VLDB 2026 Research / reviewers in the wild / expert
Dan Tang 0003
dblp:38/5641-3
· DBLP profile ↗
38ranked-venue papers
29as first author
33since 2021 · last 2026
0000-0002-0062-0213ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 15 · 13 first-author · 13 since 2021Systems, architecture and hardware · 7 · 6 first-author · 6 since 2021Security and privacy · 5 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Low-Rate Flow Table Overflow Attacks in SDN: Model, Analysis and a Machine Learning Based Mitigation ApproachabstractSoftware-defined Networking (SDN) is an emerging network architecture. The decoupled data and control plane provide flexible manageability and programmability to the network. One of the core components in SDN switches to direct traffic forwarding is the flow table, which is usually stored in the ternary content addressable memory (TCAM) with limited space and high power consumption, making the flow table a potential target for attacks. This paper examines the Low-Rate Flow Table Overflow (LRFTO) attacks, which fill the flow table and render it unavailable by continuously sending attack rules to occupy the space. We propose a quantitative model of LRFTO attacks to describe the attack behavior, analyze its difference from legitimate traffic, and summarize some key aspects and features to distinguish attack rules from legitimate rules. We also propose LRFTO-ADMS, a system that utilizes machine learning-based classification as its core to evict suspicious rules, thereby ensuring flow table availability. Experimental results show that the threat model can adapt correctly to the network environment. The proposed LRFTO-ADMS can evict attack rules with an accuracy of more than 95% and low overhead while protecting the flow table and the legitimate rules from being unavailable. Dan Tang 0003, Pei Tan, Yudong Yan, Keqin Li 0001, Wei Liang 0005, Zheng Qin 0001, Jiliang Zhang 0002 |
IEEE Trans. Computers | 1 |
| 2026 | DNSGreen: A Comprehensive Defense System Against Bounce-Style DNS DDoS Attacks With P4abstractDNS recursive resolver plays the role of intermediary agent in domain name query service, making it easy to observe various DNS flooding attack behaviors. The programmable data plane has promoted innovation in in-band attack detection, but previous work has not concentrated on DNS services, and there are concerns with mistakenly killing benign traffic and low classification accuracy. In this paper, we propose DNSGreen, a comprehensive defense system against bounce-style DNS DDoS attacks in the programmable data plane. DNSGreen discusses flow and packet characteristics under anomalous behavior, employing a “flow-detection and packet-filtering” pattern to ensure effective defense while allowing benign traffic to pass through as much as possible. Furthermore, DNSGreen designs a whitelist collection module, which eliminates the need to inspect trusted streams in subsequent filtering and thereby reducing the occurrence of false positives. Finally, DNSGreen improves the allocation method of the statistical structure to enhance the accuracy of system alarms. We deploy DNSGreen on BMv2 switches and conduct tests in three attack scenarios, demonstrating that DNSGreen safeguards normal users with excellentF0:5score while filtering attack traffic. Dan Tang 0003, Xiaocai Wang, Pei Tan, Zheng Qin 0001, Keqin Li 0001, Jiliang Zhang 0002 |
IEEE Trans. Computers | 1 |
| 2026 | REAPER: Real-Time Detection of Malicious Traffic via Deep Time-Series Embedding Analysis
Dan Tang 0003, Boru Liu, Zheng Qin 0001, Wei Liang 0005, Keqin Li 0001, Wenqiang Jin |
IEEE Trans. Netw. | 1 |
| 2026 | DOE-DTL: A ML-Utilized System Combined With PDP for Detection and Mitigation of DLDoS AttackabstractSoftware-Defined Network (SDN) revolutionizes traditional network structures by isolating the data plane and the control plane, which offers greater flexibility in managing network resources. Nevertheless, SDN remains vulnerable to certain threats inherited from the traditional network, including Distributed Low-rate Denial-of-Service (DLDoS) attack. This attack is more subtle and harder to detect than traditional Distributed Denial-of-Service (DDoS) attacks, because it employs a lower average attack rate. We design a real-time detection and mitigation system named DOE-DTL specifical