EDBT 2026 Demo / reviewers in the wild / expert
Sandra Scott-Hayward
dblp:23/10701
· DBLP profile ↗
25ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0002-0330-1963ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 3 first-author · 7 since 2021Security and privacy · 3 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RSLAQ - A Robust SLA-Driven 6G O-RAN QoS Xapp Using Deep Reinforcement LearningabstractThe evolution of 6G envisions a wide range of applications and services characterized by highly differentiated and stringent Quality of Service (QoS) requirements. Open Radio Access Network (O-RAN) technology has emerged as a transformative approach that enables intelligent software-defined management of the RAN. A cornerstone of O-RAN is the RAN Intelligent Controller (RIC), which facilitates the deployment of intelligent applications (xApps and rApps) near the radio unit. In this context, QoS management through O-RAN has been explored using network slice and machine learning (ML) techniques. Although prior studies have demonstrated the ability to optimize RAN resource allocation and prioritize slices effectively, they have not considered the critical integration of Service Level Agreements (SLAs) into the ML learning process. This omission can lead to suboptimal resource utilization and, in many cases, service outages when the target Key Performance Indicators (KPIs) are not met. This work introduces RSLAQ, an innovative xApp designed to ensure robust QoS management for RAN slicing while incorporating SLAs directly into its operational framework. RSLAQ translates operator policies into actionable configurations, guiding resource distribution and scheduling for RAN slices. Using deep reinforcement learning (DRL), RSLAQ dynamically monitors RAN performance metrics and computes optimal actions, embedding SLA constraints to mitigate conflicts and prevent outages. Extensive system-level simulations validate the efficacy of the proposed solution, demonstrating its ability to optimize resource allocation, improve SLA adherence, and maintain operational reliability (> 95%) in challenging scenarios. Noe Marcelo Yungaicela-Naula, Vishal Sharma 0001, Sandra Scott-Hayward |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | Evaluation of Autonomous Intrusion Response Agents in Adversarial and Normal Scenarios
Matthew Reaney, Kieran McLaughlin, Sandra Scott-Hayward |
ESORICS (1) | 3 |
| 2025 | Epidemic Oracle: An Approach to Boost Security and Performance of Delay Tolerant NetworksabstractDelay Tolerant Networks (DTNs) play a vital role in disaster response to address intermittent connectivity, in particular when Unmanned Aerial Vehicles (UAVs) are deployed to relay critical information. However, most existing DTN protocols are highly susceptible to Denial-of-Service (DoS) attacks because their flooding-based or simplistic routing decisions can be exploited by malicious nodes to quickly saturate buffers, exhausting network resources and disrupting legitimate traffic. This paper presents an Epidemic Oracle (EO) implementation, to mitigate DoS threats by intelligently removing delivered messages from all buffers, thus reducing overhead and freeing network resources. Through extensive simulation in the ONE environment, EO is evaluated against three established encounter-based DTN protocols—Epidemic, Spray and Wait, and Spray and Wait Binary—under varying buffer sizes, transmission speeds, and both aggressive and stealthy DoS attacks. The findings indicate that EO substantially increases delivery ratios while curtailing buffer congestion, even under severe adversarial conditions. These improvements highlight the potential of oracle-based interventions to bolster performance in UAV-assisted disaster scenarios, paving the way for more resilient and efficient DTNs in emergency communications. Fayzuddin Topu, Kieran McLaughlin, Sandra Scott-Hayward |
ISCC | 3 |
| 2025 | SLAQ: An SLA-Driven 6G O-RAN QoS Framework Using Deep Reinforcement LearningabstractAs 6G scenarios grow in complexity, network operators need an automated and optimized approach to managing Quality-of-Service (QoS) in the radio access network (RAN). Transitioning from resource-focused management to one that considers evolving operator intents is essential. This can be achieved by translating service-level agreement (SLA) intents into operational rules to ensure compliance and save costs. O-RAN introduced the RAN intelligent controller (RIC) and intelligent applications (xApps) to enhance the RAN operation. Furthermore, RAN slicing has been shown as the most promising method to provide O-RAN-based QoS in 6G. However, while existing methods optimize resources allocated per slice, they often overlook SLAs. This leads to suboptimal resource usage and outages when the system fails to meet target key performance indicators (KPIs). This work introduces SLAQ, an xApp designed to translate service operator requirements to optimize spectrum resource sharing. SLAQ monitors key performance metrics (KPMs) and employs deep reinforcement learning (DRL) to make decisions within the RAN. SLA policies are modeled and integrated into the xApp to optimize resource distribution while preventing SLA conflicts and outages. Our highly-detailed system-level simulations show that SLAQ effectively learns optimal actions, achieving high communication reliability, i.e., close to $99 \%$ for ultra-reliable low-latency communications. Noe Marcelo Yungaicela-Naula, Vishal Sharma 0001, Sandra Scott-Hayward |
