<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CSSE</journal-id>
<journal-id journal-id-type="nlm-ta">CSSE</journal-id>
<journal-id journal-id-type="publisher-id">CSSE</journal-id>
<journal-title-group>
<journal-title>Computer Systems Science &#x0026; Engineering</journal-title>
</journal-title-group>
<issn pub-type="ppub">0267-6192</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">58327</article-id>
<article-id pub-id-type="doi">10.32604/csse.2024.058327</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>An Intelligent Security Service Optimization Method Based on Knowledge Base</article-title>
<alt-title alt-title-type="left-running-head">An Intelligent Security Service Optimization Method Based on Knowledge Base</alt-title>
<alt-title alt-title-type="right-running-head">An Intelligent Security Service Optimization Method Based on Knowledge Base</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Gao</surname><given-names>Xianju</given-names></name><email>22120052 @bjtu.edu.cn</email></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Zhou</surname><given-names>Huachun</given-names></name></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Wang</surname><given-names>Weilin</given-names></name></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Yan</surname><given-names>Jingfu</given-names></name></contrib>
<aff>
<institution>School of Electronic and Information Engineering, Beijing Jiaotong University</institution>, <addr-line>Beijing, 100044</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Xianju Gao. Email: <email>22120052 @bjtu.edu.cn</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>03</day><month>01</month><year>2025</year>
</pub-date>
<volume>49</volume>
<issue>1</issue>
<fpage>19</fpage>
<lpage>48</lpage>
<history>
<date date-type="received">
<day>10</day>
<month>9</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>28</day>
<month>10</month>
<year>2024</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CSSE_58327.pdf"></self-uri>
<abstract>
<p>The network security knowledge base standardizes and integrates network security data, providing a reliable foundation for real-time network security protection solutions. However, current research on network security knowledge bases mainly focuses on their construction, while the potential to optimize intelligent security services for real-time network security protection requires further exploration. Therefore, how to effectively utilize the vast amount of historical knowledge in the field of network security and establish a feedback mechanism to update it in real time, thereby enhancing the detection capability of security services against malicious traffic, has become an important issue. Our contribution is fourfold. First, we design a feedback interface to update the knowledge base with information such as features of attack traffic, detection outcomes from network service functions (NSF), and system resource utilization. Second, we introduce a feature selection method that combines PageRank and RandomForest to identify influential features in the knowledge base and dynamically incorporate them into the NSFs. Third, we propose a path selection method that combines graph attention network (GAT) and deep reinforcement learning (DRL) to learn the local knowledge of the knowledge base and determine the optimal traffic path within the Service Function Chains (SFC). Finally, experimental results demonstrate that the knowledge base can be updated in real time according to feedback information, and the optimized service achieves an accuracy, recall, and F1 score exceeding 96%. Compared to preset paths and paths selected using the deep Q-network (DQN) method, our proposed method increases the malicious traffic detection rate by an average of 12.4% and 4.6%, respectively, enhances the total malicious traffic detection capability (TMTDC) of the path by 18.1% and 11.5%, and significantly reduces path detection delay. It has been verified that the proposed intelligent security optimization method can monitor malicious traffic in real time, update knowledge, and enhance the system&#x2019;s detection capability against malicious traffic.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Network security knowledge base</kwd>
<kwd>feature selection</kwd>
<kwd>path selection</kwd>
<kwd>knowledge feedback</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>National Key R&#x0026;D Program of China</funding-source>
<award-id>2018YFA0701604</award-id>
</award-group>
<award-group id="awg2">
<funding-source>NSFC</funding-source>
<award-id>62341102</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>With the rapid growth of the Internet&#x2019;s scale and the emergence of new technologies like the Internet of Things and cloud computing, the landscape of network security faces increasingly blurred boundaries. Traditional network security systems struggle to combat the continuous stream of network threats effectively. In response, researchers have increasingly turned to integrating artificial intelligence algorithms with security services [<xref ref-type="bibr" rid="ref-1">1</xref>], aiming to automate the detection of abnormal traffic. These intelligent network service functions (NSF) are typically delivered to users in the form of Service Function Chains (SFC) [<xref ref-type="bibr" rid="ref-2">2</xref>]. However, attackers continuously update their attack strategies to make the traffic features resemble normal traffic more closely to evade detection. Most existing intelligent security service methods are inflexible and lack dynamic adaptability to changes in the network [<xref ref-type="bibr" rid="ref-3">3</xref>].</p>
<p>The advent of the network security knowledge base standardizes and integrates network security data, enabling continuous storage and updates of information on malicious traffic across highly interconnected terminals. This capability forms a dependable foundation for developing real-time network security protection solutions [<xref ref-type="bibr" rid="ref-4">4</xref>]. The network security knowledge base stores information in the form of knowledge graphs, which depict relationships between entities as a graph. This method serves as a semantic network, offering efficient query and display features, flexible storage, and update capabilities.</p>
<p>However, current research on network security knowledge bases mainly focuses on their construction, while the potential to optimize intelligent security services for real-time network security protection requires further exploration. Therefore, we propose an optimization method of intelligent security services based on the network security knowledge base that solves the three challenges described in the following paragraphs.</p>
<p>The first challenge is how to update the information on malicious traffic in the knowledge base in real-time. To address this, we design a feedback interface that sends information on malicious traffic, including attack traffic features, detection outcomes from NSFs, and system resource utilization, back to the knowledge base for continuous updates.</p>
<p>The second challenge is how to select the features of malicious traffic from the knowledge base for detection. We use a feature selection method that combines PageRank and RandomForest for feature selection. PageRank is used for effective knowledge inference and feature selection in the knowledge graph, while RandomForest is used for selecting information from the feature datasets.</p>
<p>The third challenge is how to select the path of traffic through the SFC using the information in the knowledge base. We use the graph attention network (GAT) to optimize deep reinforcement learning (DRL) to select an optimum detection path. GAT utilizes an attention mechanism, allowing the model to better capture the relational and feature information between data, enabling deep analysis and mining of the data. DRL allows agents to explore the environment and learn from experience without human heuristics.</p>
<p>In this work, our main contributions are as follows:
<list list-type="order">
<list-item>
<p>We design a feedback interface to update the knowledge base with information such as attack traffic features, detection outcomes from NSFs, and system resource utilization. This interface also dynamically adjusts the traffic path through the SFC.</p></list-item>
<list-item>
<p>We introduce a feature selection method that combines PageRank and RandomForest, identifying influential features in the knowledge base and dynamically incorporating them into the NSFs to improve their detection capability.</p></list-item>
<list-item>
<p>We propose a path selection method that combines GAT and DRL, enabling the system to learn the local knowledge from the knowledge base and determine the optimal traffic path within the SFC.</p></list-item>
<list-item>
<p>In the experimental environment, we performed offline training and online detection, systematically comparing the performance across different schemes. The results demonstrate that the optimization method of intelligent security services based on the network security knowledge base in this paper can significantly improve the detection performance and reduce path detection delay.</p></list-item>
</list></p>
<p>The remainder of the paper is organized as follows: <xref ref-type="sec" rid="s2">Section 2</xref> introduces the related work. <xref ref-type="sec" rid="s3">Section 3</xref> describes the intelligent security services optimization method. <xref ref-type="sec" rid="s4">Section 4</xref> presents the experimental environment and results. <xref ref-type="sec" rid="s5">Section 5</xref> concludes this paper.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Works</title>
<p>The network security knowledge base contains all kinds of malicious traffic information in the network, which can be used as a valuable data source for security incident analysis and provide a reliable defense scheme for the network system. Many researches at home and abroad focus on the network security knowledge base and intelligent security services.</p>
<p>The knowledge base can display data in the form of knowledge graphs. As specific knowledge graphs in the security field, network security knowledge graphs consist of nodes and edges to form a large-scale security semantic network. This provides an intuitive modeling method for various attack and defense scenarios in the real security world. To describe the Distributed Denial of Service (DDoS) attacks comprehensively, Reference [<xref ref-type="bibr" rid="ref-5">5</xref>] constructed a malicious behavior knowledge base of DDoS attacks, which consists of a malicious traffic detection knowledge base and a network security knowledge base. The former is responsible for detecting and classifying malicious traffic generated by DDoS attacks. The network security knowledge base is responsible for data structure processing, malicious behavior knowledge graph creation, and behavior reasoning. Reference [<xref ref-type="bibr" rid="ref-6">6</xref>] established a knowledge base, which mainly includes two parts: knowledge construction and knowledge display. Knowledge construction is responsible for extracting knowledge from structured data sources and unstructured texts, and knowledge display is mainly responsible for the visualization function of network security knowledge. Reference [<xref ref-type="bibr" rid="ref-7">7</xref>] proposed a malicious behavior knowledge base construction model based on a five-element model. First, entities are extracted and constructed by the machine learning method to acquire network security knowledge, and the NER method is used to complete the knowledge extraction method in the field of network security.</p>
<p>In the field of intelligent security services, data transmission over wireless channels necessitates essential security measures to prevent attackers from eavesdropping or manipulating information. In this regard, Reference [<xref ref-type="bibr" rid="ref-8">8</xref>] proposed a key management protocol that uses three auxiliary keys along with a master key to encrypt information at three different levels within the network. Additionally, the detection and defense against DDoS attacks have been a persistent challenge in the realm of network security.</p>