for the DLDoS attack in SDN. For the DLDoS attack detection, we utilize Machine-Learning (ML) methods to construct a detection model and introduce it in DOE-DTL. In the construction, we leverage Extreme Learning Machine (ELM) and make a dual optimization using Whale Optimization Algorithm (WOA). For the DLDoS attack mitigation, we use double thresholds to determine the attack sources and make corresponding mitigation rules. DOE-DTL innovatively combines the Programmable Data Plane (PDP) in detection and mitigation, shifting some control plane tasks to the data plane. Performance assessments reveal that DOE-DTL ensures fast, accurate attack identification and low-latency mitigation while maintaining low resource usage. Dan Tang 0003, Xinmeng Li, Pei Tan, Keqin Li 0001, Zheng Qin 0001, Jiliang Zhang 0002 |
IEEE Trans. Netw. | 1 |
| 2026 | MWD-CFM: Detection and Mitigation of DDoS Attack Against SDN Flow TablesabstractThe decoupling of SDN control plane and data plane allows control to be carried out independently, enhancing the programmability and manageability of the whole network. However, though this new architecture brings convenience for control, it also sets a pool for attacks. Due to the expensive and resource-consumption characteristics, SDN switches usually have a limited ternary content addressable memory to cache the flow rules in the data plane. Attackers can launch a space-consuming attack to maliciously preempt the flow table, forcing switches to reduce the quality of service. Among them, DDoS attacks should be taken seriously, especially the low-rate ones that have a lower attack rate with stronger concealment. In this paper, an architecture named MWD-CFM is proposed to protect against low-rate DDoS attacks in the switch flow tables. Multi-windows work collaboratively to improve detection performance. The feature of flow rules is corrected to do better classification, improving the effectiveness of attack traffic removal. Experiments based on real network topology and datasets are conducted to verify the deployment of MWD-CFM. Results prove that our architecture can greatly reduce the survival time of attack flows and ensure the availability of flow tables for legitimate services. Dan Tang 0003, Chenguang Zuo, Xinmeng Li, Siyuan Wang 0019, Wei Liang 0005, Keqin Li 0001, Jiliang Zhang 0002 |
IEEE Trans. Netw. | 1 |
| 2025 | Low-rate flow table overflow attack defense system based on two-level threshold in software-defined networks
Dan Tang 0003, Chenguang Zuo, Xinmeng Li, Pei Tan, Dongshuo Zhang, Zheng Qin 0001 |
Expert Syst. Appl. | 1 |
| 2025 | A Low-Rate DoS Attack Mitigation Scheme Based on Port and Traffic State in SDNabstractLow-rate Denial of Service (DoS) attacks can significantly compromise network availability and are difficult to detect and mitigate due to their stealthy exploitation of flaws in congestion control mechanisms. Software-Defined Networking (SDN) is a revolutionary architecture that decouples network control from packet forwarding, emerging as a promising solution for defending against low-rate DoS attacks. In this paper, we propose Trident, a low-rate DoS attack mitigation scheme based on port and traffic state in SDN. Specifically, we design a multi-step strategy to monitor switch states. First, Trident identifies switches suspected of suffering from low-rate DoS attacks through port state detection. Then, it monitors the traffic state of switches with abnormal port states. Once a switch is identified as suffering from an attack, Trident analyzes the flow information to pinpoint the malicious flow. Finally, Trident issues rules to the switch's flow table to block the malicious flow, effectively mitigating the attack. We prototype Trident on the Mininet platform and conduct experiments using a real-world topology to evaluate its performance. The experiments show that Trident can accurately and robustly detect low-rate DoS attacks, respond quickly to mitigate them, and maintain low overhead. Dan Tang 0003, Chenguang Zuo, Keqin Li 0001, Zheng Qin 0001 |
IEEE Trans. Computers | 1 |
