Yudong Yan

dblp:250/0446 · DBLP profile ↗
← Back
10ranked-venue papers
0as first author
10since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Low-Rate Flow Table Overflow Attacks in SDN: Model, Analysis and a Machine Learning Based Mitigation Approach
abstract
Software-defined Networking (SDN) is an emerging network architecture. The decoupled data and control plane provide flexible manageability and programmability to the network. One of the core components in SDN switches to direct traffic forwarding is the flow table, which is usually stored in the ternary content addressable memory (TCAM) with limited space and high power consumption, making the flow table a potential target for attacks. This paper examines the Low-Rate Flow Table Overflow (LRFTO) attacks, which fill the flow table and render it unavailable by continuously sending attack rules to occupy the space. We propose a quantitative model of LRFTO attacks to describe the attack behavior, analyze its difference from legitimate traffic, and summarize some key aspects and features to distinguish attack rules from legitimate rules. We also propose LRFTO-ADMS, a system that utilizes machine learning-based classification as its core to evict suspicious rules, thereby ensuring flow table availability. Experimental results show that the threat model can adapt correctly to the network environment. The proposed LRFTO-ADMS can evict attack rules with an accuracy of more than 95% and low overhead while protecting the flow table and the legitimate rules from being unavailable.
Dan Tang 0003, Pei Tan, Yudong Yan, Keqin Li 0001, Wei Liang 0005, Zheng Qin 0001, Jiliang Zhang 0002
IEEE Trans. Computers3
2025 Housed pig identification and tracking for precision livestock farming
Albert Compte, Yudong Yan, Xavier Cortés, Sergio Escalera, Júlio C. S. Jacques Júnior
Expert Syst. Appl.2
2023 LtRFT: Mitigate the Low-Rate Data Plane DDoS Attack With Learning-To-Rank Enabled Flow Tables
abstract
Software-Defined Networking (SDN) switches typically have limited ternary content addressable memory (TCAM) that caches the flow entries on the data plane. The scarcity and strong resource competitiveness of TCAM space put the flow tables at the risk of malicious Distributed Denial-of-Service (DDoS) attacks. In this paper, we propose LtRFT, a Learning-To-Rank (LtR) based scheme for mitigating the low-rate DDoS attacks targeted at flow tables. LtRFT consists of three modules:monitor,ranker, andmitigator.Monitormanages the flow table status and sends alerts to other modules after detecting attacks.Rankermodels the attack mitigation problem as a flow entry ranking task, and ranks malicious flows with a high eviction priority using a pairwise-based LtR algorithm. Themitigatorfrees up the flow table space by deleting malicious flow entries according to the flow entry ranking sequence generated byranker. We introduce LtR to network attack detection innovatively and use both classification and information retrieval metrics to describe and evaluate LtRFT. Extensive experiments were conducted to validate the effectiveness and robustness of LtRFT in detecting and mitigating the low-rate data plane DDoS attacks. LtRFT can detect malicious attack flows with an accuracy of over 96%, and can reduce the attack flow duration by 97.7% with an average extra latency of 0.5 seconds, which proves that LtRFT is practicable in SDN deployments.
Dan Tang 0003, Yudong Yan, Chenjun Gao, Wei Liang 0005, Wenqiang Jin
IEEE Trans. Inf. Forensics Secur.2
2022 ADMS: An online attack detection and mitigation system for LDoS attacks via SDN
Dan Tang 0003, Xiyin Wang, Yudong Yan, Dongshuo Zhang, Huan Zhao 0003
Comput. Commun.3
2022 A new detection method for LDoS attacks based on data mining
Dan Tang 0003, Xiyin Wang, Yudong Yan
Future Gener. Comput. Syst.5
2022 Performance and Features: Mitigating the Low-Rate TCP-Targeted DoS Attack via SDN
abstract
Software-Defined Networking (SDN) is an emerging network architecture. The decoupled data and control plane provides programmability for efficient network management. However, the centralized control mode of SDN also exposes unique vulnerabilities. Low-rate Denial of Service (LDoS) has a lower attack rate than ordinary DDoS attacks with the characteristics of periodicity and concealment, which is among one of the severe threats to SDN. In this paper, we propose a lightweight, real-time framework Performance and Features (P&F) to detect and mitigate LDoS attacks with SDN. We implement LDoS attacks in SDN, extract traffic features with OpenFlow, and classify the features into two categories. By analyzing the performance (P) of normal traffic under attack state, P&F determines whether LDoS attacks take effect based on machine learning. Meanwhile, P&F tries to locate attack sources and victims according to flow features (F) of LDoS attacks based on time-frequency analysis. According to detection and locating results, P&F sets corresponding mitigation schemes. Experimental results show that P&F has a high detection rate and low false positive rate for detecting LDoS attacks. P&F can deploy on controllers to achieve real-time attack detection and mitigation with low system cost, which can defend against LDoS attacks effectively.
