Telemetry-Aware Risk-Adaptive Routing for Link-Flooding Resilience in Software-Defined Networks ()
1. Introduction
Software-defined networking separates forwarding behavior from logically centralized control and enables systematic path changes [1]. Its programmability also enlarges the consequences of inaccurate or delayed network state, so resilience claims must identify exactly what the controller can observe [2].
Low-rate link-flooding attacks can congest selected transit links without sending traffic directly to the victim [3]. Defenses that perturb routes can increase attacker cost, but their benefit depends on whether congestion can be inferred quickly enough [4]. Evaluations that disclose the attack set or instantaneous attack load to a routing controller risk overstating deployable resilience.
This study asks how much service protection risk-adaptive path diversity provides when attack state is hidden and the controller receives only imperfect telemetry. Attack ground truth exists only in the traffic generator and evaluator; routing decisions use noisy delayed measurements, detector output, and controller state.
The contributions are an observable telemetry and detection layer; fair information timing for all policies; detector-quality sensitivity; four structural ablations; and paired confidence intervals over fixed seeds. Figure 1 summarizes the information boundary and the controller workflow.
Figure 1. Information flow from generated traffic through noisy delayed telemetry to detector-derived risk and routing decisions.
2. Related Work
Software-driven wide-area traffic engineering demonstrated centralized allocation over multiple paths [5], while OSPF weight optimization established a classical link-cost baseline [6]. These systems motivate load-aware routing but do not by themselves model adversarial uncertainty.
Disjoint-path construction [7] and loopless k-shortest path enumeration [8] provide the topology-only diversity used in this study. TARA uses the same candidate set as its ablations, preventing candidate-generation differences from confounding the comparison.
Exponentially weighted state estimation is a standard way to smooth noisy time series [9]. Intrusion-detection guidance distinguishes sensor evidence, detection decisions, and ground truth and emphasizes false alarms and missed detections [10]. Those distinctions determine the detector model.
Congestion-control principles [11], differentiated-services architecture [12], and the end-to-end argument [13] caution against treating a controller as omniscient. Simulation studies also require explicit scope because Internet behavior is difficult to reproduce in full [14]. The present model therefore isolates route selection and telemetry quality rather than claiming Internet-scale realism.
Recent work has combined link-flooding prevention with alternate-path and topology-obfuscation mechanisms [15], measured SD-WAN delay through in-band telemetry [16], and used monitored data-plane state for reliable path prediction [17]. Scalable software-defined sensor networks likewise expose controller-update and state-prediction overheads [18]. Link verification based on observed latency [19] and credibility-oriented link-flooding mitigation [20] reinforce the importance of detection uncertainty. Control-plane resilience in SD-WANs [21] and flooding defenses in information-centric networks [22] provide complementary perspectives on failure containment and adversarial traffic.
3. System Model and Information Boundary
Figure 2 shows one generated 36-node backbone. Red links are attack targets in the evaluator. The controller never receives those labels; the coloring exists only to explain the simulated ground truth.
Table 1 separates variables available to the traffic generator, telemetry process, controller, and evaluator. This separation is enforced in the executable code: routing functions accept measured risk and utilization state but not the attack dictionary.
Table 1. Information boundary.
Component |
Available state |
Unavailable state |
Traffic generator |
Demand matrix; attack schedule |
Controller estimate |
Telemetry process |
Actual utilization and delay for measurement generation |
Routing objective |
Controller |
Delayed noisy measurements; detector risk; topology |
Attack labels; attack load; future measurements |
Evaluator |
Ground truth and delivered traffic |
No decision authority |
For link e and epoch t, Equation (1) defines measured utilization and delay as physical values plus zero-mean detector-scenario noise.
(1)
Noise standard deviations are 0.025, 0.060, and 0.110 utilization units and 0.35, 0.75, and 1.25 ms for strong, moderate, and weak detection.
Figure 2. Representative synthetic backbone. Red links are evaluator-only attack ground truth and are not exposed to any routing policy.
4. Telemetry Derived TARA
4.1. Delayed EWMA Detector
The detector converts delayed utilization and delay measurements into bounded normalized anomaly scores. These quantities are denoted as anomaly scores rather than statistical z-scores because they are referenced to fixed operating thresholds rather than estimated sample means and standard deviations. For delayed measured utilization (
) and delayed measured latency (
), the two anomaly components are
(2)
where (
) is the nominal propagation latency of link (e). Detector evidence is
The utilization baseline of 0.62 represents the nominal utilization level above which congestion evidence begins to accumulate. For delay, evidence begins when measured latency exceeds 1.15 times nominal propagation latency. Both signals are clipped to [0, 1].