| 2025 | PLUTO: A Robust LDoS Attack Defense System Executing at Line SpeedabstractThe Low-Rate Denial of Service (LDoS) attack poses a significant threat to Internet services. Exploiting vulnerabilities in adaptive mechanisms embedded within network protocols, LDoS attacks are covert and exhibit legal behavior, making defense challenging. Existing LDoS attack solutions cannot perform real-time LDoS attack defense at line speed. With the emergence of P4, users can program the per-packet processing logic of the P4 switch, which offers us the chance to propose PLUTO, the first data plane-aware LDoS attack defense system built upon the P4 switch, possessing line-speed execution capacity. To meet the resource constraints of the P4 switch, we propose the time window-based pre-inference strategy to detect LDoS attacks and the time-limited per-flow state management to filter the LDoS attack flows. For the practical deployment, we develop the P4 Function Tool to extend the P4 primitives for more function operations. We also adopt an encoding-based mapping method to deploy the pre-inference model. Furthermore, we develop the async-updated hash table for quickly filtering LDoS attack flows. Compared with the baseline, PLUTO reduces the equal error rate (EER) by 27.96% and the average mitigation response time by 12.749 s, increasing the AUC by 1.83%, the F1 Score by 7.27%, and the Recall by 9.58%. Dan Tang 0003, Boru Liu, Keqin Li 0001, Sheng Xiao, Wei Liang 0005, Jiliang Zhang 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | MARS: Defending TCP Protocol Abuses in Programmable Data PlaneabstractThe TCP protocol’s inherent lack of built-in security mechanisms has rendered it susceptible to various network attacks. Conventional defense approaches face dual challenges: insufficient line-rate processing capacity and impractical online deployment requirements. The emergence of P4-based programmable data planes now enables line-speed traffic processing at the hardware level, creating new opportunities for protocol protection. In this context, we present MARS -a data plane-native TCP abuse detection and mitigation system that synergistically combines the Beaucoup traffic monitoring algorithm with artificial neural network (ANN) based anomaly detection, enhanced by adaptive heuristic mitigation rules. Through comprehensive benchmarking against existing TCP defense mechanisms, our solution demonstrates 12.95% higher throughput maintenance and 25.93% improved congestion window recovery ratio during attack scenarios. Furthermore, the proposed framework establishes several novel evaluation metrics specifically for TCP protocol protection systems. Dan Tang 0003, Chenguang Zuo, Jiliang Zhang 0002, Keqin Li 0001, Qiuwei Yang, Zheng Qin 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | EXCLF: A LDoS attack detection & mitigation model based on programmable data plane
Dan Tang 0003, Hongbo Cao, Jiliang Zhang 0002, Zheng Qin 0001, Wei Liang 0005, Xiaopu Ma |
Comput. Networks | 1 |
| 2024 | ERT-EDR: Online defense framework for TCP-targeted LDoS attacks in SDN
Boru Liu, Dan Tang 0003, Wei Liang 0005, Qiuwei Yang |
Expert Syst. Appl. | 2 |
| 2024 | FTODefender: An efficient flow table overflow attacks defending system in SDN
Dan Tang 0003, Zhiqing Zheng, Bing Xiong 0001, Zheng Qin 0001, Qiuwei Yang |
Expert Syst. Appl. | 1 |
| 2024 | An LDoS attack detection method based on FSWT time-frequency distribution
Xiaocai Wang, Dan Tang 0003, Zheng Qin 0001, Bing Xiong 0001 |
Expert Syst. Appl. | 2 |
| 2024 | An optimized resource scheduling algorithm based on GA and ACO algorithm in fog computing
Qin Fang, Yingjian Peng, Xiaogang Xu 0008, Dan Tang 0003 |
J. Supercomput. | 6 |
| 2024 | FAPM: A Fake Amplification Phenomenon Monitor to Filter DRDoS Attacks With P4 Data PlaneabstractDistributed Reflection Denial-of-Service (DRDoS) attacks have caused significant destructive effects by virtue of emerging protocol vulnerabilities and amplification advantages, and their intensity is increasing. The emergence of programmable data plane supporting line-rate forwarding provides a new opportunity for fine-grained and efficient attack detection. This paper proposed a light-weight DRDoS attack detection and mitigation system called FAPM, which is deployed at the victim end with the intention of detecting the amplification behavior caused by the attack. It places the work of collecting and calculating reflection features on the data plane operated by “latter window assisting former window” mechanism, and arranges complex identification and