ISNCC | 3 |
| 2024 | Misconfiguration in O-RAN: Analysis of the impact of AI/MLabstractUser demand on network communication infrastructure has never been greater with applications such as extended reality, holographic telepresence, and wireless brain-computer interfaces challenging current networking capabilities. Open RAN (O-RAN) is critical to supporting new and anticipated uses of 6G and beyond. It promotes openness and standardisation, increased flexibility through the disaggregation of Radio Access Network (RAN) components, supports programmability, flexibility, and scalability with technologies such as Software-Defined Networking (SDN), Network Function Virtualization (NFV), and cloud, and brings automation through the RAN Intelligent Controller (RIC). Furthermore, the use of xApps, rApps, and Artificial Intelligence/Machine Learning (AI/ML) within the RIC enables efficient management of complex RAN operations. However, due to the open nature of O-RAN and its support for heterogeneous systems, the possibility of misconfiguration problems becomes critical. In this paper, we present a thorough analysis of the potential misconfiguration issues in O-RAN with respect to integration and operation, the use of SDN and NFV, and, specifically, the use of AI/ML. The opportunity for AI/ML to be used to identify these misconfigurations is investigated. A case study is presented to illustrate the direct impact on the end user of conflicting policies amongst xApps along with a potential AI/ML-based solution to this problem. This research presents a first analysis of the impact of AI/ML on misconfiguration challenges in O-RAN. Noe Marcelo Yungaicela-Naula, Vishal Sharma 0001, Sandra Scott-Hayward |
Comput. Networks | 3 |
| 2024 | Defeating Data Plane Attacks With Program ObfuscationabstractData plane switches in software-defined networks are increasingly recognised as potential targets for attack, with recent exploits showing their vulnerability to full compromise. The serious consequences of such a breach have prompted the design of compromise detection mechanisms, which monitor switch forwarding behaviour at runtime to ensure that it has not been altered by an attack. However, such defences cannot achieve full coverage in stateful, programmable data planes, creating an opportunity for an attacker to evade detection by carefully editing a switch's forwarding program to mishandle a small subset of packets. To exploit this opportunity and avoid detection, an attacker must analyse and edit the program's behaviour within a narrow time window, which is possible when the data plane is defined by a uBPF program compiled from P4, due to the predictable compilation process. In this work, we aim to invalidate this analysis-guided attack technique with targeted obfuscation of P4-uBPF programs that increases the analysis complexity. We find that, by inserting additional program paths and syntactic dependencies between variables, we can force an attacker to analyse a higher proportion of program instructions and carry out time-consuming SMT solving to find valid program paths, rendering the previous attack technique infeasible. Furthermore, by applying our identified program optimisations, program performance can often be maintained after obfuscation. In evaluating our work, we identify the potential to improve our solution by tailoring obfuscations to individual program paths. Conor Black, Sandra Scott-Hayward |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Investigating the Vulnerability of Programmable Data Planes to Static Analysis-Guided AttacksabstractProgrammable network data planes are paving the way for networking innovations, with the ability to perform complex, stateful tasks defined in high-level languages such as P4. The enhanced capabilities of programmable data plane devices has made verification of their runtime behaviour, using established methods such as probe packets, impossible to scale beyond probabilistic detection. This has created a potential opportunity for an attacker, with access to a compromised device, to subtly alter its forwarding program to mishandle only a small subset of packets, evading probabilistic detection. In practice, such subtle binary instrumentation attacks require extensive knowledge of the forwarding program, yet it is unclear whether a static analysis of compiled P4 programs to obtain this knowledge can be fast and accurate enough for an on-device attack scenario. In this work, we investigate this possibility by implementing a static analysis of P4 programs compiled to BPF bytecode. This analysis gathers sufficient information for the attacker to identify appropriate (reliably correct) edits to the program. We found that, due to predictable compiler behaviours, our analysis remains accurate even when several program behaviours are abstracted away. Our evaluation of the analysis requirements shows that, from a defensive perspective, there is scope for selectively manipulating those instructions in P4-BPF programs that are critical to attack-focused analysis in order to increase its difficulty, without increasing the number of program instructions. Conor Black, Sandra Scott-Hayward |
