Sentry: An Adaptive Countermeasure against Low-Volume Denial-of-Service Attacks
Abstract
Static machine learning algorithms render intrusion detection systems ineffective in dynamic environments, as these systems remain constrained to the data patterns observed during the training phase. This paper proposes Sentry, an adaptive countermeasure based on the Online Isolation Forest algorithm, aimed at identifying low-rate denial-of-service attacks in software-defined networks. Sentry performs continuous updates and incorporates selective criteria conditioned on the network state, preventing improper learning during attack periods and reducing the risk of model contamination. The experimental evaluation demonstrates that Sentry outperforms both the Online Isolation Forest with unrestricted updates and XGBoost. Sentry achieves recall and F1-score metrics of up to 98.89% and 98.53%, respectively. In contrast, XGBoost and Online Isolation Forest exhibit a sharp degradation in performance, with recall dropping to 17.95% and 10.50%, respectively.
References
Alashhab, A. A., Zahid, M. S. M., Alashhab, M., and Alashhab, S. (2023). Online machine learning approach to detect and mitigate low-rate ddos attacks in sdn-based networks. In 2023 IEEE International Conference on Artificial Intelligence in Engineering and Technology (IICAIET), pages 1–6, Kota Kinabalu, Malaysia. IEEE.
Camarda, S., Musumeci, F., and Torre, G. (2025). Managing concept drift in online intrusion detection systems. Joint National Conference on Cybersecurity.
Chen, T. and Guestrin, C. (2016). Xgboost: A scalable tree boosting system. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pages 785–794, New York, NY, USA. ACM.
dos Santos, B. M., Bastos, I. V., and Moraes, I. M. (2026). Degradação de desempenho de contramedidas estáticas a ataques de negação de serviço de baixo volume. In Anais do XLIV Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos (SBRC), Brasil. Sociedade Brasileira de Computação (SBC).
Fu, Z., Li, M., Wu, Y., and Liu, Q. (2022). Low-rate denial of service attack detection method based on time-frequency characteristics. Journal of Cloud Computing, 11.
Gama, J., Žliobait schoole, I., Bifet, A., Pechenizkiy, M., and Bouchachia, A. (2014). A survey on concept drift adaptation. ACM Computing Surveys (CSUR), 46(4):1–37.
Knight, S., Nguyen, H. X., Falkner, N., Bowden, R., and Roughan, M. (2011). Internet topology zoo. IEEE Journal on Selected Areas in Communications, 29(9):1765–1775.
Leveni, F. and Boracchi, G. (2025). Online isolation forest. In Proceedings of the 41st International Conference on Machine Learning (ICML), volume 235 of Proceedings of Machine Learning Research, pages 26858–26876. PMLR.
Liu, B., Tang, D., Chen, J., and Liang, W. (2024). ERT-EDR: Online defense framework for TCP-targeted LDoS attacks in SDN. Expert Systems with Applications, 254:124356.
Ma, X., Li, X., He, Y., Qi, Q., and Li, H. (2025). BDTM: Bidirectional detection and traceability mitigation of LDoS attacks in SDN. IEEE Transactions on Network and Service Management, 20:6826 – 6839.
Mathew, R. R. and Vidhate, A. (2024). Adaptive dos attack detection in sdn. In Proceedings of the 2024 International Conference on Emerging Smart Computing and Informatics (ESCI). IEEE.
Montgomery, D. C. and Runger, G. C. (2018). Applied Statistics and Probability for Engineers. John Wiley & Sons, 7th edition.
Pandiyakumari S, H. and Suganya R, D. (2025). Adaptive detection of low-rate denial-of-service attacks: A machine learning and reinforcement learning perspective. In Proceedings of the 2025 6th International Conference on Communication, Computing & Industry 6.0 (C2I6). IEEE.
Pérez-Díaz, J. A., Valdovinos, I. A., Choo, K.-K. R., and Zhu, D. (2020). A flexible SDN-based architecture for identifying and mitigating low-rate DDoS attacks using machine learning. IEEE Access, 8:155859–155872.
Rios, V. M., Inácio, P. R. M., and Maimó, D. (2022). Detection and mitigation of low-rate denial-of-service attacks: A survey. IEEE Access, 10:76648–76668.
Rong, X., Wang, S., Guo, C., and Tao, X. (2024). Adaptive weight xgboost: Detecting and mitigating low-rate dos attack in network slicing. In Proceedings of the 2024 IEEE Wireless Communications and Networking Conference (WCNC). IEEE.
Shyaa, W., Gharaibeh, H., and Rawashdeh, M. (2024). Evolving cybersecurity frontiers: A comprehensive survey on concept drift and feature dynamics-aware machine learning and deep learning in intrusion detection systems. Engineering Applications of Artificial Intelligence.
Tang, D., Yan, Y., Zhang, S., Chen, J., and Qin, Z. (2022). Performance and features: Mitigating the low-rate TCP-targeted DoS attack via SDN. IEEE Journal on Selected Areas in Communications, 40:428 – 444.
Tang, D., Yan, Y., Zhang, S., Chen, J., and Qin, Z. (2025). Trident: A low-rate DoS attack mitigation scheme based on port and traffic state in SDN. IEEE Transactions on Computers, 74:1758–1770.
Wahab, O. A. (2022). Intrusion detection in the IoT under data and concept drifts: Online deep learning approach. IEEE Internet of Things Journal, 9(20):19706 – 19716.
Yoachimik, O. and Pacheco, J. (2026). 2025 q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults. Technical report, Cloudflare. Disponível em [link].