<p>Feature selection is a key aspect for improving the performance of DDoS attacks detection. The existing attack detection work has the following representative works in feature selection. Reference [<xref ref-type="bibr" rid="ref-9">9</xref>] obtained a typical botnet feature set by Boruta feature selection method, but a single feature selection algorithm can&#x2019;t fully mine the correlation between data features and prediction results, which may lead to insufficient feature expression ability and affect the online detection performance. Reference [<xref ref-type="bibr" rid="ref-10">10</xref>] combined various feature selection algorithms, the features selected by three or more feature selection algorithms are important features. The features selected by only two feature selection algorithms are the second most important features. The remaining features form an unimportant feature set. Reference [<xref ref-type="bibr" rid="ref-11">11</xref>] used Pearson moment correlation to analyze the correlation between features and category labels, and used the area under the curve (AUC) measurement to measure the importance of each feature. Only the first five features are used and good results are obtained. Reference [<xref ref-type="bibr" rid="ref-12">12</xref>] proposed a method called RFUTE based on RandomForest, to deal with the problem of feature selection in Phase Locked Loop (PLL). Firstly, the ambiguity of candidate tags is eliminated, and then the feature selection is carried out by calculating and ranking the total changes of information entropy of all features of all trees in the forest. PageRank, the web ranking algorithm, was created and applied by Google, mainly to evaluate the importance of each node in the network. It is widely used in the network, such as friend recommendations [<xref ref-type="bibr" rid="ref-13">13</xref>], web search [<xref ref-type="bibr" rid="ref-14">14</xref>], and link analysis [<xref ref-type="bibr" rid="ref-15">15</xref>]. However, it has yet to be applied in the field of feature selection.</p>
<p>SFC path selection aims to provide users with high-speed and low-delay diversified network function customization services, which is another key aspect of improving detection performance. Reference [<xref ref-type="bibr" rid="ref-16">16</xref>] proposed an algorithm for constructing the SFC based on a graph neural network. The algorithm uses the representation of nodes in the graph neural network to construct a flexible and efficient SFC under the influence of its neighboring nodes. Reference [<xref ref-type="bibr" rid="ref-17">17</xref>] proposed a dynamic arrangement framework of SFC for DRL of the Internet of Things to solve the problem of optimizing the deployment of Virtual Network Functions (VNF) and service path with end-to-end delay in the edge cloud. Reference [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed a deep Q-network (DQN) path selection method for security SFC. However, its accuracy in detecting malicious traffic needs improvement, and the detection latency needs to be reduced. Reference [<xref ref-type="bibr" rid="ref-19">19</xref>] combined DQN with convolutional neural network (CNN), and proposed an SFC path selection algorithm. The algorithm adopts the CNN approximate Q function of state-action pair, which can extract data features with the convolution layer and pooling layer and provide automatic learning from the data structure. Aiming at the dense cellular network scene with network slices on multiple base stations, Reference [<xref ref-type="bibr" rid="ref-20">20</xref>] combined the GAT with DRL and designed an intelligent real-time inter-chip resource management strategy to cope with frequent base station handovers and meet the fluctuation of different service requirements.</p>
<p>The relevant literature indicates several key issues in current research on knowledge bases and intelligent security services. First, most studies on the network security knowledge base focus primarily on their construction, leaving the potential for optimizing intelligent security services to enable real-time network security protection largely unexplored. Second, the current feature selection methods, which rely solely on feature engineering algorithms like RandomForest, fail to fully capture the importance of data features, resulting in insufficient representation of malicious behavior traits. Moreover, while GAT can capture relational information between data for deep analysis and data mining, and DRL can enhance adaptability in SFC path selection, there is currently no research that integrates these two approaches in the context of SFC path selection.</p>
<p>These gaps have inspired the development of the proposed method, which leverages the rich data resources in knowledge bases to optimize intelligent security services. It combines graph-based feature selection methods called PageRank with traditional feature engineering techniques to more effectively uncover attack features. Additionally, the integration of GAT and DRL into SFC path selection is introduced to enhance the efficiency of SFC path selection, aiming to detect various types of malicious attacks, improve detection accuracy, and reduce detection latency, thereby offering strong practical value.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Intelligent Security Service Optimization Method</title>
<p>We propose an intelligent security service framework and divide it into four modules according to their functions. <xref ref-type="sec" rid="s3_1">Section 3.1</xref> provides an overview of the entire framework. <xref ref-type="sec" rid="s3_2">Section 3.2</xref> delves into the specifics of the data feedback module. <xref ref-type="sec" rid="s3_3">Section 3.3</xref> elaborates on the composition of the knowledge base module. <xref ref-type="sec" rid="s3_4">Section 3.4</xref> details the implementation of the NSF feature selection module and the SFC path selection module.</p>
<sec id="s3_1">
<label>3.1</label>
<title>Framework</title>
<p>The Intelligent security service framework introduced in this study is illustrated in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>, encompassing four key modules: the data feedback module, knowledge base module, security policy reasoning module, and service function module.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Intelligent security service framework</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-1.tif"/>
</fig>
<p>The main function of the data feedback module is to periodically collect feedback data from various NSFs, store it in the knowledge base, and update the knowledge base to guide the reasoning of security policies. The collected data includes the packet-level features of network traffic entering the SFC, malicious traffic detection outcomes of various NSFs, and system resource utilization.</p>
<p>The knowledge base module consists of the malicious behavior knowledge base, malicious traffic detection knowledge base, and resource usage knowledge base. The malicious behavior knowledge base mainly includes flow-level feature datasets and packet-level feature datasets of DDoS attacks, as well as a malicious behavior feature graph. The malicious traffic detection knowledge base stores detection results from the service function module, such as accuracy, malicious traffic detection rate, detection capability, and detection time. The resource usage knowledge base tracks system resource utilization of the service function module, including CPU usage rate, memory usage rate, disk usage rate, packet loss rate, etc.</p>
<p>The security policy reasoning module consists of an NSF feature selection module and an SFC path selection module. Using the knowledge stored in the knowledge base, we design algorithms to dynamically adjust the NSFs that the traffic needs to pass through.</p>
<p>The service function module virtualizes the malicious traffic detection methods into NSFs, including the Network layer DDoS (NetDDoS) detection module [<xref ref-type="bibr" rid="ref-21">21</xref>], Application layer DDoS (AppDDoS) detection module [<xref ref-type="bibr" rid="ref-22">22</xref>], Botnet detection module [<xref ref-type="bibr" rid="ref-10">10</xref>], Low-rate DoS (LDDoS) detection module [<xref ref-type="bibr" rid="ref-23">23</xref>], Distributed Reflection Dos (DRDoS) detection module [<xref ref-type="bibr" rid="ref-24">24</xref>] and firewall. Detection methods are combined to form the detection path of SFC, and different detection paths have different effects on security performance.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Data Feedback Module</title>
<p>The data feedback module is responsible for collecting the packet-level features of network traffic entering the SFC, malicious traffic detection outcomes of various NSFs, and system resource utilization. This information is fed back to the knowledge base in real time, enabling dynamically adjustments to the traffic path through the SFC. The flow chart is shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Data feedback diagram</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-2.tif"/>
</fig>
<p>We capture DDoS attack traffic entering the SFC with the Tcpdump data packet capture tool at the ingress classifier. This traffic is saved as pcap files, which are then parsed using a Python script to extract packet-level features. These features are saved as Comma Separated Values (CSV) files and fed back to the malicious behavior knowledge base via an interface established using the Network Configuration (NETCONF) protocol. In this step, the malicious behavior knowledge base acts as the client, while the ingress classifier, responsible for extracting the packet-level features from attack traffic, serves as the server. Initially, the malicious behavior knowledge base subscribes to the server. Upon extraction, the server automatically sends the subscribed client the packet-level features. Subsequently, the client utilizes Python&#x2019;s xml.dom library to analyze the packet-level feature information received through the NETCONF protocol. This information is saved to the malicious behavior knowledge base, which is updated in real time.</p>
<p>Each NSF [<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-21">21</xref>&#x2013;<xref ref-type="bibr" rid="ref-24">24</xref>] employs the CICFlowMeter [<xref ref-type="bibr" rid="ref-25">25</xref>] flow feature extraction tool to aggregate five identical data packets into a single flow. This process extracts detailed flow-level feature information, enabling model training and online deployment for fine-grained attack classification. Simultaneously, we utilize Python&#x2019;s psutil library to monitor CPU, memory, and other resource utilization within Docker containers hosting each NSF at specific intervals. The classification detection outcomes of each NSF and resource utilization of the system are transmitted back to the malicious traffic detection knowledge base and the resource usage knowledge base via a Socket interface. These knowledge bases serve as servers, employing multi-threaded Socket interfaces to receive feedback from the detection modules. Traffic detection information and resource utilization from each NSF, acting as the clients, are transmitted via Socket to update both knowledge bases. Each module&#x2019;s traffic detection data includes accuracy, malicious traffic detection rate, detection capability, and detection time. Resource utilization metrics include CPU usage rate, memory usage rate, disk usage rate, and packet loss rate.</p>
<p>The knowledge base is continuously updated through a real-time feedback mechanism, where data such as attack features and system resource usage detected by the traffic monitoring modules are fed back into the system. This dynamic update strategy ensures that the knowledge base remains up-to-date, allowing the system to respond promptly to emerging threats and new attack patterns. We input the packet-level feature of DDoS attack traffic stored in the malicious behavior database into the SFC path selection module as input for the path selection algorithm. The detection outcomes from the malicious traffic detection knowledge base and the CPU usage rate of the resource usage knowledge base are used as parameters for the path selection algorithm. This approach aims to dynamically adjust the service path based on data from the real-time updated knowledge base, in order to determine the optimal detection path, which involves integrating various NSFs.</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Knowledge Base Module</title>
<p>The knowledge base module comprises a malicious behavior knowledge base, a malicious traffic detection knowledge base, and a resource usage knowledge base. These correspond to the three types of information fed back to the knowledge base by the data feedback module. <xref ref-type="fig" rid="fig-3">Fig. 3</xref> depicts the structure diagram of each knowledge base and other modules.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Relationship between the knowledge base and other modules</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-3.tif"/>