A detector-quality-specific calibration function is applied to the anomaly evidence:
where (
) is 0.95, 0.80, or 0.62 for the strong, moderate, and weak detector settings, respectively. Link risk is then updated using
(3)
where (
) is the detector delay.
To simulate imperfect detection, an attack-associated evidence value is attenuated to 12% of its original magnitude when a configured false-negative event occurs. For an unattacked link experiencing a configured false-positive event, alert-like evidence between approximately 0.58 and 0.93 is injected before calibration. These stochastic error events use the probabilities reported in Table 2.
For reporting detector precision and recall, a link is classified as detector-positive when (
). Precision and recall are computed over link-epoch decisions during attack-active evaluation epochs by comparing this detector output with evaluator-only attack ground truth. Ground-truth attack labels are used only by the simulation generator to impose controlled false-negative/false-positive events and by the evaluator to score detector performance; they are never supplied to the routing controller.
Table 2. Detector quality scenarios.
Quality |
Utilization noise SD |
Delay noise SD |
False positive |
False negative |
Delay |
Strong |
0.025 |
0.35 ms |
1% |
5% |
1 epoch |
Moderate |
0.060 |
0.75 ms |
4% |
15% |
2 epochs |
Weak |
0.110 |
1.25 ms |
10% |
30% |
3 epochs |
4.2. Utilization Prediction and Path Cost
For a candidate path (p), let
denote nominal propagation latency,
denote the maximum predicted utilization after accounting for provisional traffic (
) already assigned during the current routing pass, and
denote mean detector-derived path risk.
The TARA path score is
(4)
Candidate paths are initially ordered by (
). The lowest-cost path becomes the primary path. When path splitting is enabled, the secondary path is selected from the remaining candidates by first minimizing the number of links shared with the primary path and then minimizing (
) among equal-overlap candidates. The no-overlap ablation omits this shared-link preference. Traffic shares across the selected paths are proportional to (
) and normalized to sum to one.
4.3. Policy Definitions and Fair Access
Table 3 identifies what each policy does with the common information stream. Static and topology-disjoint routing intentionally ignore telemetry after initialization; this is a policy restriction, not unequal information delivery. Reactive routing uses the same risk signal as TARA and changes a route only when its current path contains a link whose risk is at least 0.55.
Table 3. Policies and ablations.
Policy |
Risk |
Utilization forecast |
Diversity |
Overlap control |
Static shortest path |
No |
No |
No |
No |
Reactive rerouting |
Threshold only |
No |
No |
No |
Topology disjoint |
No |
No |
Two paths |
Topology only |
Full TARA |
Continuous |
Yes |
Two paths |
Yes |
No risk term |
No |
Yes |
Two paths |
Yes |
No overlap term |
Continuous |
Yes |
Two paths |
No |
Single path |
Continuous |
Yes |
No |
No |
No utilization prediction |
Continuous |
Current EWMA |
Two paths |
Yes |
5. Experimental Design
5.1. Scenario Generation and Reproducibility
For each seed, 36 nodes are placed independently and uniformly in a
two-dimensional coordinate region. Each node is connected to its four nearest neighbors, after which 18 additional undirected node pairs are selected uniformly without replacement to increase path diversity. Duplicate undirected links are merged. Propagation latency for a link between nodes
and
is generated as
ms, where
is Euclidean distance and
. Capacities of
nearest-neighbor links are sampled from
, while the additional random links use
.
Each topology contains 90 legitimate demands. Source and destination nodes are sampled uniformly from distinct node pairs. The offered rate for each demand is sampled from a lognormal distribution with log-location 1.05 and log-scale 0.42 and is clipped to the interval 1 - 8 simulation rate units.
Initial shortest paths are computed using propagation latency as link cost. For every demand, up to four candidate paths are generated through repeated shortest-path searches in which links used by an already discovered path have their temporary cost multiplied by 2.0. This produces alternative paths while retaining a bounded candidate set.
Attack targets are selected from links that occur most frequently in the initial shortest paths. Specifically, links are ranked by the number of baseline paths that
traverse them, and the highest-ranked
links are selected as attack
targets. The target set remains fixed within a seed-scenario trial.
The simulation contains 10 routing epochs, with attacks active during epochs 4 - 10. For every attacked link (e) and attack-active epoch (t), attack load is generated as
,
where (
) is link capacity,
is the configured attack-intensity factor, and
introduces epoch-level fluctuation. Random streams are deterministically derived from the simulation seed, attack intensity, and detector setting so that policies evaluated within a scenario experience paired underlying conditions.