Dan Tang 0003, Yudong Yan, Zheng Qin 0001
IEEE J. Sel. Areas Commun.2
2022 Real-Time Detection and Mitigation of LDoS Attacks in the SDN Using the HGB-FP Algorithm
abstract
The software-defined network (SDN) has created the conditions for the optimization and development of network structures. However, its architecture is still not sufficient to resist or identify all denial of service (DoS) attacks, such as low-rate DoS (LDoS) attacks. Due to their low transporting rate and flash-crowd-like nature, LDoS attacks are well hidden in the background traffic and difficult to identify by anti-DoS mechanisms in the SDN. By implementing LDoS attacks in the SDN, we confirm that they can severely degrade the quality of service. We further propose a framework based on the histogram-based gradient boosting and finding peaks (HGB-FP) algorithm to detect LDoS attacks and mitigate their influence in the SDN in real-time. The histogram-based gradient boosting (HGB) algorithm, an ensemble learning with high quality and low complexity, can identify LDoS attacks quickly and accurately. The finding peaks (FP) algorithm locates the attacker via peak properties of the flow and installs flow rules on the switches to drop the attack flows. Experiments prove that our framework has higher accuracy and F-measure in identifying LDoS attacks than other machine learning approaches and mitigates the impact of LDoS attacks on bottleneck links in the SDN within seconds on average.
Dan Tang 0003, Yudong Yan, Zheng Qin 0001
IEEE Trans. Serv. Comput.3
2021 LDoS Attack Detection using PSO and K-means Algorithm
abstract
Low-rate Denial of Service (LDoS) attack exploiting vulnerabilities of TCP protocol for periodic attacks usually results in the degradation of service quality. Its short attack duration and low average attack traffic make it highly efficient and concealed. Existing detection methods against this type of attack still have a shortcoming that the accuracy is not so satisfactory. A method for detecting LDoS attacks using PSO and k-means algorithm is proposed in this paper. The method first divides the detection time into multiple detection units, samples the traffic data of the data stream and summarizes the traffic characteristics in each detection unit, and then it uses the K-means algorithm to calculate the clustering center. In order to conduct a better detection, the particle swarm optimization algorithm is used to perturb the clustering center to avoid the defect that the K-means algorithm is easy to fall into the local optimal solution. Finally, the network features after clustering are compared with the anomalous features generated after the LDoS attacks, and the relevant criteria is adopted to judge and subsequently verify the LDoS attacks. The experiments are carried out on multiple platforms and public datasets such as NS2 platform, test-bed platform, DARPA dataset, LBNL dataset and WIDE2018 dataset. The results of comparative experiments show that the proposed method has a better performance in effectively detecting LDoS attacks.
Siyuan Wang 0019, Dan Tang 0003, Yudong Yan
CSCWD5
2021 Work in Progress: Network Attack Detection Towards Smart Factory
abstract
With the continuous development of network communication and Internet of Things technology, the smart factory of new energy vehicles is increasingly dependent on network communication technology. Due to its increasing openness, which leads to increasing security risks, the attackers' system vulnerability discovery ability and attack techniques are also improving, making the security threats of smart factories escalating. To improve the autonomous sensing and defence capability of smart production lines for security vulnerabilities in the collaborative manufacturing environment, we put forward an adaptive LDoS attack detection scheme based on RF-GMM algorithm in an SDN environment. The method distinguishes normal and abnormal states of networks in smart factories by establishing a multi-feature selection model and profiling network anomalies to achieve the detection for external intrusions.
Dan Tang 0003, Dongshuo Zhang, Huan Zhao 0003, Dashun Liu, Yudong Yan
RTAS5
2021 TS-SVM: Detect LDoS Attack in SDN Based on Two-step Self-adjusting SVM
abstract
The Low-Rate Denial of Service (LDoS) attack is a new type of Denial of Service attack. Because of its adequate concealment, it is not easy to detect by conventional detection methods. The detection method using a Support Vector Machine (SVM) is feasible, but it has the defect of insufficient generalization ability; consequently, this paper proposes the LDoS attack detection method based on the Two-step Self-adjusting Support Vector Machine (TS-SVM). For the network traffic data, the Discrete Wavelet Transform is used as the feature extraction tool to decompose and reconstruct the network traffic, and the time-domain features such as the mean value of the traffic subband are selected for detection. Two kinds of SVM approaches of self-adjusting are put forward in this paper: to adjust the increasing degree of data dimension, and the other is to adjust the error tolerance. Next, the Adaptive Particle Swarm Optimization (APSO) algorithm is used to realize the two adjustment approaches, ultimately achieving the goal of ascension generalization ability. The detection model constructed has a higher detection effect. To verify the method's feasibility, experiments are carried out in a Software Defined Network (SDN) created by the Mininet simulator and Ryu controller. By comparing the proposed method with the traditional SVM method, it is shown that the performance of this method is better than that of the method based on the traditional SVM. By comparing with the traditional LDoS detection methods, it is manifested that the detection accuracy of this method is 92.36%-96.65%, which is higher than the traditional detection methods.
Boru Liu, Dan Tang 0003, Yudong Yan, Zhiqing Zheng, Jiangmeng Zhou
TrustCom3