Related Experiment Video
Updated: Jan 9, 2026

Automated Deployment of an Internet Protocol Telephony Service on Unmanned Aerial Vehicles Using Network Functions Virtualization
Published on: November 26, 2019
SFARP: a multi-layered real-time security framework for hybrid ARP and DDoS attack defense in SD-IoT networks
Ameer El-Sayed1, Hagar Ramadan2, Ehab R Mohamed2
1Department of Information Technology, Faculty of Computers and Informatics, Zagazig University, Zagazig, 44511, Egypt. aegouda@fci.zu.edu.eg.
This study introduces SFARP, a novel security framework for Software-Defined Internet of Things (SD-IoT) networks, effectively detecting and mitigating sophisticated multi-vector cyberattacks in real-time. SFARP enhances network defense against evolving threats.
Area of Science:
- Cybersecurity
- Network Security
- Internet of Things (IoT)
Background:
- Software-Defined Internet of Things (SD-IoT) networks face escalating vulnerabilities due to rapid expansion and sophisticated multi-vector attacks (e.g., DDoS, ARP spoofing).
- Existing defenses are often bypassed by adaptive, sequential, and hybrid attack behaviors exploiting static control planes and centralized architectures.
- There is a critical need for real-time, scalable, and adaptive security solutions tailored for the unique challenges of SD-IoT environments.
Purpose of the Study:
- To propose and evaluate SFARP, a multi-layered real-time security framework designed to enhance the resilience of SD-IoT networks against advanced cyber threats.
- To demonstrate the framework's capability in detecting and mitigating a wide range of attacks, including hybrid and multi-vector scenarios.
- To assess the hardware feasibility and scalability of the proposed solution for practical deployment in carrier-grade IoT infrastructures.
Main Methods:
- SFARP integrates three modules: Dynamic Flow Analysis Module (DFAM) for feature extraction using P4-programmed switches, Adaptive Dynamic Flow Detection System (ADFDS) employing machine learning classifiers for anomaly detection, and Distributed Adaptive Mitigation System (DAMS) for coordinated defense.
- The framework was evaluated against twelve complex attack scenarios, including hybrid, adaptive, mimicry, and sequential attacks, using five real-world IoT datasets (CICIoMT2024, CICIoT2023, IoTID20, Edge-IIoTset, TON_IoT).
- Hardware feasibility was assessed on NetFPGA and Tofino ASIC, alongside system-level performance metrics like controller CPU usage, packet loss, and detection latency.
Main Results:
- SFARP demonstrated superior performance, with ADFDS achieving up to 98.3% accuracy and a 2.3% False Alarm Rate (FAR) on the CICIoMT2024 dataset, outperforming state-of-the-art models on CICIoT2023.
- System-level benefits included over 70% reduction in controller CPU usage, 90% decrease in packet loss, and end-to-end detection latency under 50 ms, even during high-volume attacks.
- Hardware evaluations confirmed carrier-grade scalability, supporting over 250k concurrent flows with minimal memory overhead, validating the practical feasibility of SFARP.
Conclusions:
- SFARP offers a scalable, hardware-feasible, and effective solution for real-time defense of SD-IoT infrastructures against evolving hybrid and multi-layer attacks.
- The integration of programmable data-plane telemetry, adaptive ML-driven detection, and distributed mitigation provides a robust security posture for heterogeneous IoT deployments.
- This framework represents a significant advancement in securing critical IoT ecosystems against increasingly sophisticated cyber threats.
Related Concept Videos
Radial System Protection
In a radial system with a fault downstream of the third breaker, ideally, only the third breaker will open, isolating the fault and interrupting the load connected beyond it. The second breaker has a longer delay setting,...
Zones of Protection
Protective zones are defined by closed dashed lines, containing one or more components. A key characteristic of these zones is the strategic placement of...
Masking and Demasking Agents
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
Network Function of a Circuit
Line Protection with Impedance Relays
Under normal conditions, low load currents keep the measured...
Fast Decoupled and DC Powerflow