regulation logic on the control plane. This approach avoids the hardware constraints of the programmable switch while leveraging their per-packet processing capability. Also, it reduces communication traffic significantly through feature compression and state transitions. Experiments show that FAPM has (1) fast response capability within seconds (2) a memory footprint at the KB level and communication overhead of 1 Kbps, and (3) good robustness. Dan Tang 0003, Xiaocai Wang, Keqin Li 0001, Wei Liang 0005, Jiliang Zhang 0002 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | SFTO-Guard: Real-time detection and mitigation system for slow-rate flow table overflow attacks
Dan Tang 0003, Dongshuo Zhang, Zheng Qin 0001, Qiuwei Yang, Sheng Xiao |
J. Netw. Comput. Appl. | 1 |
| 2023 | AKN-FGD: Adaptive Kohonen Network Based Fine-Grained Detection of LDoS AttacksabstractLow-rate denial of service (LDoS) attacks exploit the security vulnerabilities of network protocols adaptive mechanisms to launch periodic bursts. These attacks result in the severe destruction of the quality of service of TCP applications. Therefore, detection of LDoS attacks is a concern among scientific communities. However, the existing coarse-scale detection methods yield poor detection performance and adaptability. To achieve the accurate detection of LDoS attacks, an adaptive Kohonen Network based fine-grained detection (AKN-FGD) model for LDoS attacks is proposed. Based on the burst and periodicity characteristics of attack traffic, the Smith-Waterman (SW) algorithm is used to estimate the pulse period, which is the length of the detection unit. Subsequently, cluster analysis is performed for each detection unit using the adaptive Kohonen network (AKN) algorithm because the discreteness of traffic suffering from LDoS attacks is more pronounced than that of legitimate traffic. Finally, the existence of LDoS attacks can be verified in view of a novel decision metric, denoted as the anomaly degree, based on the clustering results. We conducted experiments not solely in traditional networks using NS3 and in a test-bed environment but also in a software-defined network (SDN), with accuracies of 99.7%, 99.8%, and 95.6% for detecting LDoS bursts, respectively. The experimental results show that the AKN-FGD scheme not only enables accurate fine-grained detection, that is, it can detect every attack burst, but also estimates the start and end times of the attacks. Moreover, we have compared the AKN-FGD scheme with some other detection methods, and a comparison of the results show that our proposed approach displays better detection performance. Dan Tang 0003, Xiyin Wang, Xiong Li 0002, Pandi Vijayakumar, Neeraj Kumar 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | LtRFT: Mitigate the Low-Rate Data Plane DDoS Attack With Learning-To-Rank Enabled Flow TablesabstractSoftware-Defined Networking (SDN) switches typically have limited ternary content addressable memory (TCAM) that caches the flow entries on the data plane. The scarcity and strong resource competitiveness of TCAM space put the flow tables at the risk of malicious Distributed Denial-of-Service (DDoS) attacks. In this paper, we propose LtRFT, a Learning-To-Rank (LtR) based scheme for mitigating the low-rate DDoS attacks targeted at flow tables. LtRFT consists of three modules:monitor,ranker, andmitigator.Monitormanages the flow table status and sends alerts to other modules after detecting attacks.Rankermodels the attack mitigation problem as a flow entry ranking task, and ranks malicious flows with a high eviction priority using a pairwise-based LtR algorithm. Themitigatorfrees up the flow table space by deleting malicious flow entries according to the flow entry ranking sequence generated byranker. We introduce LtR to network attack detection innovatively and use both classification and information retrieval metrics to describe and evaluate LtRFT. Extensive experiments were conducted to validate the effectiveness and robustness of LtRFT in detecting and mitigating the low-rate data plane DDoS attacks. LtRFT can detect malicious attack flows with an accuracy of over 96%, and can reduce the attack flow duration by 97.7% with an average extra latency of 0.5 seconds, which proves that LtRFT is practicable in SDN deployments. Dan Tang 0003, Yudong