</fig>
<p>The primary components of the malicious behavior knowledge base include the flow-level feature datasets of DDoS attacks, the malicious behavior feature graph, and the packet-level feature datasets of DDoS attacks. The flow-level feature datasets of DDoS attacks encompass 83 feature attributes extracted by the CICFlowMeter, exemplified in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Flow-level features of DDoS attacks</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Feature type</th>
<th>Feature name</th>
</tr>
</thead>
<tbody>
<tr>
<td>Flow identification feature</td>
<td>Protocol</td>
</tr>
<tr>
<td>Marker bit features</td>
<td>FIN Flag Count, SYN Flag Count, RST Flag Count, ACK Flag Count, Fwd PSH Flag, Bwd URG Flag</td>
</tr>
<tr>
<td>Flow header features</td>
<td>Fwd Header Length, Bwd Header Length, FWD Init Win Bytes</td>
</tr>
<tr>
<td>Time features</td>
<td>Fwd IAT Min, Fwd IAT Max, Fwd IAT Mean, Fwd IAT Std, Fwd IAT Total, Flow IAT Min, Flow IAT Mean, Flow IAT Std, Flow duration, Idle Min, Idle Max, Idle Mean</td>
</tr>
<tr>
<td>Payload features</td>
<td>Total Fwd Packet, Total Bwd Packet, Total Length of Fwd Packet, Packet Length Min, Bwd Packet Length Max, AVG Bwd Segment Size, Flow Byte/s, Fwd Packets/s, Bwd Avg Bytes/Bulk</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The malicious behavior feature graph [<xref ref-type="bibr" rid="ref-26">26</xref>] provides detailed classification and feature matching of DDoS attacks. As depicted in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>, purple nodes represent five types of DDoS attacks, light pink nodes denote 21 specific subtypes encompassed within these five types, and blue nodes signify 83 distinct feature attributes. For instance, within the category of DRDoS attacks, there are subtypes like Chargen, NTP, and TFTP. Each subtype exhibits unique features distinguishing it from normal traffic, such as Idle Mean. The flow-level feature datasets of DDoS attacks and the malicious behavior feature graph serve as inputs to the NSF feature selection module, providing data support for it.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Malicious behavior feature graph</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-4.tif"/>
</fig>
<p><xref ref-type="table" rid="table-2">Table 2</xref> illustrates the packet-level features utilized in identifying DDoS attacks, predominantly focusing on entropy-based features. The packet-level features include entropy of IP and port, packet rate, conditional entropy of packets, etc. DDoS attacks typically generate higher traffic rates compared to normal traffic, so we selected packet rate and byte rate as features. During a DDoS attack, a significant number of packets are directed to the same target IP address. By measuring the entropy of IP addresses within a specified time window, we can effectively identify the occurrence of a DDoS attack. Additionally, calculating the entropy of port numbers, along with the conditional entropy that combines both port and IP, allows us to effectively differentiate between various types of DDoS attack traffic. They serve as inputs to the SFC path selection module, providing data support for dynamically adjusting the service path to determine the optimal detection path.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Packet-level features of DDoS attacks</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left" />
<col align="left" />
</colgroup>
<thead>
<tr>
<th>Feature</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>Packet rate</td>
<td>Average number of packets forwarded per second</td>
</tr>
<tr>
<td>Byte rate</td>
<td>Average number of bytes forwarded per second</td>
</tr>
<tr>
<td>Average packet length</td>
<td>Average length of data packets</td>
</tr>
<tr>
<td>Source IP entropy</td>
<td>Entropy of source IP address</td>
</tr>
<tr>
<td>Destination IP entropy</td>
<td>Entropy of destination IP address</td>
</tr>
<tr>
<td>TTL entropy</td>
<td>Entropy of packet lifetime TTL</td>
</tr>
<tr>
<td>TCP source port entropy</td>
<td>Entropy of TCP packet source port</td>
</tr>
<tr>
<td>TCP destination port entropy</td>
<td>Entropy of TCP packet destination port</td>
</tr>
<tr>
<td>UDP source port entropy</td>
<td>Entropy of UDP packet source port</td>
</tr>
<tr>
<td>UDP destination port entropy</td>
<td>Entropy of UDP packet destination port</td>
</tr>
<tr>
<td>Packet length entropy</td>
<td>Entropy of packet length</td>
</tr>
<tr>
<td>H(Sip|Dip)</td>
<td>Entropy of source IP when destination IP is given</td>
</tr>
<tr>
<td>H(Sip|Dport)</td>
<td>Entropy of source IP when destination port is given</td>
</tr>
<tr>
<td>H(Dport|Dip)</td>
<td>Entropy of source port when destination IP is given</td>
</tr>
<tr>
<td>Variance of packet number</td>
<td>Variance of the number of packets per unit interval</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-3">Table 3</xref> outlines the content of the resource usage knowledge base, which includes critical indicators such as CPU usage rate, memory usage rate, disk usage rate, and packet loss rate. By analyzing CPU usage, memory usage, and disk usage, we can effectively identify and address causes of system performance degradation or failures. Monitoring packet loss rates also helps identify network connectivity issues, facilitating timely troubleshooting and resolution. These metrics are essential for constructing optimal SFC paths while ensuring that resource utilization remains within acceptable limits. They are used as parameters for the path selection algorithm.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Resource usage knowledge base</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left" />
<col align="left" />
<col align="left" />
</colgroup>
<thead>
<tr>
<th>Name</th>
<th>Description</th>
<th>Unit</th>
</tr>
</thead>
<tbody>
<tr>
<td>cpu_usage</td>
<td>CPU usage rate</td>
<td>%</td>
</tr>
<tr>
<td>cpu_freq</td>
<td>CPU frequency</td>
<td>MHz</td>
</tr>
<tr>
<td>memory_total</td>
<td>Total system memory</td>
<td>GB</td>
</tr>
<tr>
<td>memory_available</td>
<td>Available memory</td>
<td>GB</td>
</tr>
<tr>
<td>memory_usage</td>
<td>Memory usage rate</td>
<td>%</td>
</tr>
<tr>
<td>disk_usage</td>
<td>Disk usage rate</td>
<td>%</td>
</tr>
<tr>
<td>disk_left</td>
<td>Disk remaining space</td>
<td>GB</td>
</tr>
<tr>
<td>packet_loss_rate</td>
<td>Packet loss rate</td>
<td>%</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The core content of the malicious traffic detection knowledge base consists of detection outcomes from various NSFs, as shown in <xref ref-type="table" rid="table-4">Table 4</xref>. These detection results correspond to traffic features, indicating accuracy, detection rate, detection capability, and detection time for each module at a given time, reflecting the effectiveness of the detection modules in identifying current traffic patterns. These results are used as parameters for the path selection algorithm, providing crucial data support.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Malicious traffic detection knowledge base</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left" />
<col align="left" />
</colgroup>
<thead>
<tr>
<th>Content</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>Module name</td>
<td>Name of the detection module</td>
</tr>
<tr>
<td>Time stamp</td>
<td>Detected time stamp</td>
</tr>
<tr>
<td>Accuracy</td>
<td>The ratio of correctly predicted traffic to total traffic</td>
</tr>
<tr>
<td>Detection rate</td>
<td>The ratio of correctly predicted attacks to all predicted attacks</td>
</tr>
<tr>
<td>Detection capability</td>
<td>The ratio of total number of attacks to undetected attacks</td>
</tr>
<tr>
<td>Detection time</td>
<td>The time consumed by the detection module</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The malicious behavior knowledge base, resource usage knowledge base, and malicious traffic detection knowledge base do not operate independently; they rely on traffic numbers as a common primary key for data linkage. Feedback information received within the same period is aggregated under the corresponding traffic number. This approach facilitates retrieval of traffic features, identifies which NSF detected the traffic, and provides access to results and resource usage data from detection modules. The entity relationship diagram is shown in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Entity relationship diagram</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-5.tif"/>
</fig>
<p>To maintain the timeliness of the knowledge base, we implement an automatic expiration mechanism where each data entry is assigned a timestamp. Entries that exceed a predefined threshold are flagged as outdated and are either archived for further analysis or removed from active use. Additionally, the system periodically reviews the knowledge base content, ensuring that outdated information is purged or updated based on current network conditions and threat dynamics.</p>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Security Policy Reasoning Module</title>
<sec id="s3_4_1">
<label>3.4.1</label>
<title>NSF Feature Selection Module</title>
<p>Feature selection [<xref ref-type="bibr" rid="ref-27">27</xref>] plays a crucial role in machine learning, particularly for enhancing detection module performance by identifying a subset of original feature data. In this section, we propose a novel feature selection method that combines the PageRank feature ranking approach with the RandomForest algorithm. This method leverages the malicious behavior feature graph and the flow-level feature datasets of DDoS attacks from the malicious behavior knowledge base. The goal is to assess the importance of the features corresponding to each attack in the graph, pinpoint flow-level features that significantly influence attack classification, and integrate this information into various NSFs to enhance detection efficiency and capability. The overall flow diagram is depicted in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Feature ranking flow diagram</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-6.tif"/>
</fig>
<p>The malicious behavior feature graph of DDoS attacks shows that there is a correlation between each type of attack and the specific types of traffic features. However, relying only on feature engineering algorithms such as RandomForest cannot fully exploit the importance of data features, resulting in insufficient expression of malicious behavior features. PageRank is a well-known graph-based ranking algorithm [<xref ref-type="bibr" rid="ref-28">28</xref>] primarily used to rank web pages by analyzing the link structure within a network. In this study, the PageRank algorithm is applied to effectively reason over and select features from the malicious behavior feature graph. Therefore, we combine PageRank and RandomForest for feature selection. PageRank is used for knowledge inference and feature selection in the malicious behavior feature graph, while RandomForest is used for selecting information from the flow-level feature datasets of DDoS attacks.</p>
<p>However, the malicious behavior feature graph within the knowledge base lacks relationships between features, which are essential for PageRank&#x2019;s random walk on a strongly connected directed graph. To address this, it becomes necessary to transform the graph from a tree structure into a strongly connected directed graph. The conversion formula is provided below:
<disp-formula id="eqn-1">
<label>(1)</label>
<mml:math id="mml-eqn-1" display="block"><mml:mi>A</mml:mi><mml:mo>&#x003A;</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>Y</mml:mi><mml:mo>,</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>Z</mml:mi></mml:math></disp-formula>
<disp-formula id="eqn-2">
<label>(2)</label>
<mml:math id="mml-eqn-2" display="block"><mml:mi>B</mml:mi><mml:mo>&#x003A;</mml:mo><mml:mi>Y</mml:mi><mml:mo stretchy="false">&#x21D4;</mml:mo><mml:mi>Z</mml:mi></mml:math></disp-formula>where <italic>X</italic> represents the attack type, <italic>Y</italic> and <italic>Z</italic> represent the flow-level features. The graph undergoes a transformation from state <italic>A</italic> to state <italic>B</italic>. For instance, in the case of a DRDoS attack, <xref ref-type="fig" rid="fig-7">Fig. 7</xref> illustrates the relationships among its six attack subtypes, Chargen, NTP, and TFTP, and certain flow-level features such as Fwd Bulk Rate Avg and Packet Length Max. Each attack subtype&#x2019;s corresponding flow-level features are paired to construct a feature map, as depicted in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>. For example, for the TFTP attack subtype, the flow-level features include Fwd Bulk Rate Avg, Flow IAT Min, and Total Fwd Packet, all connected pairwise in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>.</p>
