CO-STOP: A Robust P4-Powered Adaptive Framework for Comprehensive Detection and Mitigation of Coordinated and Multi-Faceted Attacks in SD-IoT Networks

Faculty Computer Science Year: 2025
Type of Publication: ZU Hosted Pages:
Authors:
Journal: Computers & Security Elsevier Ltd Volume: 151
Keywords : CO-STOP: , Robust P4-Powered Adaptive Framework , Comprehensive    
Abstract:
The increasing sophistication of multi-faceted attacks (MFAs) presents significant challenges for securing Internet of Things (IoT) networks, where traditional defenses and even contemporary solutions often fail to provide comprehensive protection. Current frameworks in the literature face critical limitations such as centralized control architectures that are prone to bottlenecks and single points of failure, inadequate traffic monitoring capabilities, and limited adaptability to dynamic attack surfaces. These gaps make IoT environments vulnerable to stealthy, coordinated, and complex attacks that can simultaneously target multiple layers of the network. Addressing these challenges requires a more dynamic and distributed approach to security. This paper introduces CO-STOP, an innovative framework designed to overcome these limitations by integrating machine learning (ML), the P4 programming language, Software-Defined Networking (SDN), and a novel multi-control design (MCD). CO-STOP enhances IoT network management by distributing both detection and mitigation efforts across multiple controllers, improving scalability and resilience. It also addresses the shortcomings of existing solutions by incorporating adaptive traffic monitoring and a distributed mitigation strategy that reduces the risks of network disruption. The framework comprises four interconnected modules: (1) Authenticated Dynamic Multi-Control (ADMC), which introduces secure, synchronized controller collaboration; (2) P4-Enabled Adaptive Traffic Monitoring (P4-ATM), leveraging programmable state tables for real-time traffic analysis; (3) Multi-Faceted Attack Detection and Prevention (MFADP), employing a Dynamic Meta-Ensemble with Confidence-Based Prioritization (DMECP) for accurate attack detection; and (4) P4-Enabled Multi-Control Adaptive Mitigation (P4-MCAM), which distributes mitigation efforts across multiple controllers. CO-STOP demonstrates significant resource efficiency, with the P4-based solution reducing bandwidth consumption by 27%, memory usage by 19%, and CPU utilization by 21% compared to the OpenFlow-based approach. Experiments reveal that the proposed multi-controller architecture consistently outperforms the single-controller design across six key evaluation metrics. CO-STOP sets new benchmarks in SD-IoT security, achieving 99.25% accuracy, a 98.83% F1-score, and a low false positive rate of 0.51%. By addressing both the limitations of existing frameworks and the critical need for scalable, efficient, and adaptive security solutions, CO-STOP represents a substantial advancement in safeguarding SD-IoT networks from emerging attacks.
   
     
 
       

Author Related Publications

  • Wael Said AbdelMageed Mohamed, "A big data approach to sentiment analysis using greedy feature selection with cat swarm optimization-based long short-term memory neural networks", Springer Nature, 2018 More
  • Wael Said AbdelMageed Mohamed, "High-Precision Brain Tumor Diagnosis Using SECNN-MNet Framework and Explainable AI", Springer Nature Link, 2025 More
  • Wael Said AbdelMageed Mohamed, "Deception and cloud integration: A multi-layered approach for DDoS detection, mitigation, and attack surface minimization in SD-IoT networks", .Elsevier Ltd, 2025 More
  • Wael Said AbdelMageed Mohamed, "Reinforcement Learning for Industrial Automation: A Comprehensive Review of Adaptive Control and Decision-Making in Smart Factories", MDPI, 2025 More
  • Wael Said AbdelMageed Mohamed, "RAUM-GANs: A Multi-Layer GAN-Enhanced Framework for Accurate Multiple Sclerosis Lesion Segmentation in MRI", Nature Portfolio, 2025 More

Department Related Publications

  • Ahmed Salah Mohamed Mostafa, "Cluster-Distribute-Align-Merge: A General Algorithm to Speed Up Multiple Sequence Alignment on Multi-Core Computers", Journal of Computational and Theoretical Nanoscience, 2014 More
  • Zaher Awad Aboelenieen Elhendy, "NEW APPROACH TO IMAGE EDGE DETECTION BASED ON QUANTUM ENTROPY", JOURNAL OF RUSSIAN LASER RESEARCH, 2016 More
  • Sarah AbdelRazek Ahmed AbdulHameid, "Cloud Storage Forensics: Survey", International Journal of Engineering Trends and Technology (IJETT), 2017 More
  • Doaa El-Shahat Barakat Mohammed, "A modified hybrid whale optimization algorithm for the scheduling problem in multimedia data objects", Wiley online library, 2019 More
  • Abdallah Gamal abdallah mahmoud, "A novel model for evaluation Hospital medical care systems based on plithogenic sets", Elsevier B.V., 2019 More
Tweet