{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T17:20:00Z","timestamp":1784136000974,"version":"3.55.0"},"reference-count":23,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2023,6,8]],"date-time":"2023-06-08T00:00:00Z","timestamp":1686182400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&amp;D Program of China","doi-asserted-by":"publisher","award":["2022YFB3104602"],"award-info":[{"award-number":["2022YFB3104602"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key R&amp;D Program of China","doi-asserted-by":"publisher","award":["2021FNA02004"],"award-info":[{"award-number":["2021FNA02004"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"name":"China University Industry-University-Research Collaborative Innovation Fund","award":["2022YFB3104602"],"award-info":[{"award-number":["2022YFB3104602"]}]},{"name":"China University Industry-University-Research Collaborative Innovation Fund","award":["2021FNA02004"],"award-info":[{"award-number":["2021FNA02004"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The limited computation resource of the centralized controller and communication bandwidth between the control and data planes become the bottleneck in forwarding the packets in Software-Defined Networking (SDN). Denial of Service (DoS) attacks based on Transmission Control Protocol (TCP) can exhaust the resources of the control plane and overload the infrastructure of SDN networks. To mitigate TCP DoS attacks, DoSDefender is proposed as an efficient kernel-mode TCP DoS prevention framework in the data plane for SDN. It can prevent TCP DoS attacks from entering SDN by verifying the validity of the attempts to establish a TCP connection from the source, migrating the connection, and relaying the packets between the source and the destination in kernel space. DoSDefender conforms to the de facto standard SDN protocol, the OpenFlow policy, which requires no additional devices and no modifications in the control plane. Experimental results show that DoSDefender can effectively prevent TCP DoS attacks in low computing consumption while maintaining low connection delay and high packet forwarding throughput.<\/jats:p>","DOI":"10.3390\/s23125426","type":"journal-article","created":{"date-parts":[[2023,6,8]],"date-time":"2023-06-08T02:02:28Z","timestamp":1686189748000},"page":"5426","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["DoSDefender: A Kernel-Mode TCP DoS Prevention in Software-Defined Networking"],"prefix":"10.3390","volume":"23","author":[{"given":"Dongbin","family":"Wang","sequence":"first","affiliation":[{"name":"School of Cyberspace Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Cyberspace Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"},{"name":"Engineering Research Center of Blockchain and Network Convergence Technology, Ministry of Education, Beijing 100876, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hui","family":"Zhi","sequence":"additional","affiliation":[{"name":"TravelSky Technology Limited, Beijing 100190, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dongzhe","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Cyberspace Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"},{"name":"Cyberspace Security Research Center, Peng Cheng Laboratory, Shenzhen 518055, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weihan","family":"Zhuo","sequence":"additional","affiliation":[{"name":"Tencent, Shenzhen 518000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yueming","family":"Lu","sequence":"additional","affiliation":[{"name":"School of Cyberspace Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"},{"name":"Key Laboratory of Ministry of Education and Trustworthy Distributed Computing and Service, Beijing 100876, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4385-1027","authenticated-orcid":false,"given":"Xu","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"},{"name":"National Engineering Research Center of Mobile Network, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,6,8]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1145\/1355734.1355746","article-title":"OpenFlow: Enabling innovation in campus networks","volume":"38","author":"McKeown","year":"2008","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3301614","article-title":"Software-defined Networking-based DDoS Defense Mechanisms","volume":"52","author":"Swami","year":"2020","journal-title":"ACM Comput. Surv."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1109\/MNET.2016.1600109NM","article-title":"On denial of service attacks in software defined networks","volume":"30","author":"Zhang","year":"2016","journal-title":"IEEE Netw."