<fig id="fig-7"><label>Figure 7</label><caption><title>DRDoS attack features diagram</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-7.tif"/></fig><fig id="fig-8"><label>Figure 8</label><caption><title>Feature map diagram</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-8.tif"/></fig>
<p>The RandomForest feature selection algorithm [<xref ref-type="bibr" rid="ref-29">29</xref>] assesses the importance of each type of DDoS attack and prioritizes features based on their significance. This method evaluates the contribution of each feature to every tree within the random forest, calculates their average contribution, and compares the importance across features.</p>
<p>The pseudo-code for combining PageRank with RandomForest to compute feature importance scores is outlined in Algorithm 1. The malicious behavior feature graph comprises 83 nodes representing DDoS attack features, thus setting the number of nodes to <italic>n</italic> &#x003D; 83. To enhance the reliability of PageRank, parameters are configured as follows: the damping factor <italic>d</italic> &#x003D; 0.85, the calculation accuracy <italic>&#x03C3;</italic> &#x003D; 1e &#x2212; 5, and the maximum number of iterations <italic>Q</italic> &#x003D; 100, as recommended in [<xref ref-type="bibr" rid="ref-14">14</xref>]. The first-order Markov chain transition matrix <italic>M</italic> is derived from the strongly connected feature map post-mapping, <italic>x</italic><sub><italic>(1)</italic></sub> denotes the initial distribution matrix for feature importance scores, initialized assuming equal importance for each feature node, which is 1/83.</p>
<fig id="fig-26">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-26.tif"/>
</fig>
<p>PageRank is integrated with the RandomForest method, and the formula for computing the final score of each feature node is as follows:
<disp-formula id="eqn-3">
<label>(3)</label>
<mml:math id="mml-eqn-3" display="block"><mml:mi>s</mml:mi><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mi>R</mml:mi><mml:mi>F</mml:mi><mml:mo>+</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mi>P</mml:mi><mml:mi>R</mml:mi></mml:math></disp-formula>
<disp-formula id="eqn-4">
<label>(4)</label>
<mml:math id="mml-eqn-4" display="block"><mml:mn>0</mml:mn><mml:mo>&#x003C;</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mi>R</mml:mi><mml:mo>,</mml:mo><mml:mi>R</mml:mi><mml:mi>F</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mn>1</mml:mn></mml:math></disp-formula>
<disp-formula id="eqn-5">
<label>(5)</label>
<mml:math id="mml-eqn-5" display="block"><mml:mi>&#x03B1;</mml:mi><mml:mo>+</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></disp-formula>where <italic>PR</italic> and <italic>RF</italic> denote feature importance scores from the PageRank and RandomForest algorithms, respectively. <italic>&#x03B1;</italic> and <italic>&#x03B2;</italic> represent the participation coefficients for <italic>RF</italic> and <italic>PR</italic>, ranging from 0 to 1. Subsequently, feature importance is ranked based on these scores, and the top flow-level features are selected. Using this refined feature set, the attack detection models in the service function module are retrained, resulting in optimized detection performance.</p>
</sec>
<sec id="s3_4_2">
<label>3.4.2</label>
<title>SFC Path Selection Module</title>
<p>The SFC path selection module trains a path selection model called GAT&#x002B;DRL, which combines GAT and DRL to select the optimal detection path. As illustrated in <xref ref-type="fig" rid="fig-9">Fig. 9</xref>, we first feed the packet-level feature datasets of DDoS attacks from the malicious behavior knowledge base into GAT. GAT learns both feature representations and structural relationships within the data. The aggregated features are then passed to DRL, which formulates the path selection task as Markov decision processes. DRL selects the optimal detection path by maximizing rewards derived from combining detection outcomes from the malicious traffic detection knowledge base and CPU usage rates from the resource usage knowledge base.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>GAT&#x002B;DRL model framework</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-9.tif"/>
</fig>
<p>GAT is a graph neural network model that incorporates an attention mechanism between data, enhancing its ability to capture both relational and feature information between data, thus enabling deep analysis and data mining capabilities. It can uncover high-level feature information about malicious traffic in the knowledge base, and based on these high-level features, DRL can more effectively select paths. On the other hand, DRL combines deep learning&#x2019;s perceptual capabilities with reinforcement learning&#x2019;s decision-making prowess. One prominent example is DQN, which approximates the Q-function using a deep neural network. The network takes the environment state as input and predicts Q-values for all possible actions in that state.</p>
<p>As depicted in <xref ref-type="fig" rid="fig-10">Fig. 10</xref>, a substantial volume of packet-level feature data from diverse DDoS attacks in the malicious behavior knowledge base is initially inputted into GAT. Here, each attack node aggregates feature information transmitted by its neighboring nodes using an aggregation function. This accumulated information undergoes modification through a nonlinear update function. This iterative process repeats multiple times to generate the resultant features for each attacking node.</p>
<fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>GAT architecture diagram</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-10.tif"/>
</fig>
<p>The feature information of input nodes is denoted as <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>h</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mi>R</mml:mi><mml:mrow><mml:mi>F</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, where <italic>N</italic> represents the total number of input malicious traffic and <italic>F</italic> represents the feature dimension of each traffic instance. The self-attention mechanism is then applied to compute the attention score between node <italic>i</italic> and its neighbor node <italic>j</italic>.
<disp-formula id="eqn-6">
<label>(6)</label>
<mml:math id="mml-eqn-6" display="block"><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mi>W</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mi>R</mml:mi><mml:mrow><mml:msup><mml:mi>F</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x00D7;</mml:mo><mml:mi>F</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> denotes a shared linear transformation matrix that is trainable. The matrix is applied to each traffic node, enabling the original feature space to be transformed into a higher-level feature space, thereby enhancing the node&#x2019;s expression capability. The function <italic>a</italic>(&#x2022;) computes the correlation between two nodes (vectors).</p>
<p>The importance of node <italic>j</italic> to node <italic>i</italic> is determined through <italic>e</italic><sub><italic>i,j</italic></sub>. To ensure coefficients are comparable across different nodes, we normalize using the softmax function, which yields standardized attention scores.
<disp-formula id="eqn-7">
<label>(7)</label>
<mml:math id="mml-eqn-7" display="block"><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mtext>softmax</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>K</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mi>L</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>k</mml:mi><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>L</mml:mi><mml:mi>u</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>K</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mi>L</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>k</mml:mi><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>L</mml:mi><mml:mi>u</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula>where || denotes the concatenation of two transformed nodes, <italic>a</italic> is a trainable parameter vector, known as the attention parameter vector, with a size of 2 &#x00D7; <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:msup><mml:mi>F</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> (twice the embedded size after conversion), which is utilized to learn the relative importance between nodes and their neighbors, the entire expression <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>a</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> represents the dot product between <italic>a</italic> and the transformed node.</p>
<p>After each neighbor&#x2019;s feature vector is multiplied by a dimension transformation vector parameter, weighted by attention scores, and subsequently passed through an activation function, the resulting aggregated features corresponding to each node are obtained.
<disp-formula id="eqn-8">
<label>(8)</label>
<mml:math id="mml-eqn-8" display="block"><mml:msup><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mi>W</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>Based on the aggregated features of GAT, the detection outcomes in the malicious traffic detection knowledge base and the resource utilization in the resource usage knowledge base, a DRL environment is constructed. Subsequently, the problem of SFC path selection is modeled as a Markov Decision Process (MDP), comprising state space, action space, and reward functions.</p>
<p>State: In the DRL framework, the state represents the information available to the agent from the environment. For the SFC path selection problem, the state space consists of the aggregated features output by the GAT and the accuracy of each detection module in the malicious traffic detection knowledge base. This state can be represented as a vector <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>&#x03D5;</mml:mi><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula>, where <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:msup><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> denotes the high-level feature aggregated by GAT in the previous stage, and <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>&#x03D5;</mml:mi></mml:math></inline-formula> represents the detection accuracy of each detection module.</p>
<p>Action: In DRL, the selection of NSFs is guided by traffic features and detection outcomes. Therefore, the action space <italic>A</italic> is defined as the set of possible NSFs <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>A</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mn>6</mml:mn></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula>, including five detection modules and firewalls, totaling six schemes. When an agent takes an action, it adds the corresponding NSF to the path list. If the action is to add a firewall, the path list construction concludes, making the end of a training round.</p>
<p>Reward: The DRL agent improves its performance by receiving reward signals from the external environment. Typically, when an NSF is selected based on the current state, a positive reward is issued to reinforce the likelihood of action being chosen. This positive reward correlated with the malicious traffic detection capability in the malicious traffic detection knowledge base and the CPU usage rate in the resource usage knowledge base. Conversely, if the selected action duplicates a detection module already included in the SFC path, a negative reward is given. This negative reinforcement prompts the agent to explore alternative decisions. The reward function for action at is defined as follows:
<disp-formula id="eqn-9">
<label>(9)</label>
<mml:math id="mml-eqn-9" display="block"><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:mi>F</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mrow><mml:mtext>duplicate</mml:mtext></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>c</mml:mi><mml:mi>p</mml:mi><mml:mi>u</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>u</mml:mi><mml:mi>s</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi><mml:mi>e</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mi>n</mml:mi></mml:mfrac></mml:mstyle><mml:mo>,</mml:mo><mml:mrow><mml:mtext>otherwise</mml:mtext></mml:mrow></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math></disp-formula>where <italic>&#x03C9;</italic> is a fixed positive number, <italic>MTDC</italic> is the malicious traffic detection capability of the selected NSF, <italic>cpu_usage</italic> is the CPU usage rate, and <italic>n</italic> is the number of NSFs that the packet passes through.</p>