NetSoft | 2 |
| 2022 | Detecting Data Exfiltration over Encrypted DNSabstractData breaches linked to individual and company information are exposed on an almost daily basis. With increasing media attention and visibility of this security issue, users are becoming more aware of privacy concerns related to their activity on the Internet. Fundamental to the operation of the Internet is the Domain Name System (DNS), which translates domain names to IP addresses enabling easy web browsing. Encrypted DNS has become popular to increase user privacy by ensuring that activity transmitted over domain queries is not visible to intermediary network devices between the client and the DNS endpoint. Unfortunately, this undermines the security services designed to analyse DNS traffic for the detection of exploitation of DNS for use as a covert communication and data exfiltration channel. In this work, we propose a solution, DoHxP, to enable protection of DNS over HTTPS (DoH) traffic from data exfiltration without compromising user privacy. Our results show that DoHxP successfully prevents up to 99.88% of the malicious DoH traffic from being transmitted outside of the network. Jacob Steadman, Sandra Scott-Hayward |
NetSoft | 2 |
| 2022 | Guest Editors Introduction: Special Section on Recent Advances in Network Security ManagementabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Sandra Scott-Hayward, Qi Li 0002, Fulvio Valenza, Cristian Hesselman |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | Adversarial Exploitation of P4 Data Planes
Conor Black, Sandra Scott-Hayward |
IM | 2 |
| 2021 | DNSxP: Enhancing data exfiltration protection through data plane programmability
Jacob Steadman, Sandra Scott-Hayward |
Comput. Networks | 2 |
| 2021 | Guest Editors' Introduction: Special Issue on Latest Developments for Security Management of Networks and ServicesabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Sandra Scott-Hayward, Qi Li 0002, Jie Zhang 0002, Cristian Hesselman |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | Can SDN deanonymize Bitcoin users?abstractAccording to the Internet Organised Crime Threat Assessment (IOCTA) 2019 report, Bitcoin is still the currency of choice in criminal markets and as payment for cyber-related extortion attempts, such as from ransomware or a Distributed Denial-of-Service (DDoS) attack. Bitcoin is a peer-to-peer electronic cash system first proposed by Satoshi Nakamoto in 2008. By design, Bitcoin is a pseudonymous coin, meaning that users can transact with the currency without revealing their true identity. To tackle the challenge of Bitcoin-related crime, a range of deanonymization techniques have been proposed. In general, these solutions are limited by the time and resources required to predict likely transaction owners. In this paper, we propose the first software-defined network (SDN)-based Bitcoin transaction mapping solution. We analyse the Bitcoin transaction process in an SDN environment and demonstrate a deterministic approach to deanonymize users in Bitcoin's network. Victoria Wallace, Sandra Scott-Hayward |
ICC | 2 |
| 2020 | A comprehensive security assessment framework for software-defined networks
Seungsoo Lee 0001, Jinwoo Kim 0006, Seungwon Woo, Changhoon Yoon, Sandra Scott-Hayward, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
Comput. Secur. | 5 |
| 2020 | Guest Editorial: Special Section on Cybersecurity Techniques for Managing Networked SystemsabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Qi Li 0002, Sandra Scott-Hayward |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | Lucid: A Practical, Lightweight Deep Learning Solution for DDoS Attack DetectionabstractDistributed Denial of Service (DDoS) attacks are one of the most harmful threats in today's Internet, disrupting the availability of essential services. The challenge of DDoS detection is the combination of attack approaches coupled with the volume of live traffic to be analysed. In this paper, we present a practical, lightweight deep learning DDoS detection system called Lucid, which exploits the properties of Convolutional Neural Networks (CNNs) to classify traffic flows as either malicious or benign. We make four main contributions; (1) an innovative application of a CNN to detect DDoS traffic with low processing overhead, (2) a dataset-agnostic preprocessing mechanism to produce traffic observations for online attack detection, (3) an activation analysis to explain Lucid's DDoS classification, and (4) an empirical validation of the solution on a resource-constrained hardware platform. Using the latest datasets, Lucid matches existing state-of-the-art detection accuracy whilst presenting a 40x reduction in processing time, as compared to the state-of-the-art. With our evaluation results, we