Yan, Chenjun Gao, Wei Liang 0005, Wenqiang Jin |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | FTMaster: A Detection and Mitigation System of Low-Rate Flow Table Overflow Attacks via SDNabstractSoftware-defined networking (SDN) faces challenges in efficiently forwarding packets across the network due to the limited capacity of flow tables in the switches. Ternary content addressable memory (TCAM) is typically used to store flow tables, but its limited capacity makes it vulnerable to attacks. Specifically, the Low-rate Flow Table Overflow (LFTO) attack is an attack against the flow table capacity limit, which can occupy massive space in the flow table to decrease the forwarding performance of normal flow rules by slowly sending packets that cannot match the flow table. To address this, we propose the FTMaster, a system to monitor, detect and mitigate LFTO attacks based on machine learning. FTMaster monitors and detects the flow table state by analyzing the features of flow tables. Once the LFTO attack is detected, FTMaster will activate the mitigation module to extract and analyze the features of each flow rule, evict attack flows, and ultimately block the attack source, thereby protecting flow tables and normal flows. Experimental results demonstrate that FTMaster enables real-time LFTO attack detection and mitigation, ensuring normal forwarding and availability of flow tables. Dan Tang 0003, Chenjun Gao, Wei Liang 0005, Jiliang Zhang 0002, Keqin Li 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | PeakSAX: Real-Time Monitoring and Mitigation System for LDoS Attack in SDNabstractSoftware-Defined Networking (SDN) is a new paradigm that facilitates network management by enabling programmability and disassociating the control plane from the data plane. SDN places the control plane into one or more controllers that take charge of the entire network. However, the logically centralized controller of SDN makes it subject to some security issues. Denial-of-Service (DoS) attacks are the main threat to SDN that can lead to impaired performance of the entire network. Low-rate Denial-of-Service (LDoS) attack is a variant of DoS attacks with a lower average attack rate and high concealability which is difficult to identify with traditional DDoS/DoS attack detection mechanisms. Additionally, existing LDoS attack detection and defense mechanisms often have weak real-time performance. To address this issue, we propose in this paper PeakSAX, a novel framework that can protect SDN against LDoS attacks in real-time by (1) Attack monitoring, (2) Traffic symbolization, (3) Malicious traffic identifying, (4) Attacker location, and (5) Mitigation strategy deployment. Simulation results show that PeakSAX can quickly identify and mitigate the impact of LDoS attacks about 4s, which improves over 70% compared to existing solutions. Dan Tang 0003, Zhiqing Zheng, Xiaocai Wang, Sheng Xiao, Qiuwei Yang |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | GASF-IPP: Detection and Mitigation of LDoS Attack in SDNabstractSoftware defined networking (SDN), a highly regarded architecture, enhances the programmability and manageability of the network by decoupling the data plane and the control plane. It has emerged to bring more possibilities to the Internet, but at the same time, its inherent shortcomings have become a pool for malicious attackers. Low-rate denial of service (LDoS) attacks, a variant of denial of service attacks, also pose a threat to the SDN architecture. In this article, we replicate LDoS attacks for the SDN data plane and propose a detection and mitigation framework called GASF-IPP based on multiple traffic and IP-port data by analyzing the network anomalies. By leveraging the OpenFlow protocol, the traffic of switches is monitored. We use Gramian angular summation field (GASF) transformation based on timing analysis to analyze the traffic and combine it with other features to determine whether an attack has occurred. By locating the attacker and the victim, flow rules can be constructed for mitigation. Experiments prove that our proposed framework is correct and effective, the detection and mitigation module can perform real-time work with a low false positive rate (FPR) and respond in average 6.77 s. Dan Tang 0003, Siyuan Wang 0019, Boru Liu, Wenqiang Jin, Jiliang Zhang 0002 |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | ADMS: An online attack detection and mitigation system for LDoS attacks via SDN