Table 4 gives the complete design. Each seed fixes node coordinates, capacities, demands, attack targets, measurement noise, false-alarm draws, and attack fluctuations. Policies within that scenario are therefore paired.
Table 4. Executed simulation design.
Factor |
Values |
Seeds |
24, numbered 1001 - 1024 |
Topology |
36 nodes; geometric links; 90 demands |
Epochs |
10 total; attack active in epochs 4 - 10 |
Attack load |
60%, 100%, or 140% of target-link capacity |
Detector quality |
Strong, moderate, weak |
Policies |
3 baselines, full TARA, 4 structural ablations |
Trials |
1728 seed-scenario-policy records |
Primary outcomes |
Delivered demand and 95th-percentile path latency |
Attack-active epochs |
4 - 10 of 10 |
Attack targets |
Highest baseline-path-centrality links;
targets per topology |
Attack fluctuation |
Independent multiplier
per target link and epoch |
Candidate paths |
Up to 4 per demand |
The 95% paired interval for a comparison uses Equation (5), where each difference is computed between policies sharing a seed and scenario.
The two-sided 95% paired confidence interval is computed using the Student-(t) distribution:
(5)
where is the mean paired difference,
is the sample standard deviation of the paired differences, and
. For the reported comparisons,
and
.
The interval is descriptive for the executed seed population; no claim is made that synthetic topology seeds are a random sample of deployed networks.
5.2. Attack Effects and Evaluation Metrics
Attack traffic and legitimate routed traffic contribute jointly to link load. For each link
, utilization is
For a legitimate path (p), the deliverable fraction is limited by its most capacity-constrained link. The delivered fraction associated with each path share is therefore computed from
Demand delivery is the weighted sum of the fractions delivered through its selected paths.
The performance-latency model uses total utilization to approximate congestion-induced delay. For link
, the queueing factor is
The primary results aggregate only the seven attack-active epochs (epochs 4 -10). Trial-level delivered demand is the mean delivery percentage across those epochs. At each epoch, the 95th percentile of modeled path latency is computed across the 90 legitimate demands; the reported trial-level P95 latency is the 95th percentile of those seven epoch-level P95 values.
Dropped or partially undelivered demand is represented through the delivery-ratio metric and is not assigned an artificial infinite or penalty latency. The latency statistic therefore represents modeled path delay under the offered load rather than packet-completion latency for successfully delivered traffic only.
6. Results
6.1. Principal Scenario
Figure 3 and Table 5 report the moderate-detector, 100%-attack scenario. Full TARA delivered 97.25% (SD 1.20) and reactive rerouting delivered 93.18% (SD 2.52). The paired difference was 4.07 percentage points, with a two-sided 95% paired t-interval from 3.39 to 4.74 percentage points.
Figure 3. Mean delivered demand for the principal scenario across 24 paired seeds.
Table 5. Principal scenario results.
Policy |
Delivery mean ± SD (%) |
P95 latency mean ± SD (ms) |
Route changes |
Static shortest path |
92.93 ± 2.77 |
33.47 ± 5.65 |
0.0 |
Reactive rerouting |
93.18 ± 2.52 |
33.61 ± 5.74 |
15.2 |
Topology disjoint |
94.44 ± 2.41 |
27.70 ± 5.36 |
0.0 |
Full TARA |
97.25 ± 1.20 |
27.15 ± 4.93 |
91.8 |
No risk term |
97.19 ± 1.18 |
27.37 ± 4.97 |
44.2 |
No overlap term |
97.16 ± 1.22 |
27.45 ± 4.44 |
91.4 |
Single path |
97.07 ± 1.04 |
32.67 ± 5.25 |
94.0 |
No utilization prediction |
97.08 ± 1.26 |
27.23 ± 4.95 |
89.3 |
Full TARA’s mean 95th-percentile latency was 27.15 ms. Its paired difference from reactive routing was −6.47 ms (two-sided 95% paired t-interval: −7.94 to −5.00 ms); negative values favor TARA.
6.2. Detector Quality Sensitivity
Figure 4 shows degradation as detector quality weakens. Full TARA delivery was 97.89% with strong detection and 96.71% with weak detection. Table 6 pairs those service results with the detector precision and recall produced by the simulated measurement pipeline.
Figure 4. Delivery under strong, moderate, and weak detector settings. Axis values 1, 2, and 3 denote strong, moderate, and weak.
Table 6. Full TARA detector sensitivity at 100% attack.