prove that the proposed approach is suitable for effective DDoS detection in resource-constrained operational environments. Roberto Doriguzzi Corin, Stuart Millar, Sandra Scott-Hayward, Jesús Martínez del Rincón, Domenico Siracusa |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | Dynamic and Application-Aware Provisioning of Chained Virtual Security Network FunctionsabstractA promising area of application for Network Function Virtualization (NFV) is in network security, where chains of Virtual Security Network Functions (VSNFs), i.e., security-specific virtual functions such as firewalls or Intrusion Prevention Systems, can be dynamically created and configured to inspect, filter or monitor the network traffic. However, the traffic handled by VSNFs could be sensitive to specific network requirements, such as minimum bandwidth or maximum end-to-end latency. Therefore, the decision on which VSNFs should apply for a given application, where to place them and how to connect them, should take such requirements into consideration. Otherwise, security services could affect the quality of service experienced by customers. In this paper, we propose PESS (Progressive Embedding of Security Services), a solution to efficiently deploy chains of virtualised security functions based on the security requirements of individual applications and operators' policies, while optimizing resource utilization. We provide the PESS mathematical model and heuristic solution. Simulation results show that, compared to state-of-the-art application-agnostic VSNF provisioning models, PESS reduces computational resource utilization by up to 50%, in different network scenarios. This result ultimately leads to a higher number of provisioned security services and to up to a 40% reduction in end-to-end latency of application traffic. Roberto Doriguzzi Corin, Sandra Scott-Hayward, Domenico Siracusa, Marco Savi, Elio Salvadori |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2019 | SODA: A software-defined security framework for IoT environments
Yeonkeun Kim, Jaehyun Nam, Taejune Park, Sandra Scott-Hayward, Seungwon Shin 0001 |
Comput. Networks | 4 |
| 2018 | Tennison: A Distributed SDN Framework for Scalable Network SecurityabstractDespite the relative maturity of the Internet, the computer networks of today are still susceptible to attack. The necessary distributed nature of networks for wide area connectivity has traditionally led to high cost and complexity in designing and implementing secure networks. With the introduction of software-defined networks (SDNs) and network functions virtualization, there are opportunities for efficient network threat detection and protection. SDN's global view provides a means of monitoring and defense across the entire network. However, current SDN-based security systems are limited by a centralized framework that introduces significant control plane overhead, leading to the saturation of vital control links. In this paper, we introduce TENNISON, a novel distributed SDN security framework that combines the efficiency of SDN control and monitoring with the resilience and scalability of a distributed system. TENNISON offers effective and proportionate monitoring and remediation, compatibility with widely available networking hardware, support for legacy networks, and a modular and extensible distributed design. We demonstrate the effectiveness and capabilities of the TENNISON framework through the use of four attack scenarios. These highlight multiple levels of monitoring, rapid detection, and remediation, and provide a unique insight into the impact of multiple controllers on network attack detection at scale. Lyndon Fawcett, Sandra Scott-Hayward, Matthew Broadbent, Andrew Wright, Nicholas J. P. Race |
IEEE J. Sel. Areas Commun. | 2 |
| 2018 | Guest Editors' Introduction: Special Section on Novel Techniques for Managing Softwarized NetworksabstractThe softwarization of networks is enabled by the SDN (Software-Defined Networking), NV (Network Virtualization), and NFV (Network Function Virtualization) paradigms, and offers many advantages for network operators, service providers and datacenter providers. Given the strong interest in both industry and academia in the softwarization of telecommunication networks and cloud computing infrastructures, a series of special section was established in IEEE Transactions on Network and Service Management, which aims at the timely publication of recent innovative research results on management of softwarized networks. Wolfgang Kellerer, Raouf Boutaba, Prosper Chemouil, Rafael Pasquini, Giovanni Schembra, Stefan Schmid 0001, Sandra Scott-Hayward, Kohei Shiomoto |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2014 | Optimized packet classification for Software-Defined NetworkingabstractRecent trends, such as Software-Defined Networking (SDN), introduce programmability to the network with the opportunity to dynamically route traffic based on flow descriptions. Packet header lookup is the first phase in this process. In this paper, we illustrate improved header lookup and flow rule update speeds over conventional lookup algorithms. This is achieved by performing individual packet header field searches and combining the search results. We propose that individual algorithms should be selected for packet classification based on the application requirements. Improving the network processing performance with our configurable solution will directly support the proposed capability of programmability in SDN. K. Guerra Perez, Xin Yang 0010, Sandra Scott-Hayward, Sakir Sezer |