<p>In the training process of the DRL model, after each decision, the agent selects actions using an <italic>&#x025B;</italic>-greed strategy. <italic>&#x025B;</italic> is a value between 0 and 1. In this strategy, the agent selects the known optimal action with a probability of <italic>&#x025B;</italic>, and with a probability of 1-<italic>&#x025B;</italic>, it chooses a random action to explore unknown situations. Given the diversity and complexity of security service functions, the number of alternative paths can be very large. It is not practical to design alternative paths manually at this point, so the agent is needed to explore the environment and enhance adaptability in SFC path selection in order to select the optimal path. Upon executing an action, the corresponding state, action, reward, and subsequent state information are stored in the experience pool. Periodically, batches of data are sampled from this pool for training, during which the target network parameters are updated. The loss function used to assess the estimation performance during training is defined as follows:
<disp-formula id="eqn-10">
<label>(10)</label>
<mml:math id="mml-eqn-10" display="block"><mml:mi>J</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>arg</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mo form="prefix">max</mml:mo><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>]</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msup><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> represent the parameters of the evaluated network and target network, respectively, and <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>&#x03B3;</mml:mi></mml:math></inline-formula> is the discount factor. The loss function is defined as the mean square error between the target Q-value <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>arg</mml:mi><mml:mo>&#x2061;</mml:mo><mml:munder><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:munder><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msubsup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> from the target network, and the estimated Q-value <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> from the evaluated network. Minimizing this loss function improves the evaluation performance of the model. The gradient descent algorithm is employed to update the parameters of the evaluated network, optimizing the loss function as follows:
<disp-formula id="eqn-11">
<label>(11)</label>
<mml:math id="mml-eqn-11" display="block"><mml:msubsup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>arg</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mo form="prefix">max</mml:mo><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msubsup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mi>Q</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <italic>&#x03B8;</italic><sub><italic>t</italic></sub><sup><italic>&#x002B;</italic></sup> represents the updated parameters of the estimated network after applying the gradient descent algorithm, and <italic>&#x03B2;</italic> represents the step size parameter used in the gradient descent update process.</p>
<p>This pseudo-code outlines the training process for a system that combines GAT with DRL for detecting DDoS attacks in Algorithm 2. It initializes the environment and network parameters, performs GAT-based feature extraction, allows the DRL agent to interact with the environment using &#x025B;-greedy exploration, stores experiences in a replay memory, updates the network parameters based on sampled experiences, and periodically updates the target network. Finally, it saves the trained model for use in the online detection of malicious traffic.</p>
<fig id="fig-27">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-27.tif"/>
</fig>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Experimental Results</title>
<p>This section focuses on experimental testing and result analysis of the proposed intelligent security service optimization method. <xref ref-type="sec" rid="s4_1">Section 4.1</xref> outlines the construction of the experimental environment. <xref ref-type="sec" rid="s4_2">Section 4.2</xref> presents some new evaluation metrics. The update process of the knowledge base data is evaluated in <xref ref-type="sec" rid="s4_3">Section 4.3</xref>. <xref ref-type="sec" rid="s4_4">Section 4.4</xref> scrutinizes the performance of both the NSF feature selection algorithm and the SFC path selection algorithm. <xref ref-type="sec" rid="s4_5">Section 4.5</xref> assesses the system&#x2019;s online detection performance under different paths. Finally, to verify the impact of updating the knowledge base with real-time feedback data on path selection performance, <xref ref-type="sec" rid="s4_6">Section 4.6</xref> evaluates the effectiveness of the knowledge base before and after updating based on detection delay and TMTDC.</p>
<sec id="s4_1">
<label>4.1</label>
<title>Experimental Environment</title>
<p>This section establishes an experimental environment using VMware vSphere, with the experimental topology illustrated in <xref ref-type="fig" rid="fig-11">Fig. 11</xref>. Each virtual machine runs Ubuntu 18.04 with 16 GB of memory and 30 GB of disk space allocated. The experimental setup comprises a knowledge base host, two classifiers, four repeaters, a host for generating attack and normal traffic, and a target host. For software implementation, Open vSwitch and OpenDaylight are utilized to construct the SFC, facilitating the virtualized deployment of NSFs through Docker.</p>
<fig id="fig-11">
<label>Figure 11</label>
<caption>
<title>Experimental topology</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-11.tif"/>
</fig>
<p>In our experimental environment, several NSFs are employed, including the NetDDoS detection module, AppDDoS detection module, Botnet detection module, LDDoS detection module, DRDoS detection module, and firewall. To evaluate the system, we utilize Python scripts and attack tools to simulate 21 types of attacks on designated hosts. Additionally, normal traffic data is collected from activities such as voice calls, video streaming, and online gaming within a 5G environment [<xref ref-type="bibr" rid="ref-21">21</xref>].</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Evaluation Metrics</title>
<p>In the experiment, five evaluation metrics are employed to assess the detection effectiveness: confusion matrix, accuracy, precision rate, recall rate, and F1 score. The confusion matrix illustrates the relationship between the model&#x2019;s predictions and the actual labels.</p>
<p>In addition, we define new evaluation metrics to assess the effectiveness of online detection: malicious traffic detection rate, path detection delay, and total malicious traffic detection capability (TMTDC). The malicious traffic detection rate quantifies the proportion of attack traffic correctly identified after detection. Here, <italic>i</italic> is the attack traffic category, <italic>n</italic> is the total number of attack traffic categories, <italic>T</italic><sub><italic>i</italic></sub> is the number of correctly detected instances within category <italic>i</italic>, and <italic>A</italic><sub><italic>i</italic></sub> is the total number of instances in category <italic>i</italic>. The malicious traffic detection rate is defined as:
<disp-formula id="eqn-12">
<label>(12)</label>
<mml:math id="mml-eqn-12" display="block"><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi>R</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>A</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>The path detection delay: For an SFC path, the path detection delay reflects its response speed and serves as a crucial performance evaluation metric. <xref ref-type="disp-formula" rid="eqn-13">Eq. (13)</xref> outlines the calculation formula for the path detection delay:
<disp-formula id="eqn-13">
<label>(13)</label>
<mml:math id="mml-eqn-13" display="block"><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>a</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>F</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:munderover><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:munderover><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>y</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mi>C</mml:mi></mml:mfrac></mml:math></disp-formula>where <italic>C</italic> represents the length of the SFC, and <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:munderover><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:munderover><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>y</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> denotes the path delay from the <italic>c</italic>-th NSF to the (<italic>c</italic> &#x002B; 1)-th NSF, which is the sum of delays along the SFC path.</p>
<p>TMTDC: This metric measures the malicious traffic detection capability along the selected path and serves as a crucial evaluation index of path quality. It is defined as:
<disp-formula id="eqn-14">
<label>(14)</label>
<mml:math id="mml-eqn-14" display="block"><mml:mi>T</mml:mi><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mi>C</mml:mi></mml:mfrac><mml:mo>+</mml:mo><mml:mfrac><mml:mrow><mml:mi>A</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi><mml:mi>e</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mo>&#x00D7;</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mi>A</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi><mml:mi>e</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle><mml:mo>&#x2212;</mml:mo><mml:mi>C</mml:mi><mml:mo>]</mml:mo></mml:mrow></mml:mrow><mml:mi>C</mml:mi></mml:mfrac></mml:math></disp-formula>where <italic>C</italic> is the number of NSFs selected in the path list, <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> represents the detection capability of the <italic>c</italic>-th NSF, <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> denotes the sum of detection capabilities of the selected NSFs, and <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mi>A</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi><mml:mi>e</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>N</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:math></inline-formula> represents the average detection capability of the selected NSFs. Detection capability refers to the ratio of the total number of malicious traffic to the undetected malicious traffic, which is defined as:
<disp-formula id="eqn-15">
<label>(15)</label>
<mml:math id="mml-eqn-15" display="block"><mml:mi>M</mml:mi><mml:mi>T</mml:mi><mml:mi>D</mml:mi><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>A</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mfrac></mml:mstyle></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Knowledge Base Update</title>
<p>The traffic detection outcomes from each detection module within the service function module include accuracy, malicious traffic detection rate, detection capability, and detection time. Resource utilization metrics encompass CPU usage rate, memory usage rate, disk usage rate, and packet loss rate. These metrics are transmitted via Socket interface feedback to the malicious traffic detection knowledge base and the resource usage knowledge base respectively. To manage this data, multi-threaded processes are created by these knowledge bases to receive feedback from each detection module. <xref ref-type="fig" rid="fig-12">Fig. 12</xref> illustrates the knowledge base listening to ports, showing data reception from port 7001, corresponding to the DRDoS detection module.</p>
<fig id="fig-12">
<label>Figure 12</label>
<caption>
<title>Monitoring of knowledge base</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-12.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-13">Fig. 13</xref> illustrates that the traffic detection outcomes are stored in the malicious traffic detection knowledge base located at <italic>/root/detection_dataset/drdos-acc.csv</italic>, while the resource utilization of the host hosting the detection module is stored in the resource usage knowledge base at <italic>/root/detection_dataset/drdos-usage.csv</italic>. The timestamp in the malicious traffic detection outcomes has been updated from 2023-12-29 to 2024-01-05, indicating the recent update of both the malicious traffic detection outcomes and the system resource utilization in the knowledge base.</p>
<fig id="fig-13">
<label>Figure 13</label>
<caption>
<title>Update of malicious traffic detection and resource usage knowledge base</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-13.tif"/>
