2019/07/27 by Trung V. Phan, Phan, Trung V., T M Rayhan Gias +9
Computer Science · Engineering · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Network Security and Intrusion Detection #Networking and Internet Architecture (cs.NI) #Smart Grid Security and Resilience #Software-Defined Networks and 5G
paper · pdf · doi:10.48550/arxiv.1907.11887
openalex publication_date 2019/07/27 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Software Defined Networking (SDN) enables flexible and scalable network\ncontrol and management. However, it also introduces new vulnerabilities that\ncan be exploited by attackers. In particular, low-rate and slow or stealthy\nDenial-of-Service (DoS) attacks are recently attracting attention from\nresearchers because of their detection challenges. In this paper, we propose a\nnovel machine learning based defense framework named Q-MIND, to effectively\ndetect and mitigate stealthy DoS attacks in SDN-based networks. We first\nanalyze the adversary model of stealthy DoS attacks, the related\nvulnerabilities in SDN-based networks and the key characteristics of stealthy\nDoS attacks. Next, we describe and analyze an anomaly detection system that\nuses a Reinforcement Learning-based approach based on Q-Learning in order to\nmaximize its detection performance. Finally, we outline the complete Q-MIND\ndefense framework that incorporates the optimal policy derived from the\nQ-Learning agent to efficiently defeat stealthy DoS attacks in SDN-based\nnetworks. An extensive comparison of the Q-MIND framework and currently\nexisting methods shows that significant improvements in attack detection and\nmitigation performance are obtained by Q-MIND.\n