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1206","DOI":"10.1109\/TNET.2016.2626287","article-title":"Lineswitch: Tackling control plane saturation attacks in software defined networking","volume":"25","author":"Ambrosin","year":"2017","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Shin, S., Yegneswaran, V., Porras, P., and Gu, G.F. (2013, January 4\u20138). AVANT-GUARD: Scalable and Vigilant Switch Flow Management in Software-Defined Networks. Proceedings of the 20th ACM Conference on Computer and Communications Security, Berlin, Germany.","DOI":"10.1145\/2508859.2516684"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Wang, H.P., Xu, L., and Gu, G.F. (2015, January 22\u201325). Floodguard: A dos attack prevention extension in software-defined networks. Proceedings of the 45th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, Rio de Janeiro, Brazil.","DOI":"10.1109\/DSN.2015.27"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Zhang, M.Z., Bi, J., Bai, J., Bai, J.S., and Li, G.Y. (2018, January 1\u20133). Floodshield: Securing the sdn infrastructure against denial-of-service attacks. Proceedings of the 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, New York, NY, USA.","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00101"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1545","DOI":"10.1109\/TNSM.2018.2861741","article-title":"SAFETY: Early detection and mitigation of TCP SYN flood utilizing entropy in SDN","volume":"15","author":"Kumar","year":"2018","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1186\/s13638-021-01957-9","article-title":"A cooperative DDoS attack detection scheme based on entropy and ensemble learning in SDN","volume":"90","author":"Yu","year":"2021","journal-title":"EURASIP J. Wireless Commun. Netw."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"685","DOI":"10.1016\/j.future.2018.07.017","article-title":"An early detection of low rate DDoS attack to SDN based data center networks using information distance metrics","volume":"89","author":"Sahoo","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Li, J., Tu, T., Li, Y., Qin, S., Shi, Y., and Wen, Q. (2022). DoSGuard: Mitigating denial-of-service attacks in software-defined networks. Sensors, 22.","DOI":"10.3390\/s22031061"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Tang, T.A., Mhamdi, L., McLernon, D., Zaidi, S.A.R., and Ghogho, M. (2018, January 25\u201329). Deep recurrent neural network for intrusion detection in SDN-based networks. Proceedings of the 4th IEEE Conference on Network Softwarization and Workshops (NetSoft), Montreal, QC, Canada.","DOI":"10.1109\/NETSOFT.2018.8460090"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Khamaiseh, S., Al-Alaj, A., and Warner, A. (2020, January 27\u201329). FloodDetector: Detecting Unknown DoS Flooding Attacks in SDN. Proceedings of the International Conference on Internet of Things and Intelligent Applications, Zhenjiang, China.","DOI":"10.1109\/ITIA50152.2020.9312310"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"607","DOI":"10.1109\/TNSM.2019.2959268","article-title":"Detecting saturation attacks based on self-similarity of openflow traffic","volume":"17","author":"Li","year":"2020","journal-title":"IEEE Trans. Netw. Serv. Man."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"156","DOI":"10.1016\/j.future.2021.06.047","article-title":"Adversarial deep learning approach detection and defense against DDoS attacks in SDN environments","volume":"125","author":"Novaes","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1862","DOI":"10.1109\/TCCN.2022.3186331","article-title":"A flow based anomaly detection approach with feature selection method against DDoS attacks in SDNs","volume":"8","author":"Azer","year":"2022","journal-title":"IEEE Trans. Cogn. Commun. Netw."},{"key":"ref_17","unstructured":"(2023, January 05). Available online: http:\/\/opennetworking.org\/wp-content\/uploads\/2013\/04\/openflow-spec-v1.0.0.pdf."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Onyema, E., Kumar, M., Balasubaramanian, S., and Bharany, S. (2022). A Security Policy Protocol for Detection and Prevention of Internet Control Message Protocol Attacks in Software Defined Networks. Sustainability, 14.","DOI":"10.3390\/su141911950"},{"key":"ref_19","unstructured":"Gao, S., Peng, Z., Xiao, B., Hu, A., and Ren, K. (2017, January 1\u20134). Flooddefender: Protecting data and control plane resources under sdn-aimed dos attacks. Proceedings of the IEEE Conference on Computer Communications, Atlanta, GA, USA."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1419","DOI":"10.1109\/TNET.2020.2983976","article-title":"Detection and mitigation of DoS attacks in software defined networks","volume":"28","author":"Gao","year":"2020","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1109\/TSC.2016.2602861","article-title":"Defending against flow table overloading attack in software-defined networks","volume":"12","author":"Yuan","year":"2019","journal-title":"IEEE Trans. Serv. Comput."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"3471","DOI":"10.1109\/TSC.2021.3102046","article-title":"Real-time Detection and Mitigation of LDoS Attacks in the SDN Using the HGB-FP Algorithm","volume":"15","author":"Tang","year":"2021","journal-title":"IEEE Trans. Serv. Comput."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Phan, T., Gias, T., Islam, S., Huong, T., Thanh, N., and Bauschert, T. (2019, January 9\u201313). Q-MIND: Defeating Stealthy DoS Attacks in SDN with a Machine learning based Defense Framework. Proceedings of the IEEE Global Communications Conference, Waikoloa, HI, USA.","DOI":"10.1109\/GLOBECOM38437.2019.9013585"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/12\/5426\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:50:33Z","timestamp":1760125833000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/12\/5426"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,8]]},"references-count":23,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2023,6]]}},"alternative-id":["s23125426"],"URL":"https:\/\/doi.org\/10.3390\/s23125426","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,6,8]]}}}