Trung V. Phan

dblp:193/6210 · DBLP profile ↗
← Back
10ranked-venue papers
7as first author
5since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 6 first-author · 5 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Learning the APT Kill Chain: Temporal Reasoning over Provenance Data for Attack Stage Estimation
Trung V. Phan, Thomas Bauschert
ICC1
2022 DeepPlace: Deep reinforcement learning for adaptive flow rule placement in Software-Defined IoT Networks
Tri Gia Nguyen, Trung V. Phan, Dinh Thai Hoang, Hai Hoang Nguyen, Duc Tran Le
Comput. Commun.2
2022 DeepAir: Deep Reinforcement Learning for Adaptive Intrusion Response in Software-Defined Networks
abstract
In this paper, we propose an adaptive intrusion response solution based on deep reinforcement learning, namely DeepAir, to effectively defend against cyber-attacks in Software-Defined Networks (SDN). Specifically, we first study an intrusion response system (IRS) that operates at the SDN control plane. Next, we propose a dynamic intrusion response solution to maximize the attack defense performance while minimizing the negative impact on benign traffic forwarding and the policy deployment cost in the SDN data plane. Then, we model the intrusion response system based on a Markov decision process (MDP) approach and formulate the related optimization problem. Afterward, we develop a Double Deep${Q}$-Network based intrusion response control algorithm to assist the intrusion response system to quickly obtain the optimal intrusion response policy. In our case study, we consider denial-of-service (DoS) attacks—the performance evaluation results demonstrate that DeepAir can effectively prevent malicious packets from arriving at the victim in all considered DoS attack scenarios, i.e., approximately 85% of attack packets are dropped. Moreover, by applying the optimal intrusion response policy, DeepAir can significantly reduce the ratio of Quality-of-Service violated traffic flows compared to a${Q}$-learning based approach (by 70%), and to two existing solutions, i.e., GATE (by 75%) and GTAC-IRS (by 80%), respectively.
Trung V. Phan, Thomas Bauschert
IEEE Trans. Netw. Serv. Manag.1
2021 DeepMatch: Fine-Grained Traffic Flow Measurement in SDN With Deep Dueling Neural Networks
abstract
In this paper, we propose a novel flow rule matching framework, DeepMatch, in Software-Defined Networking (SDN) to provide a fine-grained traffic flow measurement capability. Specifically, the flow rule matching control at a particular SDN switch is examined to maximize the traffic flow granularity degree while proactively protecting the flow-table in the switch from being overflowed. This control process is supervised by a control module referred to as DeepMatch instance. Regarding this instance, an optimization problem is formulated based on a Markov decision process (MDP) and a Partially Observable Markov decision process (POMDP), respectively. We develop a deep dueling neural network based flow rule matching control algorithm to solve the optimization problem, thereby quickly attaining a significant traffic flow granularity level and eliminating the switch flow-table overflow problem. Furthermore, we propose an experience data sharing (EDS) mechanism that enables a new instance to learn faster about the flow rule matching control. The results of our performance evaluation show that, by applying the DeepMatch framework in a highly dynamic traffic scenario, the traffic flow granularity degree at the access and the core switches increases by 24.0% and 31.63%, respectively, compared to the FlowStat method. DeepMatch is also highly outperforming the ReWiFlow, SDN-Mon, and Exact-Match approaches. In addition, by employing the EDS mechanism, a new instance can reduce its learning time up to 46.42% for supervising an access switch and up to 37.50% for supervising a core switch.