ICC | 3 |
| 2014 | OperationCheckpoint: SDN Application ControlabstractOne of the core properties of Software Defined Networking (SDN) is the ability for third parties to develop network applications. This introduces increased potential for innovation in networking from performance-enhanced to energy-efficient designs. In SDN, the application connects with the network via the SDN controller. A specific concern relating to this communication channel is whether an application can be trusted or not. For example, what information about the network state is gathered by the application? Is this information necessary for the application to execute or is it gathered for malicious intent? In this paper we present an approach to secure the northbound interface by introducing a permissions system that ensures that controller operations are available to trusted applications only. Implementation of this permissions system with our Operation Checkpoint adds negligible overhead and illustrates successful defense against unauthorized control function access attempts. Sandra Scott-Hayward, Christopher Kane, Sakir Sezer |
ICNP | 1 |
| 2014 | Utility-based resource allocation for real-time IPTV in wireless networksabstractInternet Protocol Television (IPTV) is a key growth application for Internet traffic. The combination of real-time services such as video and voice along with best effort Internet access introduces challenging Quality of Service (QoS) issues. In order to meet the QoS requirements, smart resource allocation is required, in particular for IPTV provision across wireless networks. In existing research, IPTV is generally described as a video application. This supports the high bandwidth characteristic of IPTV but not the low latency requirement of realtime transmission. In this work, we present a real-time IPTV utility function describing the application with respect to the stage of transmission. This accurately represents IPTV with high bandwidth, low latency characteristics. The function describes the relationship between allocated channel time and the user perceived quality of the transmission. In an example wireless networking scenario, the resource allocation solution illustrates accurate prioritization in accordance with the individual user requirements. Sandra Scott-Hayward, Emi Garcia-Palacios |
WCNC | 1 |
| 2014 | Channel Time Allocation PSO for Gigabit Multimedia Wireless NetworksabstractThis article introduces a resource allocation solution capable of handling mixed media applications within the constraints of a 60 GHz wireless network. The challenges of multimedia wireless transmission include high bandwidth requirements, delay intolerance and wireless channel availability. A new Channel Time Allocation Particle Swarm Optimization (CTA-PSO) is proposed to solve the network utility maximization (NUM) resource allocation problem. CTA-PSO optimizes the time allocated to each device in the network in order to maximize the Quality of Service (QoS) experienced by each user. CTA-PSO introduces network-linked swarm size, an increased diversity function and a learning method based on the personal best, Pbest, results of the swarm. These additional developments to the PSO produce improved convergence speed with respect to Adaptive PSO while maintaining the QoS improvement of the NUM. Specifically, CTA-PSO supports applications described by both convex and non-convex utility functions. The multimedia resource allocation solution presented in this article provides a practical solution for real-time wireless networks. Sandra Scott-Hayward, Emi Garcia-Palacios |
IEEE Trans. Multim. | 1 |
| 2011 | High definition video in IEEE 802.15.3c mm-Wave wireless personal area networksabstractMultimedia applications place high demands on resources in wireless networks. The 60 GHz frequency band has been adopted to support high data rate applications in wireless personal area networks (WPANs). In the IEEE 802.15.3c standard for millimeter-wave-based high-rate WPANs, devices are allocated a dedicated transmission time called a CTA (channel time allocation) based on their request to transmit. While the duration of a CTA may be adjusted, the standard does not specify how resource allocation should be achieved. High-Definition (HD) video with variable bit rate (VBR) is a potential application for the WPAN. In this work, an IEEE 802.15.3c network is simulated and the throughput losses due to static resource provisioning for a series of H.264/SVC (MPEG-4 Part 10) HD video sources are identified. It is demonstrated that the high data rates proposed for the 60 GHz frequency band will not be achieved without dynamic resource allocation. Sandra Scott-Hayward, Emi Garcia-Palacios |
LCN | 1 |