
ABSTRACT Operators of low Earth orbit (LEO) access networks increasingly diagnose quality‐of‐service (QoS) degradation with observational machine‐learning attribution, yet when the candidate causes are produced by the resource‐management policy itself, observational attribution is unsafe: it assigns the degradation to factors that an operator cannot act on or that only proxy the true cause. We treat the satellite‐user assignment policy as the object of root‐cause analysis and use the assignment simulator as an intervention oracle, decomposing per‐user degradation into policy‐induced congestion and channel impairment through structural interventions, and contrasting interventional attribution with observational Shapley attribution and constraint‐based causal discovery. Across seven scenarios spanning three regions and assignment instances of up to half a million binary variables, policy‐induced congestion is the dominant degradation and the load‐balancing control recovers per‐user throughput by factors of 1.8 to 10 at fixed coverage, with paired tests that remain statistically significant under multiple‐comparison correction. Shapley attribution assigns the degradation to geography under its observational and interventional forms, and under the causal form in the main scenario. Constraint‐based discovery orients the load relation against its structural direction, and the rank correlation between link signal‐to‐noise ratio and delivered throughput inverts as offered load grows. The interventional analysis identifies the policy as the actionable cause and separates degradation that the policy can repair from degradation bounded by fleet capacity or by the channel, a distinction that observational root‐cause analysis does not provide.
ABSTRACT This paper presents the Blockchain‐Enhanced Secure Data‐Driven Quality of Service (QoS) Framework (BES‐DQF) for security and efficiency of wireless sensor networks (WSNs) and Internet of Things (IoT) systems. The framework combines data integrity verification using blockchain, smart contract enforcement, security compliance, and deep learning algorithms for QoS optimization. The novel combination of these technologies ensures that only verified data enters the deep learning model, avoiding adversarial attacks, such as data poisoning and Sybil attacks. Experimental results show that the accuracy of BESDQF in QoS prediction is 94%, and the attack detection rate is 92%, which is better than that of traditional QoS systems, which are only 93% accurate and 61% attack detection. In addition, BES‐DQF maintains an acceptable latency overhead (+6.8%) and energy consumption (+5.4%), proving it to be practical for large‐scale IoT applications. Our contributions include (1) the development of a secure blockchain‐integrated QoS optimization model, (2) the introduction of a novel attack‐resistant learning pipeline, and (3) a comprehensive experimental validation to show the superior performance and robustness of BES‐DQF in adversarial conditions. Future work will be done on consensus optimization for scalability and federated learning for enhanced privacy and decentralization.
ABSTRACT Cryptocurrencies, beginning with Bitcoin, have been widely adopted as they enable transactions while preserving user privacy. However, prior studies have revealed that the anonymity provided by cryptocurrencies is incomplete, with Bitcoin in particular relying on pseudonymity rather than true anonymity. To address this limitation, a variety of coin mixing protocols have been proposed to enhance anonymity. Yet, enhanced anonymity also carries the risk of misuse by malicious actors, and coin mixing protocols are no exception. Several mixing services built on these protocols have been employed in laundering illicit funds from major hacks, drawing the attention of regulators. This paper analyzes the strengths and limitations of existing coin mixing protocols and evaluates them from the perspectives of privacy, security, efficiency, and practicality. Furthermore, it reviews research on the detection of mixing protocols and discusses future directions for advancing this line of work.
ABSTRACT Edge computing networks must support heterogeneous services with sharply different latency, reliability, and bandwidth requirements under time‐varying traffic, limited radio capacity, and distributed compute resources. These challenges become more critical when orchestration decisions must be coordinated across multiple edge regions with strict response‐time constraints. This paper proposes a two‐timescale O‐RAN‐native framework for priority‐aware resource orchestration and task offloading in edge computing networks. The framework follows the O‐RAN control hierarchy by assigning long‐timescale workload analysis, policy adaptation, and service‐aware resource planning to the Non‐RT RIC, whereas a Near‐RT RIC xApp performs fast runtime decisions for task offloading, bandwidth assignment, and compute allocation according to instantaneous network conditions. To support cooperative control among distributed edge nodes, the proposed design combines graph‐based internode context modeling with a priority‐aware decision mechanism that captures queue state, service urgency, link quality, and available processing resources. This architecture enables rapid local adaptation without losing global policy consistency. Simulation results under dynamic multiservice workloads show that the proposed framework reduces service delay, improves completion reliability for urgent traffic, and increases overall resource efficiency compared with representative baseline methods.
