","author":[{"given":"Chun-Hao","family":"Yang","sequence":"first","affiliation":[{"name":"Department of Computer Science and Information Engineering, National Cheng Kung University, Tainan 701401, Taiwan"},{"name":"Department of Computer Science, National Yang Ming Chiao Tung University, Hsinchu 300093, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jhen-Ping","family":"Wu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Information Engineering, National Cheng Kung University, Tainan 701401, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fang-Yi","family":"Lee","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Information Engineering, National Cheng Kung University, Tainan 701401, Taiwan"},{"name":"Department of Computer Science, National Yang Ming Chiao Tung University, Hsinchu 300093, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ting-Yu","family":"Lin","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Information Engineering, National Cheng Kung University, Tainan 701401, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7549-5245","authenticated-orcid":false,"given":"Meng-Hsun","family":"Tsai","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Information Engineering, National Cheng Kung University, Tainan 701401, Taiwan"},{"name":"Department of Computer Science, National Yang Ming Chiao Tung University, Hsinchu 300093, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,4,7]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1645","DOI":"10.1016\/j.future.2013.01.010","article-title":"Internet of Things (IoT): A vision, architectural elements, and future directions","volume":"29","author":"Gubbi","year":"2013","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/JPROC.2014.2371999","article-title":"Software-Defined Networking: A Comprehensive Survey","volume":"103","author":"Kreutz","year":"2014","journal-title":"Proc. IEEE"},{"key":"ref_3","first-page":"870","article-title":"DDOS-attacks detection using an efficient measurement-based statistical mechanism","volume":"23","author":"Bouyeddou","year":"2020","journal-title":"Eng. Sci. Technol. Int. J."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Hill, J., Aloserij, M., and Grosso, P. (2018, January 11). Tracking Network Flows with P4. Proceedings of the 2018 IEEE\/ACM Innovating the Network for Data-Intensive Science (INDIS), Dallas, TX, USA.","DOI":"10.1109\/INDIS.2018.00006"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Lin, T.Y., Wu, J.P., Hung, P.H., Shao, C.H., Wang, Y.T., Cai, Y.Z., and Tsai, M.H. (2020, January 22\u201325). Mitigating SYN flooding attack and ARP spoofing in SDN data plane. Proceedings of the 2020 21st Asia-Pacific Network Operations and Management Symposium (APNOMS), Daegu, Republic of Korea.","DOI":"10.23919\/APNOMS50412.2020.9236951"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1145\/2656877.2656890","article-title":"P4: Programming protocol-independent packet processors","volume":"44","author":"Bosshart","year":"2014","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"122","DOI":"10.1016\/j.jalgor.2003.12.002","article-title":"Cuckoo hashing","volume":"51","author":"Pagh","year":"2004","journal-title":"J. Algorithms"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Luo, L., Guo, D., Ma, R.T.B., Rottenstreich, O., and Luo, X. (2017, January 1\u20134). Network anti-spoofing with SDN data plane. Proceedings of the IEEE INFOCOM 2017\u2014IEEE Conference on Computer Communications, Atlanta, GA, USA.","DOI":"10.1109\/INFOCOM.2017.8057008"},{"key":"ref_9","first-page":"1265","article-title":"A Study on Traffic Asymmetry for Detecting DDoS Attack in P4-based SDN","volume":"38","author":"Lin","year":"2022","journal-title":"J. Inf. Sci. Eng."},{"key":"ref_10","unstructured":"Almaiah, M.A., Al-Zahrani, A., Almomani, O., and Alhwaitat, A.K. (2021). Artificial Intelligence and Blockchain for Future Cybersecurity Applications, Springer."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1545","DOI":"10.1109\/TNSM.2018.2861741","article-title":"SAFETY: Early Detection and Mitigation of TCP SYN Flood Utilizing Entropy in SDN","volume":"15","author":"Kumar","year":"2018","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1002\/j.1538-7305.1951.tb01366.x","article-title":"Prediction and Entropy of Printed English","volume":"30","author":"Shannon","year":"1951","journal-title":"Bell Syst. Tech. J."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"487","DOI":"10.1109\/TNSM.2017.2701549","article-title":"SLICOTS: An SDN-Based Lightweight Countermeasure for TCP SYN Flooding Attacks","volume":"14","author":"Mohammadi","year":"2017","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_14","first-page":"269","article-title":"F3TM: Flooding Factor based Trust Management Framework for secure data transmission in MANETs","volume":"29","author":"Ahmed","year":"2017","journal-title":"J. King Saud Univ.-Comput. Inf. Sci."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"113311","DOI":"10.1109\/ACCESS.2019.2934632","article-title":"Delimitated anti jammer scheme for Internet of vehicle: Machine learning based security approach","volume":"7","author":"Kumar","year":"2019","journal-title":"IEEE Access"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"A84","DOI":"10.1364\/JOCN.11.000A84","article-title":"P4 Edge node enabling stateful traffic engineering and cyber security","volume":"11","author":"Paolucci","year":"2019","journal-title":"J. Opt. Commun. Netw."},{"key":"ref_17","unstructured":"Friday, K., Kfoury, E., Bou-Harb, E., and Crichigno, J. (July, January 29). Towards a Unified In-Network DDoS Detection and Mitigation Strategy. Proceedings of the IEEE Conference on Network Softwarization (NetSoft), Ghent, Belgium."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1912","DOI":"10.1109\/COMST.2018.2889329","article-title":"Optimizing Bloom Filter: Challenges, Solutions, and Comparisons","volume":"21","author":"Luo","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"6461","DOI":"10.11591\/ijece.v10i6.pp6461-6471","article-title":"A new hybrid text encryption approach over mobile ad hoc network","volume":"10","author":"Almaiah","year":"2020","journal-title":"Int. J. Electr. Comput. Eng. (IJECE)"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Ali, A., Almaiah, M.A., Hajjej, F., Pasha, M.F., Fang, O.H., Khan, R., Teo, J., and Zakarya, M. (2022). An industrial IoT-based blockchain-enabled secure searchable encryption approach for healthcare systems using neural network. Sensors, 22.","DOI":"10.3390\/s22020572"},{"key":"ref_21","unstructured":"Open Networking Foundation (2023, April 06). Mininet. Available online: http:\/\/mininet.org\/."},{"key":"ref_22","unstructured":"Open Networking Foundation (2023, April 06). Bmv2. Available online: https:\/\/github.com\/p4lang\/behavioral-model."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Cai, Y.Z., Lai, C.H., Wang, Y.T., and Tsai, M.H. (2020, January 22\u201325). Improving scanner data collection in p4-based sdn. Proceedings of the 2020 21st Asia-Pacific Network Operations and Management Symposium (APNOMS), Daegu, Republic of Korea.","DOI":"10.23919\/APNOMS50412.2020.9237047"},{"key":"ref_24","unstructured":"Stenberg, D. (2023, April 06). Curl. Available online: https:\/\/curl.se\/."},{"key":"ref_25","unstructured":"Sanfilippo, S. (2023, April 06). Hping3. Available online: http:\/\/wiki.hping.org\/."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"43920","DOI":"10.1109\/ACCESS.2020.2976609","article-title":"Low-Rate DoS Attacks, Detection, Defense, and Challenges: A Survey","volume":"8","author":"Zhijun","year":"2020","journal-title":"IEEE Access"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/8\/3817\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:12:19Z","timestamp":1760123539000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/8\/3817"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,7]]},"references-count":26,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2023,4]]}},"alternative-id":["s23083817"],"URL":"https:\/\/doi.org\/10.3390\/s23083817","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4,7]]}}}