</fig>
<p>The traffic feature information, which includes packet-level features of attack traffic such as packet rate, source IP entropy, destination IP entropy, source port entropy, destination port entropy, TTL entropy, etc., is fed back to the malicious behavior knowledge base via the NETCONF protocol. This feedback process is illustrated in <xref ref-type="fig" rid="fig-14">Fig. 14</xref>.</p>
<fig id="fig-14">
<label>Figure 14</label>
<caption>
<title>Knowledge feedback</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-14.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-15">Fig. 15</xref> demonstrates that the packet-level feature information of traffic is stored in the malicious behavior knowledge base located at <italic>/monitor/monitor_information/feature</italic>. The CSV file containing this information has been updated from 2023-06-12 to 2024-01-05, indicating the recent update of packet-level traffic features in the knowledge base.</p>
<fig id="fig-15">
<label>Figure 15</label>
<caption>
<title>Update of malicious behavior knowledge base</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-15.tif"/>
</fig>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Offline Training Results</title>
<p>This section includes the training results of the feature selection model and the SFC path selection model. Based on Python tools, this section first introduces the implementation of parameter tuning and optimization for the feature selection model, along with the result analysis using known datasets. It then presents the training results of the SFC path selection model and the corresponding result analysis using known datasets.</p>
<sec id="s4_4_1">
<label>4.4.1</label>
<title>Training Results of Feature Selection Model</title>
<p>According to <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>, the importance score varies with parameters <italic>&#x03B1;</italic> and <italic>&#x03B2;</italic>. In <xref ref-type="fig" rid="fig-16">Fig. 16a</xref>, the score is depicted under different values of <italic>&#x03B1;</italic> and <italic>&#x03B2;</italic>. The <italic>x</italic>-axis represents 83 feature types, the <italic>y</italic>-axis represents the value of <italic>&#x03B1;</italic>, and the <italic>z</italic>-axis represents the importance score. We increment <italic>&#x03B1;</italic> from 0.1 to 0.9 in steps of 0.1, while <italic>&#x03B2;</italic> varies oppositely. The importance score based on RandomForest shows significant variability, whereas the distribution of PageRank is relatively uniform. Therefore, <italic>&#x03B1;</italic> &#x003D; 0.2 is chosen to ensure that the score is not overly influenced by RandomForest, as illustrated in <xref ref-type="fig" rid="fig-16">Fig. 16b</xref>.</p>
<fig id="fig-16">
<label>Figure 16</label>
<caption>
<title>The importance score under different values of <italic>&#x03B1;</italic> and <italic>&#x03B2;</italic></title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-16.tif"/>
</fig>
<p>To validate the detection performance of the feature selection algorithm combining PageRank and RandomForest proposed in our paper, we generated three sets of feature importance rankings. These rankings include PageRank and RandomForest combined, PageRank only, and RandomForest only used in Reference [<xref ref-type="bibr" rid="ref-12">12</xref>]. For each ranking, the top 20 features were selected and are presented in <xref ref-type="table" rid="table-5">Table 5</xref>.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Selected features of three methods</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Feature selection method</th>
<th>Feature name</th>
</tr>
</thead>
<tbody>
<tr>
<td>PageRank combined with RandomForest</td>
<td>Fwd Packets/s, Flow IAT Mean, Flow Packets/s, Subflow Fwd Packets, Total Fwd Packet, Fwd Seg Size Min, Fwd IAT Std, Fwd Header Length, Fwd IAT Min, PSH Flag Count, Bwd Init Win Bytes, Flow IAT Std, Bwd Header Length, Flow IAT Min, FWD Init Win Bytes, Flow IAT Max, Fwd IAT Total, Subflow Fwd Bytes, Packet Length Max, Packet Length Variance</td>
</tr>
<tr>
<td>PageRank</td>
<td>Fwd Bulk Rate Avg, Fwd Packet/Bulk Avg, Average Packet Size, Bwd Segment Size Avg, Packet Length Min, Subflow Fwd Bytes, ACK Flag Count, Idle Min, PSH Flag Count, RST Flag Count, SYN Flag Count, FIN Flag Count, Packet Length Std, Packet Length Mean, Bwd Bytes Avg, Bwd Packet Avg, Bwd Bulk Rate Avg, Subflow Fwd Packets, Subflow Fwd Bytes, Subflow Bwd Packets</td>
</tr>
<tr>
<td>RandomForest</td>
<td>Fwd Packets/s, Flow IAT Mean, Flow Packets/s, Subflow Fwd Packets, Total Fwd Packet, Average Packet Size, Fwd IAT Std, Fwd Header Length, Subflow Fwd Bytes, PSH Flag Count, Bwd Init Win Bytes, Flow IAT Std, Bwd Header Length, Flow IAT Min, Packet Length Min, Flow IAT Max, Fwd IAT Total, Subflow Fwd Bytes, Packet Length Max, Packet Length Variance</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Based on the 20 effective features outlined in <xref ref-type="table" rid="table-5">Table 5</xref>, feature selection was conducted, and the datasets were partitioned into training and test sets with a ratio of 7:3, as detailed in <xref ref-type="table" rid="table-6">Table 6</xref>. The total number of data samples in the DRDoS feature datasets is 1,299,286, comprising 909,500 samples for training and 389,786 for testing. The performance of the feature selection methods was compared under the condition of using the same training datasets.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>DRDoS feature datasets</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left" />
<col align="left" />
<col align="left" />
</colgroup>
<thead>
<tr>
<th>Datasets type</th>
<th>Number of normal traffic samples</th>
<th>Number of attack traffic samples</th>
</tr>
</thead>
<tbody>
<tr>
<td>Training set</td>
<td>426,545</td>
<td>482,955</td>
</tr>
<tr>
<td>Test set</td>
<td>182,805</td>
<td>206,981</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>We applied the test dataset to XGBoost within the DRDoS detection module [<xref ref-type="bibr" rid="ref-30">30</xref>] and examined its output results. <xref ref-type="fig" rid="fig-17">Fig. 17</xref> displays the confusion matrix for features selected by three different methods of feature selection. Comparatively, the feature selection method combining PageRank and RandomForest achieves a high accuracy of 0.9999 overall, particularly excelling with perfect accuracies (1.0) in detecting Chargen, Memcached, and TFTP attacks. In contrast, the RandomForest feature selection method achieves an accuracy of 0.9970 overall, with perfect accuracies (1.0) for NTP and TFTP attacks but slightly lower accuracy (approximately 0.9892) for Chargen attacks. Meanwhile, the PageRank feature selection method achieves an accuracy of 0.9603 overall, with perfect recognition (1.0 accuracy) for TFTP attacks but lower accuracy for Chargen attacks.</p>
<fig id="fig-17">
<label>Figure 17</label>
<caption>
<title>Confusion matrix of XGBoost model under three feature selection methods</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-17.tif"/>
</fig>
<p>Based on the results from three feature selection methods, we further apply two additional machine learning models, LightGBM [<xref ref-type="bibr" rid="ref-31">31</xref>], KNN [<xref ref-type="bibr" rid="ref-32">32</xref>], along with the Stacking integrated learning model discussed in reference [<xref ref-type="bibr" rid="ref-19">19</xref>], and the previously mentioned XGBoost detection model to compare their training times and accuracy.</p>
<p><xref ref-type="fig" rid="fig-18">Fig. 18</xref> depicts the training times associated with three feature selection results across each model. Specifically, the KNN model, XGBoost model, LightGBM model, and Stacking model utilizing PageRank and RandomForest feature selection exhibit training times of 75.81, 160.09, 73.10, and 364.67 s, respectively. These times consistently show that models utilizing PageRank and RandomForest feature selection have the shortest training times compared to other feature selection methods.</p>
<fig id="fig-18"><label>Figure 18</label><caption><title>Training time of four models</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-18.tif"/></fig>
<p><xref ref-type="fig" rid="fig-19">Fig. 19</xref> compares the accuracy of three feature selection results across each model. The results indicate that features selected using the combination of PageRank and RandomForest consistently demonstrate higher accuracy in each training model compared to the other two feature selection methods. This approach not only achieves shorter detection times but also enhances performance in identifying various types of DRDoS attacks and normal traffic. Experimental findings underscore the capability of our feature selection method to extract more influential features related to DDoS attacks, thereby significantly improving the detection efficiency and performance of NSFs.</p>
<fig id="fig-19"><label>Figure 19</label><caption><title>Accuracy of four models</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-19.tif"/></fig>
</sec>
<sec id="s4_4_2">
<label>4.4.2</label>
<title>Training Results of SFC Path Selection Model</title>
<p>In the SFC path selection algorithm proposed in our paper, the GAT&#x002B;DRL model is trained using the Pytorch framework. We present the relevant parameters and training process used for training the SFC path selection model, as well as the results of path selection testing using the trained model on known attack datasets.</p>
<p>The experimental implementation is coded in Python, and the relevant parameters settings during the training process [<xref ref-type="bibr" rid="ref-18">18</xref>] are detailed in <xref ref-type="table" rid="table-7">Table 7</xref>.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Parameter settings</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left" />
<col align="left" />
</colgroup>
<thead>
<tr>
<th>Parameter</th>
<th>Value</th>
</tr>
</thead>
<tbody>
<tr>
<td>Learning rate</td>
<td>0.001</td>
</tr>
<tr>
<td>Total training period</td>
<td>12,000</td>
</tr>
<tr>
<td>Memory bank</td>
<td>10,000</td>
</tr>
<tr>
<td>Exploration factor</td>
<td>0.9</td>
</tr>
<tr>
<td>Discount factor</td>
<td>0.9</td>
</tr>
<tr>
<td>Parameter update frequency</td>
<td>200</td>
</tr>
<tr>
<td>Optimizer</td>
<td>Adam</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-20">Fig. 20</xref> illustrates the training process of the loss and reward values for the GAT&#x002B;DRL model using selected parameters, over a total of 12,000 iterations. As depicted in <xref ref-type="fig" rid="fig-20">Fig. 20a</xref>, the loss value steadily decreases as the number of training iterations increases. <xref ref-type="fig" rid="fig-20">Fig. 20b</xref> demonstrates that the reward value of the path exhibits a gradual increase with training iterations, reaching convergence to its maximum after approximately 5000 iterations.</p>
<fig id="fig-20">
<label>Figure 20</label>
<caption>
<title>The training process of the GAT&#x002B;DRL model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-20.tif"/>
</fig>
<p>The model achieves convergence within a training duration of 19.4 min and can distinguish between five different types of DDoS attacks and mixed attacks. <xref ref-type="fig" rid="fig-21">Fig. 21</xref> demonstrates the selection of the optimal path by inputting traffic of various attack types.</p>
<fig id="fig-21">
<label>Figure 21</label>
<caption>
<title>Path selected by GAT&#x002B;DRL model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-21.tif"/>
</fig>
</sec>
</sec>
<sec id="s4_5">
<label>4.5</label>
<title>Online Test Results</title>
<p>The online test implements real-time detection of various types of DDoS attack traffic using the trained models and provides feedback data to the knowledge base module. This section aims to assess the effectiveness of enhancing system detection performance and reducing detection time through intelligent security service optimization. The evaluation compares system performance before and after optimization across metrics such as precision rate, recall rate, F1 score, malicious traffic detection rate, path detection delay, and TMTDC.</p>