Dan Tang 0003, Xiyin Wang, Yudong Yan, Dongshuo Zhang, Huan Zhao 0003 |
Comput. Commun. | 1 |
| 2022 | An approach for detecting LDoS attack based on cloud model
Dan Tang 0003, Sijia Zhan, Zheng Qin 0001, Xiyin Wang |
Frontiers Comput. Sci. | 2 |
| 2022 | A new detection method for LDoS attacks based on data mining
Dan Tang 0003, Xiyin Wang, Yudong Yan |
Future Gener. Comput. Syst. | 1 |
| 2022 | Performance and Features: Mitigating the Low-Rate TCP-Targeted DoS Attack via SDNabstractSoftware-Defined Networking (SDN) is an emerging network architecture. The decoupled data and control plane provides programmability for efficient network management. However, the centralized control mode of SDN also exposes unique vulnerabilities. Low-rate Denial of Service (LDoS) has a lower attack rate than ordinary DDoS attacks with the characteristics of periodicity and concealment, which is among one of the severe threats to SDN. In this paper, we propose a lightweight, real-time framework Performance and Features (P&F) to detect and mitigate LDoS attacks with SDN. We implement LDoS attacks in SDN, extract traffic features with OpenFlow, and classify the features into two categories. By analyzing the performance (P) of normal traffic under attack state, P&F determines whether LDoS attacks take effect based on machine learning. Meanwhile, P&F tries to locate attack sources and victims according to flow features (F) of LDoS attacks based on time-frequency analysis. According to detection and locating results, P&F sets corresponding mitigation schemes. Experimental results show that P&F has a high detection rate and low false positive rate for detecting LDoS attacks. P&F can deploy on controllers to achieve real-time attack detection and mitigation with low system cost, which can defend against LDoS attacks effectively. Dan Tang 0003, Yudong Yan, Zheng Qin 0001 |
IEEE J. Sel. Areas Commun. | 1 |
| 2022 | Real-Time Detection and Mitigation of LDoS Attacks in the SDN Using the HGB-FP AlgorithmabstractThe software-defined network (SDN) has created the conditions for the optimization and development of network structures. However, its architecture is still not sufficient to resist or identify all denial of service (DoS) attacks, such as low-rate DoS (LDoS) attacks. Due to their low transporting rate and flash-crowd-like nature, LDoS attacks are well hidden in the background traffic and difficult to identify by anti-DoS mechanisms in the SDN. By implementing LDoS attacks in the SDN, we confirm that they can severely degrade the quality of service. We further propose a framework based on the histogram-based gradient boosting and finding peaks (HGB-FP) algorithm to detect LDoS attacks and mitigate their influence in the SDN in real-time. The histogram-based gradient boosting (HGB) algorithm, an ensemble learning with high quality and low complexity, can identify LDoS attacks quickly and accurately. The finding peaks (FP) algorithm locates the attacker via peak properties of the flow and installs flow rules on the switches to drop the attack flows. Experiments prove that our framework has higher accuracy and F-measure in identifying LDoS attacks than other machine learning approaches and mitigates the impact of LDoS attacks on bottleneck links in the SDN within seconds on average. Dan Tang 0003, Yudong Yan, Zheng Qin 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | LDoS Attack Detection using PSO and K-means AlgorithmabstractLow-rate Denial of Service (LDoS) attack exploiting vulnerabilities of TCP protocol for periodic attacks usually results in the degradation of service quality. Its short attack duration and low average attack traffic make it highly efficient and concealed. Existing detection methods against this type of attack still have a shortcoming that the accuracy is not so satisfactory. A method for detecting LDoS attacks using PSO and k-means algorithm is proposed in this paper. The method first divides the detection time into multiple detection units, samples the traffic data of the data stream and summarizes the traffic characteristics in each detection unit, and then it uses the K-means algorithm to calculate the clustering