Trung V. Phan, Tri Gia Nguyen, Thomas Bauschert
IEEE J. Sel. Areas Commun.1
2021 An efficient distributed algorithm for target-coverage preservation in wireless sensor networks
Tri Gia Nguyen, Trung V. Phan, Hai Hoang Nguyen, Phet Aimtongkham, Chakchai So-In
Peer-to-Peer Netw. Appl.2
2020 DeepGuard: Efficient Anomaly Detection in SDN With Fine-Grained Traffic Flow Monitoring
abstract
Software-Defined Networking (SDN) leverages the implementation of reliable, flexible and efficient network security mechanisms which make use of novel techniques such as artificial intelligence (AI) and machine learning (ML). In particular, these techniques - together with SDN - are the key enablers for the design of anomaly detection methods which are based on efficient traffic flow monitoring. In this paper, we tackle this problem by proposing an efficient anomaly detection framework, denoted as DeepGuard, which improves the detection performance of cyberattacks in SDN based networks by adopting a fine-grained traffic flow monitoring mechanism. Specifically, the proposed framework utilizes a deep reinforcement learning technique, i.e., Double Deep${Q}$-Network (DDQN), to learn traffic flow matching strategies maximizing the traffic flow granularity while proactively protecting the SDN data plane from being overloaded. Afterwards, by implementing the learned optimal traffic flow matching control policy, the most beneficial traffic information for anomaly detection is acquired at runtime—thereby improving the cyberattack detection performance. The performance of the proposed framework is validated by extensive experiments, and the results show that DeepGuard yields significant performance improvements compared to existing traffic flow matching mechanisms regarding the level of traffic flow granularity. In the case of distributed denial-of-service (DDoS) attacks, DeepGuard achieves a remarkable attack detection performance while effectively preventing forwarding performance degradation in the SDN data plane.
Trung V. Phan, Tri Gia Nguyen, Nhu-Ngoc Dao, Thu-Huong Truong, Nguyen Huu Thanh 0001, Thomas Bauschert
IEEE Trans. Netw. Serv. Manag.1
2019 Q-DATA: Enhanced Traffic Flow Monitoring in Software-Defined Networks applying Q-learning
abstract
The following topics are dealt with: learning (artificial intelligence); telecommunication traffic; virtualisation; resource allocation; Internet of Things; software defined networking; Internet; computer network management; mobile computing; 5G mobile communication.
Trung V. Phan, Syed Tasnimul Islam, Tri Gia Nguyen, Thomas Bauschert
CNSM1
2019 Q-MIND: Defeating Stealthy DoS Attacks in SDN with a Machine-Learning Based Defense Framework
abstract
Software Defined Networking (SDN) enables flexible and scalable network control and management. However, it also introduces new vulnerabilities that can be exploited by attackers. In particular, low-rate and slow or stealthy Denial-of-Service (DoS) attacks are recently attracting attention from researchers because of their detection challenges. In this paper, we propose a novel machine learning based defense framework named Q-MIND, to effectively detect and mitigate stealthy DoS attacks in SDN-based networks. We first analyze the adversary model of stealthy DoS attacks, the related vulnerabilities in SDN-based networks and the key characteristics of stealthy DoS attacks. Next, we describe and analyze an anomaly detection system that uses a Reinforcement Learning-based approach based on Q-Learning in order to maximize its detection performance. Finally we outline the complete Q-MIND defense framework that incorporates the optimal policy derived from the Q- Learning agent to efficiently defeat stealthy DoS attacks in SDN-based networks. An extensive comparison of the Q-MIND framework and currently existing methods shows that significant improvements in attack detection and mitigation performance are obtained by Q-MIND.
Trung V. Phan, T. M. Rayhan Gias, Syed Tasnimul Islam, Thu-Huong Truong, Nguyen Huu Thanh 0001, Thomas Bauschert
GLOBECOM1
2019 A Novel Impact Analysis Approach for SDN-based Networks
abstract
Risk assessment comprises a series of processes for evaluating the extent to which a system is threatened by cyber-attacks. One important aspect of risk assessment is to determine the magnitude of impact of cyber-attacks. In this paper we propose a novel impact analysis approach which adopts both qualitative and quantitative elements for determining the impact value. As use case, we consider a Software-Defined Networking (SDN)-based communication system and three types of Distributed Denial of Service (DDoS) attacks, namely ICMP Flood, UDP Flood, and TCP Syn Flood attacks. By applying the impact analysis approach, we are able to calculate the impact of the aforementioned DDoS attack types on each network component and identify the most impacted component. We are also able to calculate the impact on the whole SDN network and thus, to figure out the most severe DDoS attack type.
Beny Nugraha, Mehrdad Hajizadeh, Trung V. Phan, Thomas Bauschert
NetSoft3
2017 Distributed-SOM: A novel performance bottleneck handler for large-sized software-defined networks under flooding attacks
Trung V. Phan, Nguyen Khac Bao, Minho Park 0001
J. Netw. Comput. Appl.1