<p>In the system, a preset path incorporating all NSFs is established, through which traffic sequentially passes all detection modules. We conducted a replay of five types of DDoS attack traffic and applied both the DQN algorithm proposed in [<xref ref-type="bibr" rid="ref-18">18</xref>] and the intelligent security service optimization method proposed in this paper to select SFC paths. Subsequently, we compared the detection effectiveness across different paths. <xref ref-type="table" rid="table-8">Table 8</xref> presents the performance comparison of SFC detection for the five types of DDoS attack traffic under preset path, the SFC1 path selected by the DQN algorithm, and SFC2 path optimized by our method. For instance, for DRDoS attacks, preset path is [&#x2018;network&#x2019;, &#x2018;application&#x2019;, &#x2018;botnet&#x2019;, &#x2018;lddos&#x2019;, &#x2018;drdos&#x2019;, &#x2018;firewall&#x2019;], while the SFC1 path chosen by the DQN algorithm is [&#x2018;drdos&#x2019;, &#x2018;lddos&#x2019;, &#x2018;botnet&#x2019;, &#x2018;firewall&#x2019;]. The SFC2 path selected through our optimization method is [&#x2018;drdos&#x2019;, &#x2018;firewall&#x2019;].</p>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Comparison of detection performance under different paths</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left" />
<col align="left" />
<col align="left" />
<col align="left" />
<col align="left" />
<col align="left" />
</colgroup>
<thead>
<tr>
<th>Attack type</th>
<th>Selected path</th>
<th>Precision rate</th>
<th>Recall rate</th>
<th>F1 score</th>
<th>Detection rate</th>
</tr>
</thead>
<tbody>
<tr>
<td rowspan="3">AppDDoS</td>
<td>Preset path</td>
<td>0.7653</td>
<td>0.7592</td>
<td>0.7892</td>
<td>0.7782</td>
</tr>
<tr>
<td>SFC1 path</td>
<td>0.8668</td>
<td>0.8798</td>
<td>0.8849</td>
<td>0.8841</td>
</tr>
<tr>
<td>SFC2 path</td>
<td>0.9785</td>
<td>0.9749</td>
<td>0.9667</td>
<td>0.9697</td>
</tr>
<tr>
<td rowspan="3">DRDoS</td>
<td>Preset path</td>
<td>0.8898</td>
<td>0.9778</td>
<td>0.9317</td>
<td>0.9331</td>
</tr>
<tr>
<td>SFC1 path</td>
<td>0.9292</td>
<td>0.9566</td>
<td>0.9574</td>
<td>0.9582</td>
</tr>
<tr>
<td>SFC2 path</td>
<td>0.9977</td>
<td>0.9943</td>
<td>0.9959</td>
<td>0.9991</td>
</tr>
<tr>
<td rowspan="3">NetDDoS</td>
<td>Preset path</td>
<td>0.9352</td>
<td>0.8924</td>
<td>0.9028</td>
<td>0.9028</td>
</tr>
<tr>
<td>SFC1 path</td>
<td>0.9813</td>
<td>0.9146</td>
<td>0.9492</td>
<td>0.9292</td>
</tr>
<tr>
<td>SFC2 path</td>
<td>0.9805</td>
<td>0.9922</td>
<td>0.9943</td>
<td>0.9925</td>
</tr>
<tr>
<td rowspan="3">LDDoS</td>
<td>Preset path</td>
<td>0.8778</td>
<td>0.8653</td>
<td>0.8898</td>
<td>0.8524</td>
</tr>
<tr>
<td>SFC1 path</td>
<td>0.9317</td>
<td>0.9428</td>
<td>0.9541</td>
<td>0.9510</td>
</tr>
<tr>
<td>SFC2 path</td>
<td>0.9934</td>
<td>0.9874</td>
<td>0.9757</td>
<td>0.9950</td>
</tr>
<tr>
<td rowspan="3">Botnet</td>
<td>Preset path</td>
<td>0.9232</td>
<td>0.9274</td>
<td>0.9268</td>
<td>0.9245</td>
</tr>
<tr>
<td>SFC1 path</td>
<td>0.9853</td>
<td>0.9425</td>
<td>0.9617</td>
<td>0.9646</td>
</tr>
<tr>
<td>SFC2 path</td>
<td>0.9613</td>
<td>0.9641</td>
<td>0.9711</td>
<td>0.9679</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The precision rate, recall rate, and F1 score of SFC2 path, selected after optimizing the intelligent security service, consistently exceed 96% across all types of DDoS attack traffic. Compared to the preset path, SFC2 path also achieves an average increase of 12.4% in malicious traffic detection rate and 4.6% compared to the path selected by the DQN method, demonstrating overall excellent performance.</p>
<p><xref ref-type="fig" rid="fig-22">Fig. 22</xref> shows the path detection delay comparison of three different types of attack traffic, namely, LDDoS, DRDDoS, NetDDoS and mixed attacks of AppDDoS and LDDoS, before and after the intelligent security service optimization. When attack traffic traverses the preset path, it must pass through all detection modules. Conversely, when using paths selected by the DQN method or through intelligent security service optimization, traffic only passes through selected detection modules, resulting in significantly reduced delays compared to the preset path. In our method of intelligent security service optimization, the features of attack traffic chosen by detection modules and the SFC path through which traffic flows are redesigned. This reduces both detection time and the number of NSFs each detection module encounters compared to the DQN method-selected path, thereby minimizing delays from detection and forwarding. Consequently, across all types of attack traffic, the path delay achieved through intelligent security service optimization in this study has a latency that is approximately 42.8% lower than that of the DQN method, and about 58.3% lower than the preset path.</p>
<fig id="fig-22"><label>Figure 22</label><caption><title>Comparison of path detection delay</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-22.tif"/></fig>
<p><xref ref-type="fig" rid="fig-23">Fig. 23</xref> illustrates the TMTDC for three different paths: the preset path (blue line), the path chosen by the DQN method (yellow line), and the path optimized by intelligent security service (green line) under mixed attack traffic conditions. The TMTDC for the preset path is approximately 82, while the path selected by DQN shows a TMTDC of about 87. In contrast, the path optimized by intelligent security service exhibits a significantly higher TMTDC of 97, surpassing both the preset and DQN-selected paths by 18.1% and 11.5%, respectively. This indicates superior detection capability.</p>
<fig id="fig-23"><label>Figure 23</label><caption><title>Comparison of TMTDC</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-23.tif"/></fig>
</sec>
<sec id="s4_6">
<label>4.6</label>
<title>Comparison of Knowledge Base before and after Updating</title>
<p>To assess the effectiveness and intelligence of the path selected after updating the knowledge base, we initially set the traffic path through SFC as the preset path and subsequently subjected it to a DRDoS attack within 30 s. <xref ref-type="fig" rid="fig-24">Fig. 24</xref> illustrates the path detection delays before and after the knowledge base update. Initially, the delay of the preset path fluctuates between 40 and 70 s (purple solid line). Upon adjusting the path, the delay range decreases to between 20 and 40 s (purple dotted line). This reduction in delay compared to the preset path demonstrates the improved efficiency of the path selected after updating the knowledge base.</p>
<fig id="fig-24"><label>Figure 24</label><caption><title>Comparison of path detection delay</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-24.tif"/></fig>
<p><xref ref-type="fig" rid="fig-25">Fig. 25</xref> illustratesTMTDC before and after the knowledge base update. During the attack, the TMTDC for the preset path remains below 84 (solid line). However, after 15 s, the adaptive model selects an adjusted path based on current conditions (dotted line), resulting in a significantly higher TMTDC of 97, which is 15.5% greater than the preset path.</p>
<fig id="fig-25"><label>Figure 25</label><caption><title>Comparison of TMTDC</title></caption><graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_58327-fig-25.tif"/></fig>
<p>Based on the analysis, the intelligent security service optimization method proposed in this paper achieves excellent online detection performance, with precision rate, recall rate, and F1 scores for each DDoS attack type consistently exceeding 96%. Compared to both preset and DQN-selected paths, it increases malicious traffic detection rate by an average of 12.4% and 4.6%, respectively, enhancing TMTDC by 18.1% and 11.5% while reducing detection delays. Furthermore, it enables feedback on detection outcomes, system resource utilization, and packet-level network traffic features to their corresponding knowledge bases, guiding future security policy reasoning updates.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>We optimize intelligent security services based on a comprehensive network security knowledge base. It leverages rich data resources such as features of attack traffic, detection outcomes from NSF, and system resource utilization. Corresponding algorithms are developed to enhance feedback on security services, and to update and reason over the knowledge base. Real-time monitoring of malicious traffic allows for continuous knowledge updates and enables rapid, precise closed-loop optimizations. This approach facilitates real-time adjustment of path strategies. Experimental results demonstrate that the proposed scheme achieves SFC path selection, enhances system detection capabilities against DDoS attacks, and effectively reduces path latency for traffic traversing through SFC.</p>
<p>In future work, we aim to validate the efficacy of intelligent security service optimization methods based on the knowledge base in real network environments. We will also assess the impact of varying parameters in the GAT&#x002B;DRL model on path selection to enhance path detection capabilities.</p>
</sec>
</body>
<back>
<ack>
<p>The authors thank all colleagues who provided us with moral support.</p>
</ack>
<sec><title>Funding Statement</title>
<p>This paper was supported by the National Key R&#x0026;D Program of China under Grant No. 2018YFA0701604, and NSFC under Grant No. 62341102.</p>
</sec>
<sec><title>Author Contributions</title>
<p>Conceptualization, methodology, validation, formal analysis, data curation, writing&#x2014;original draft, visualization: Xianju Gao; Project administration, funding acquisition: Huachun Zhou; Writing&#x2014;review and editing: Huachun Zhou and Weilin Wang; Investigation, validation: Weilin Wang and Jingfu Yan. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability"><title>Availability of Data and Materials</title>
<p>The data is available with the corresponding author and can be shared on request.</p>
</sec>
<sec><title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Mehmood</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Khanan</surname></string-name>, and <string-name><given-names>M. M.</given-names> <surname>Umar</surname></string-name></person-group>, &#x201C;<article-title>Secure knowledge and cluster-based intrusion detection mechanism for smart wireless sensor networks</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>6</volume>, pp. <fpage>5688</fpage>&#x2013;<lpage>5694</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Ma</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Huang</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Enabling efficient service function chaining by integrating NFV and SDN: Architecture, challenges and opportunities</article-title>,&#x201D; <source>IEEE Netw.</source>, vol. <volume>32</volume>, no. <issue>6</issue>, pp. <fpage>152</fpage>&#x2013;<lpage>159</lpage>, <year>2018</year>. doi: <pub-id pub-id-type="doi">10.1109/MNET.2018.1700467</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Mittal</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Kumar</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Behal</surname></string-name></person-group>, &#x201C;<article-title>Deep learning approaches for detecting DDoS attacks: A systematic review</article-title>,&#x201D; <source>Soft. Comput.</source>, vol. <volume>27</volume>, no. <issue>18</issue>, pp. <fpage>13039</fpage>&#x2013;<lpage>13075</lpage>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Tu</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Zhang</surname></string-name></person-group>, <source>CSKB: A Cyber Security Knowledge Base Based on Knowledge Graph</source>. <publisher-loc>Singapore</publisher-loc>: <publisher-name>Springer</publisher-name>, <year>2020</year>, pp. <fpage>100</fpage>&#x2013;<lpage>113</lpage>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Liu</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>Construction of DDoS attacks malicious behavior knowledge base construction</article-title>,&#x201D; <source>Telecommun. Sci.</source>, vol. <volume>37</volume>, no. <issue>11</issue>, pp. <fpage>17</fpage>&#x2013;<lpage>32</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Ji</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Pan</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Cambria</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Marttinen</surname></string-name>, and <string-name><given-names>S. Y.</given-names> <surname>Philip</surname></string-name></person-group>, &#x201C;<article-title>A survey on knowledge graphs: Representation, acquisition, and applications</article-title>,&#x201D; <source>IEEE Trans. Neural Netw. Learn. Syst.</source>, vol. <volume>33</volume>, no. <issue>2</issue>, pp. <fpage>494</fpage>&#x2013;<lpage>514</lpage>, <year>2021</year>. doi: <pub-id pub-id-type="doi">10.1109/TNNLS.2021.3070843</pub-id>; <pub-id pub-id-type="pmid">33900922</pub-id></mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Jia</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Qi</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Shang</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Jiang</surname></string-name>, and <string-name><given-names>A.