center. In order to conduct a better detection, the particle swarm optimization algorithm is used to perturb the clustering center to avoid the defect that the K-means algorithm is easy to fall into the local optimal solution. Finally, the network features after clustering are compared with the anomalous features generated after the LDoS attacks, and the relevant criteria is adopted to judge and subsequently verify the LDoS attacks. The experiments are carried out on multiple platforms and public datasets such as NS2 platform, test-bed platform, DARPA dataset, LBNL dataset and WIDE2018 dataset. The results of comparative experiments show that the proposed method has a better performance in effectively detecting LDoS attacks. Siyuan Wang 0019, Dan Tang 0003, Yudong Yan |
CSCWD | 2 |
| 2021 | Work in Progress: Network Attack Detection Towards Smart FactoryabstractWith the continuous development of network communication and Internet of Things technology, the smart factory of new energy vehicles is increasingly dependent on network communication technology. Due to its increasing openness, which leads to increasing security risks, the attackers' system vulnerability discovery ability and attack techniques are also improving, making the security threats of smart factories escalating. To improve the autonomous sensing and defence capability of smart production lines for security vulnerabilities in the collaborative manufacturing environment, we put forward an adaptive LDoS attack detection scheme based on RF-GMM algorithm in an SDN environment. The method distinguishes normal and abnormal states of networks in smart factories by establishing a multi-feature selection model and profiling network anomalies to achieve the detection for external intrusions. Dan Tang 0003, Dongshuo Zhang, Huan Zhao 0003, Dashun Liu, Yudong Yan |
RTAS | 1 |
| 2021 | TS-SVM: Detect LDoS Attack in SDN Based on Two-step Self-adjusting SVMabstractThe Low-Rate Denial of Service (LDoS) attack is a new type of Denial of Service attack. Because of its adequate concealment, it is not easy to detect by conventional detection methods. The detection method using a Support Vector Machine (SVM) is feasible, but it has the defect of insufficient generalization ability; consequently, this paper proposes the LDoS attack detection method based on the Two-step Self-adjusting Support Vector Machine (TS-SVM). For the network traffic data, the Discrete Wavelet Transform is used as the feature extraction tool to decompose and reconstruct the network traffic, and the time-domain features such as the mean value of the traffic subband are selected for detection. Two kinds of SVM approaches of self-adjusting are put forward in this paper: to adjust the increasing degree of data dimension, and the other is to adjust the error tolerance. Next, the Adaptive Particle Swarm Optimization (APSO) algorithm is used to realize the two adjustment approaches, ultimately achieving the goal of ascension generalization ability. The detection model constructed has a higher detection effect. To verify the method's feasibility, experiments are carried out in a Software Defined Network (SDN) created by the Mininet simulator and Ryu controller. By comparing the proposed method with the traditional SVM method, it is shown that the performance of this method is better than that of the method based on the traditional SVM. By comparing with the traditional LDoS detection methods, it is manifested that the detection accuracy of this method is 92.36%-96.65%, which is higher than the traditional detection methods. Boru Liu, Dan Tang 0003, Yudong Yan, Zhiqing Zheng, Jiangmeng Zhou |
TrustCom | 2 |
| 2021 | LDoS Attack Detection Based on ASNNC-OFA AlgorithmabstractLow-rate denial of service (LDoS) attack is a derivative denial of service (DoS) attack, which reduces the quality of service in the network in the means of sending high-strength and instantaneous streams of data in cycles. Based on the above attack, we proposed a method based on adaptive shared nearest neighbor clustering and outlier factor analysis (ASNNC-OFA) to detect it, whose core idea is to calculate the traffic characteristics of network. We divide these traffic characteristic data based on shared neighbor clustering, and use the outlier factor algorithm to perform anomaly analysis on the divided data by training threshold. The experiments were carried out on NS2 and test-bed respectively, the results of them show that the detection method we proposed has low false negative rate and false positive rate, so it can effectively detect LDoS attacks. Xinmeng Li, Dan Tang 0003, Zheng Qin 0001, Zhiqing Zheng |