Detector |
Delivery mean ± SD (%) |
Precision (%) |
Recall (%) |
Strong |
97.89 ± 0.95 |
99.65 |
25.06 |
Moderate |
97.25 ± 1.20 |
93.85 |
7.74 |
Weak |
96.71 ± 1.31 |
20.83 |
0.78 |
6.3. Attack Load Sensitivity
Figure 5 reports all attack levels under moderate detection. The separation among policies grows as capacity pressure increases, but detector delay means that no telemetry-driven policy avoids the initial attacked epochs.
6.4. Ablation and Overhead
Figure 6 compares Full TARA with its four structural ablations in the principal scenario. The single-path ablation has the largest latency, showing that diversity rather than the risk term alone explains much of the resilience.
Figure 5. Delivered demand under 60%, 100%, and 140% target-capacity attack load with moderate detector quality.
Figure 6. Mean 95th-percentile latency for full TARA and four ablations in the principal scenario.
Figure 7 confirms that strong detection improves both precision and recall; weak detection reduces recall and increases false-alert exposure. Figure 8 shows that this additional adaptivity requires substantially more route changes than reactive rerouting.
Figure 7. Mean detector precision and recall obtained from the simulated telemetry pipeline.
Figure 8. Mean controller route changes in the principal scenario.
7. Discussion
TARA preserves more demand than reactive and static routing in the modeled scenarios when risk must be inferred from imperfect telemetry. This result does not imply that the controller identifies attacked links correctly in every epoch. Detection delay guarantees a period in which route decisions use stale pre-attack state.
Ablation differences are modest among full TARA, no-risk, no-overlap, and no-prediction variants in the principal scenario. Path splitting produces the largest structural change. The continuous risk term becomes more relevant as detector quality improves; under weak detection its benefit can shrink or reverse because false positives redirect flows unnecessarily.
Operationally, the delivery gain must be balanced against route churn. Full TARA changes more routes than reactive rerouting because it adjusts split paths as observed utilization evolves. Rate limiting, minimum dwell times, and rule-capacity constraints should be added before controller deployment.
8. Threats to Validity and Limitations
The topology generator is geometric and smaller than a carrier backbone. Traffic is stationary within an epoch, links are undirected, queueing is an analytic approximation, and the attacker does not adapt to observed route changes. These assumptions limit external validity.
Detector errors are parameterized rather than learned from packet traces. The strong, moderate, and weak settings are controlled sensitivity cases, not measured operating points. Ground truth is used only to generate false-negative and false-positive events and to score detector performance; it is never passed to routing code.
The paired confidence intervals describe variation across the fixed synthetic seeds. They do not account for uncertainty in the assumed traffic, detector, or queueing models. Hardware-in-the-loop evaluation with controller and switch timing remains necessary.
9. Conclusion
Full TARA delivered 97.25% of demand in the principal scenario, 4.07 percentage points more than reactive rerouting on paired seeds, while its paired 95th-percentile latency difference was −6.47 ms. Path diversity provides the dominant benefit, whereas the risk, overlap, and utilization-prediction terms show comparatively modest differences. Detector degradation changed full-TARA delivery from 97.89% to 96.71%, confirming that resilience depends on telemetry quality. These findings are simulation-based and do not constitute evidence of production deployment performance.
Data and Code Availability
The study uses no proprietary or personal data. The complete simulation source, fixed random-seed ranges, seed-level result files, aggregated tables, and publication figures are included in the accompanying reproducibility package. The code regenerates all numerical results and figures reported in this manuscript.
Funding
This research received no external funding.
Author Contributions
Utham Kumar Anugula Sethupathy: Conceptualization, methodology, software, validation, formal analysis, investigation, data curation, writing—original draft, writing—review and editing, and visualization. Vijayanand Ananthanarayanan: Validation, formal analysis, writing—review and editing.
Appendix A. Reproduction Procedure
Python run_experiments.py --study ijcns. It writes every seed-policy record, grouped summaries, figures, and an experiment manifest. The seed, detector, attack load, and policy columns uniquely identify each trial; Table A1 lists the expected checks.
A complete trial is uniquely determined by the topology seed, attack-intensity setting, detector-quality setting, and routing policy. The seed determines topology geometry and base link characteristics, while deterministic derived random streams determine demands, attack fluctuations, telemetry noise, false-positive events, and false-negative events. Policies within a common seed/intensity/detector scenario therefore operate under paired stochastic conditions. The main experiment contains
seed-scenario-policy records.
Table A1. Reproduction checks.
Check |
Expected value |
Seed range |
1001 - 1024 |
Main records |
1728 |
Attack information in routing function |
Absent |
Figure resolution |
500 dpi PNG |
Primary uncertainty |
Paired 95% confidence interval |