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>A practical approach to constructing a knowledge graph for cybersecurity</article-title>,&#x201D; <source>Engineering</source>, vol. <volume>4</volume>, no. <issue>1</issue>, pp. <fpage>53</fpage>&#x2013;<lpage>60</lpage>, <year>2018</year>. doi: <pub-id pub-id-type="doi">10.1016/j.eng.2018.01.004</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Hamid</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>A hierarchical key management method for wireless sensor networks</article-title>,&#x201D; <source>Microprocess. Microsyst.</source>, vol. <volume>90</volume>, <year>2022</year>, <comment>Art. no. 104489</comment>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Alauthman</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Aslam</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Al-kasassbeh</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Al-Qerem</surname></string-name> and <string-name><given-names>K. -K.</given-names> <surname>Raymond Choo</surname></string-name></person-group>, &#x201C;<article-title>Choo an efficient reinforcement learning-based botnet detection approach</article-title>,&#x201D; <source>J. Netw. Comput. Appl.</source>, vol. <volume>150</volume>, no. <issue>11</issue>, <year>2020, Art. no. 102479</year>. doi: <pub-id pub-id-type="doi">10.1016/j.jnca.2019.102479</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Shen</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Tu</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Qing</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name></person-group>, &#x201C;<article-title>Online botnet detection method based on ensemble learning</article-title>,&#x201D; <source>App. Res. Comput.</source>, vol. <volume>39</volume>, no. <issue>6</issue>, pp. <fpage>1845</fpage>&#x2013;<lpage>1851</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Shafiq</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Tian</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Bashir</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Du</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Guizani</surname></string-name></person-group>, &#x201C;<article-title>CorrAUC: A malicious Bot-IoT traffic detection method in IoT network using machine-learning techniques</article-title>,&#x201D; <source>IEEE Internet Things J.</source>, vol. <volume>8</volume>, no. <issue>5</issue>, pp. <fpage>3242</fpage>&#x2013;<lpage>3254</lpage>, <year>Mar. 2021</year>. doi: <pub-id pub-id-type="doi">10.1109/JIOT.2020.3002255</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Xianran</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Jing</surname></string-name></person-group>, &#x201C;<article-title>Random forest feature selection for partial label learning</article-title>,&#x201D; <source>Neurocomputing</source>, vol. <volume>561</volume>, <year>2023</year>, <comment>Art. no. 126870</comment>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Zhao</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Song</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Lee</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Chen</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Gao</surname></string-name></person-group>, &#x201C;<article-title>Ranking users in social networks with motif-based pagerank</article-title>,&#x201D; <source>IEEE Trans. Knowl. Data Eng.</source>, vol. <volume>33</volume>, no. <issue>5</issue>, pp. <fpage>2179</fpage>&#x2013;<lpage>2192</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W. -C.</given-names> <surname>Yeh</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>C. -L.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>T. -Y.</given-names> <surname>Hsu</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Liu</surname></string-name>, and <string-name><given-names>S. -Y.</given-names> <surname>Tan</surname></string-name></person-group>, &#x201C;<article-title>A new BAT and PageRank algorithm for propagation probability in social networks</article-title>,&#x201D; <source>Appl. Sci.</source>, vol. <volume>12</volume>, no. <issue>14</issue>, <year>2022, Art. no. 6858</year>. doi: <pub-id pub-id-type="doi">10.3390/app12146858</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Amelkin</surname></string-name> and <string-name><given-names>A. K.</given-names> <surname>Singh</surname></string-name></person-group>, &#x201C;<article-title>Fighting opinion control in social networks via Link recommendation</article-title>,&#x201D; in <conf-name>Proc. 25th ACM SIGKDD Int. Conf. Knowl. Dis. Data Min.</conf-name>, <publisher-loc>New York, NY, USA</publisher-loc>, <year>2019</year>, pp. <fpage>677</fpage>&#x2013;<lpage>685</lpage>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Li</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>Security service function chain based on graph neural network</article-title>,&#x201D; <source>Information</source>, vol. <volume>13</volume>, no. <issue>2</issue>, <year>2022, Art. no. 78</year>. doi: <pub-id pub-id-type="doi">10.3390/info13020078</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Lu</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Li</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Dynamic service function chain orchestration for NFV/MEC-enabled IoT networks: A deep reinforcement learning approach</article-title>,&#x201D; <source>IEEE Internet Things J.</source>, vol. <volume>8</volume>, no. <issue>9</issue>, pp. <fpage>7450</fpage>&#x2013;<lpage>7465</lpage>, <year>2020</year>. doi: <pub-id pub-id-type="doi">10.1109/JIOT.2020.3038793</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Deng</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Li</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name></person-group>, &#x201C;<article-title>Dynamic security SFC branching path selection using deep reinforcement learning</article-title>,&#x201D; <source>Intell. Autom. Soft Comput.</source>, vol. <volume>37</volume>, no. <issue>9</issue>, pp. <fpage>2919</fpage>&#x2013;<lpage>2939</lpage>, <year>2023</year>. doi: <pub-id pub-id-type="doi">10.32604/iasc.2023.039985</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Deng</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Qin</surname></string-name></person-group>, &#x201C;<article-title>Qin A path selection scheme for detecting malicious behavior based on deep reinforcement learning in SDN/NFV-Enabled network</article-title>,&#x201D; <source>Comput. Netw.</source>, vol. <volume>236</volume>, no. <issue>1</issue>, <year>2023, Art. no. 110034</year>. doi: <pub-id pub-id-type="doi">10.1016/j.comnet.2023.110034</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Shao</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Hu</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Zhao</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Graph attention network-based multi-agent reinforcement learning for slicing resource management in dense cellular network</article-title>,&#x201D; <source>IEEE Trans. Veh. Technol.</source>, vol. <volume>70</volume>, no. <issue>10</issue>, pp. <fpage>10792</fpage>&#x2013;<lpage>10803</lpage>, <year>2021</year>. doi: <pub-id pub-id-type="doi">10.1109/TVT.2021.3103416</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Qin</surname></string-name></person-group>, &#x201C;<article-title>Two-stage intelligent model for detecting malicious DDoS behavior</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>22</volume>, no. <issue>7</issue>, <year>2022, Art. no. 2532</year>. doi: <pub-id pub-id-type="doi">10.3390/s22072532</pub-id>; <pub-id pub-id-type="pmid">35408146</pub-id></mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Dong</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name></person-group>, &#x201C;<article-title>Multi-type application-layer DDoS attack detection method based on integrated learning</article-title>,&#x201D; <source>J. Comput. Appl.</source>, vol. <volume>42</volume>, no. <issue>12</issue>, pp. <fpage>3775</fpage>&#x2013;<lpage>3784</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Bi</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name></person-group>, &#x201C;<article-title>Multi-type low-rate DDoS attack detection method based on hybrid deep learning</article-title>,&#x201D; (in Chinese), <source>Chin. J. Netw. Inform. Secur.</source>, vol. <volume>8</volume>, no. <issue>1</issue>, pp. <fpage>73</fpage>&#x2013;<lpage>85</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Yang</surname></string-name></person-group>, &#x0201C;<article-title>Design and implementation of DRDoS attack detection based on machine learning</article-title>,&#x0201D; <publisher-name>Beijing Jiaotong Univ.</publisher-name>, <publisher-loc>China</publisher-loc>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Sarhan</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Layeghy</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Portmann</surname></string-name></person-group>, &#x201C;<article-title>Evaluating standard feature sets towards increased generalisability and explainability of ML-based network intrusion detection</article-title>,&#x201D; <source>Big Data Res</source>, vol. <volume>30</volume>, <year>2022, Art. no 100359</year>. doi: <pub-id pub-id-type="doi">10.1016/j.bdr.2022.100359</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Tu</surname></string-name>, and <string-name><given-names>F.</given-names> <surname>Liu</surname></string-name></person-group>, <source>Cyber-Attack Behavior Knowledge Graph Based on CAPEC and CWE towards 6G</source>. <publisher-loc>Singapore</publisher-loc>: <publisher-name>Springer</publisher-name>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Chandrashekar</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Sahin</surname></string-name></person-group>, &#x201C;<article-title>A survey on feature selection methods</article-title>,&#x201D; <source>Comput. Electr. Eng.</source>, vol. <volume>40</volume>, no. <issue>1</issue>, pp. <fpage>16</fpage>&#x2013;<lpage>28</lpage>, <year>2014</year>. doi: <pub-id pub-id-type="doi">10.1016/j.compeleceng.2013.11.024</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Ienco</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Meo</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Botta</surname></string-name></person-group>, &#x201C;<article-title>Using PageRank in feature selection</article-title>,&#x201D; in <conf-name>Proc. Sixteenth Italian Symp. Adv. Database Syst., SEBD 2008</conf-name>, <publisher-loc>Mondello, PA, Italy</publisher-loc>, <year>2008</year>, pp. <fpage>93</fpage>&#x2013;<lpage>100</lpage>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Zhuo</surname></string-name></person-group>, &#x201C;<article-title>Research on feature selection methods based on random forest</article-title>,&#x201D; <source>Tehni&#x010D;ki Vjesnik</source>, vol. <volume>30</volume>, no. <issue>2</issue>, pp. <fpage>623</fpage>&#x2013;<lpage>633</lpage>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Yang</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Multi-class DRDoS attack detection method based on feature selection</article-title>,&#x201D; <source>Res. Briefs Inform. Commun. Technol. Evol.</source>, vol. <volume>7</volume>, pp. <fpage>173</fpage>&#x2013;<lpage>187</lpage>, <year>2021</year>. doi: <pub-id pub-id-type="doi">10.56801/rebicte.v7i.127</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Ni</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Chen</surname></string-name>, and <string-name><given-names>R.</given-names> <surname>Lin</surname></string-name></person-group>, &#x201C;<article-title>Classification of aviation incident causes using LGBM with improved cross-validation</article-title>,&#x201D; <source>J. Syst. Eng. Electron.</source>, vol. <volume>35</volume>, no. <issue>2</issue>, pp. <fpage>396</fpage>&#x2013;<lpage>405</lpage>, <year>2024</year>. doi: <pub-id pub-id-type="doi">10.23919/JSEE.2024.000035</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Holmstrm</surname></string-name> and <string-name><given-names>J. E. S.</given-names> <surname>Fransson</surname></string-name></person-group>, &#x201C;<article-title>Combining remotely sensed optical and radar data in KNN-estimation of forest variables</article-title>,&#x201D; <source>For. Sci.</source>, vol. <volume>49</volume>, no. <issue>3</issue>, pp. <fpage>409</fpage>&#x2013;<lpage>418</lpage>, <year>2003</year>. doi: <pub-id pub-id-type="doi">10.1093/forestscience/49.3.409</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>