WCNC | 3 |
| 2021 | The detection of low-rate DoS attacks using the SADBSCAN algorithm
Dan Tang 0003, Xiyin Wang |
Inf. Sci. | 1 |
| 2021 | MF-CNN: a New Approach for LDoS Attack Detection Based on Multi-feature Fusion and CNN
Dan Tang 0003, Sijia Zhan, Qiuwei Yang |
Mob. Networks Appl. | 1 |
| 2021 | FR-RED: Fractal Residual Based Real-Time Detection of the LDoS AttackabstractThe low-rate denial of service (LDoS) attack mainly exploits security vulnerabilities of adaptive mechanisms in network protocols and application services. The high-rate attack pulses within a short time interval are sent periodically, which will result in the degradation of service quality. The attack traffic is similar to normal traffic from legitimate users in the network, consequently, it is easy to escape the traditional detection methods because of its intermittence. Research works have demonstrated that there are fractal characteristics (self-similarity) of the network traffic over the large scale of time. Although the fractal characteristics of the network traffic will be changed under the LDoS attack, the variations of the fractal characteristics in some network states are not apparent in real-time detection. Based on the fractal characteristics, the fractal residual of the network traffic is analyzed through the Hurst parameters calculating process by R/S algorithm in this article. It can be found that the fractal residual of the network traffic can better reflect the different states of the LDoS attack. Combining the idea behind the sliding window, a novel fractal residual based real-time detection (FR-RED) method of the LDoS attack is proposed. The effectiveness of the method in this article is verified by performing some experiments on two platforms, the NS2 and test-bed. The results manifest the beginning and end of the LDoS attack can be estimated in real-time with high detection accuracy. Dan Tang 0003, Zheng Qin 0001 |
IEEE Trans. Reliab. | 1 |
| 2020 | An Efficient Detection Approach for LDoS Attack based on NCS-SVM AlgorithmabstractLow Rate Denial of Service (LDoS) Attack is a sort of DoS attack with analogous effects but is more hidden. The LDoS attack is essentially launched by a malicious attacker who utilizes the loopholes of the TCP/IP congestion control mechanism to aim the purpose of attacking by using the periodic burst co-intensity attack flow and causing repeated congestion on the network. Disadvantages of high false positive rate and high false negative rate still remain in the existing detection methods for LDoS attacks. In this paper, a new method based on NCS-SVM algorithm for LDoS attacks is presented. By judging the similarity between the normal cloud model and the reference, this method determines whether the LDoS attack has occurred. In this detection process, the inverse cloud generator and the normal cloud’s expectation curve are also adopted. For the purpose of improving the accuracy of detection, a Support Vector Machine (SVM) is introduced to classify the similarity of cloud models. Experiments to verify this algorithm used multiple data sets, namely NS2, Testbed, and WIDE2018. And at last, the experimental results and comparison with other methods are given to prove that the NCS-SVM-based LDoS attack detection method is effective. Zhiqing Zheng, Dan Tang 0003, Siyuan Wang 0019 |
ICCCN | 2 |
| 2020 | WEDMS: An advanced mean shift clustering algorithm for LDoS attacks detection
Dan Tang 0003, Jianping Man, Qiuwei Yang |
Ad Hoc Networks | 1 |
| 2020 | MF-Adaboost: LDoS attack detection based on multi-features and improved Adaboost
Dan Tang 0003, Xiong Li 0002, Joel J. P. C. Rodrigues |
Future Gener. Comput. Syst. | 1 |
| 2020 | An improved VLC mapping method with parameter optimization for reversible data hiding in JPEG bitstream
Cheng Zhang 0038, Bo Ou, Dan Tang 0003 |
Multim. Tools Appl. | 3 |
| 2018 | Low-Rate DoS Attack Detection Based on Two-Step Cluster Analysis
Dan Tang 0003, Sijia Zhan, Jianping Man |
ICICS | 1 |