ABSTRACT This special issue explores emerging trends and technologies in ubiquitous network intelligence for next‐generation mobile edge network management and aims to provide valuable insights into the future of intelligent network management in an increasingly interconnected world. We received 48 original research contributions from different geographies, focusing on key challenges such as efficient data gathering from IoT and sensor nodes, distributed learning algorithms for network management, advanced Kubernetes orchestrators for inference, and security in 5G/6G networks. After a rigorous review process, involving three to seven experts per paper and oversight from guest editors, we selected 13 high‐quality research papers, representing a 27% acceptance rate. These papers collectively address the challenges and opportunities in realizing ubiquitous network intelligence from two crucial perspectives: AI for networking and networking for AI. Further, we summarize several open challenges that need to be addressed in the near future related to intelligent ubiquitous mobile edge network management.
As Internet middleboxes become increasingly prevalent, their influence on traffic streams introduces both significant challenges and opportunities for network management. Enabling end hosts to detect these middleboxes is not only beneficial but, in many cases, crucial. Existing detection approaches are typically ad hoc, designed to target a specific middlebox type. In contrast, we propose a generalized framework capable of detecting a broad range of middleboxes. To illustrate this concept, we use transparent middleboxes as an example-middleboxes that interfere with traffic without altering its contents, while maintaining the appearance of simple routing and forwarding. This transparency property makes end-to-end detection of such middleboxes particularly challenging. In this paper, we present a generalized framework for detecting transparent middleboxes. Using this framework, we detect three common types of middleboxes: network compression, traffic prioritization, and traffic shaping. Our results are validated through analysis, network simulations, and live Internet experiments involving real middleboxes.
Multicloud environments provide multicloud environment provision of cyber-attacks demands to have flexible security mechanisms, which can dynamically respond to evolving patterns of attacks. In this paper, a novel framework of Self-Adaptive Federated Intelligence known as Self-Adaptive Federated Intelligence of Real-time security Enforcement (SAFIRE) is introduced, which implements a combination of real-time security intelligence extraction, cross-cloud threat correlation, and adaptive learning to provide a more efficient security solution. This model uses a security insight system that trains itself to analyze multicloud attack patterns dynamically in order to provide real-time detection of advanced threats. A dynamic learning mechanism that provides changes in the dynamic trends in security decision-making is an important aspect of the model. A hierarchical classification module also divides the different types of attacks and corrects mitigation measures based on this. By employing an attention-based system of cross-cloud adaptation, the suggested system will enable a number of cloud service providers to collaborate toward greater levels of security in a noncentralized fashion. The key strength of this work is its potential to trace the pattern of multicloud attacks, adjust security policy in real-time situations, and enhance its threat detection with limited reliance on the centralized view of data accumulation. As experimental findings show, the proposed methodology is more accurate (98.9%), less prone to false positives (1.9), lower response time (180 ms), and less resource-intensive (4%). The findings indicate that the model takes minimal time to adapt to emerging cyber-attacks with high detection and low overhead rates and is therefore interesting as a solution to secure cloud infrastructure of the future.
Ensuring transparency and integrity in agricultural data management is a critical challenge as the sector increasingly relies on advanced technologies. The primary problem is maintaining data traceability and security throughout the supply chain. In this paper, we explore the use of directed acyclic graph (DAG) technology to address these challenges in agricultural environments. We have implemented the corresponding software to test the following three DAG-based data storage and traceability scenarios: serverless, utilizing the interplanetary file system (IPFS), and a centralized server for data storage and transaction validation. Our results demonstrate that DAG and PoA ensure fast and secure transaction validation, crucial to maintaining trust and efficiency in the agricultural supply chain. We find that each scenario presents unique strengths and limitations, suggesting that a hybrid approach may offer the most robust solution for agricultural data management.
The growing demands for network capacity and the increasing complexities of modern network environments pose significant challenges for efficient network management and orchestration. To solve these problems, artificial intelligence (AI) techniques have attracted attention to enable automated network management, to enhance the quality of service (QoS), and to ensure the service level objectives (SLOs). However, there still remain significant limitations in automated network management within the paradigm of intent-based networking (IBN). In this paper, we propose intent-based network management methods using large language models (LLMs) for NFV environment. The proposed methods translate user's high-level intents expressed in natural language and generate the executable network and service management policies such as service function chaining (SFC), autoscaling, and network security. To improve domain understanding and generation accuracy, we apply domain adaptation techniques for LLMs including prompt engineering, retrieval-augmented generation (RAG), and iterative feedback mechanisms. Evaluations conducted on a real Kubernetes cluster showed that the proposed methods significantly improve intent translation and policy generation performance and effectively fulfill user intents, compared with baseline approaches. These results indicate the feasibility of leveraging LLMs to enable practical end-to-end intent-based automation for cloud-native NFV management.
Multiaccess edge computing (MEC) reduces end-to-end (E2E) latency by offloading computation from user equipment (UE) to nearby edge hosts, but host-selection policies in simulators such as Simu5G typically focus on service availability or CPU headroom. They do not explicitly account for dynamic UE-host latency and can therefore steer delay-sensitive flows to topologically distant or temporarily congested hosts, inflating tail delay and limiting effective throughput. We extend Simu5G's ETSI-compliant MEC orchestrator with LatencyAwareSelectionBased, a lightweight host-selection policy that jointly accounts for (i) a dynamic UE-host delay estimate derived from measurable run-time delay statistics and smoothed via an exponential moving average and (ii) the host's normalized CPU load. These two signals are combined in a simple score, S(h) = L(h) (1 + a C(h)), controlled by a single trade-off parameter a. The policy is implemented as a plug-in selection module activated through Simu5G's native selectionPolicy hook, requiring only minimal changes to existing scenarios and preserving the standard orchestration pipeline. We evaluate the proposed policy in Simu5G's MultiMecHost scenario under three operating points (Best, Moderate, and Worst) and an additional multitenant burst configuration with up to 20 UEs generating bursty arrivals. Using Simu5G scalar outputs, we take downlink MAC delay and per-UE throughput as primary metrics and also examine CPU-only, latency-only, and mixed-score variants for different values of a. Across all configurations, the latency-aware policy consistently maintains low tail latency (95th-percentile downlink MAC delay below approximately 7 ms) while improving per-UE throughput relative to Simu5G's default CPU-and service-based strategies and avoiding persistent host hot spots. The resulting design provides a simple, reproducible baseline for latency-sensitive MEC orchestration and a practical integration point for future mobility-aware and learning-based host-selection schemes.
The combination of control plane flexibility and data plane programmability enables the emergence of groundbreaking features in network systems. One of the key advancements is the provision of new network monitoring capabilities. This innovation has the potential to meet diverse demands arising from unique characteristics and specific requirements of certain network infrastructures, such as the Internet of Things (IoT). However, existing monitoring approaches primarily focus on assessing the overall network condition and lack the capability to accurately analyze specific target events. This presents a significant challenge for network management, where identifying and tracking critical events is a fundamental requirement. To address this limitation, this paper proposes a latency-aware proactive event monitoring (LPEM) scheme, a novel monitoring mechanism tailored to IoT requirements. LPEM leverages the programmable features of software-defined networking (SDN) and Programming Protocol-Independent Packet Processors (P4) to identify specified events and proactively report relevant information to a controller. This enables the controller to track specific events while simultaneously monitoring the network latency they experience in the network. Measurement results demonstrate that LPEM effectively tracks target events and monitors their experienced link latency, regardless of variations in network traffic. Furthermore, LPEM enables real-time monitoring with millisecond-level response times and enhances monitoring reliability by addressing both the loss of monitoring data and unexpected events.
Software-defined networking (SDN) enables flexible, programmable networks, but in large deployments, poor controller placement can raise latency and energy use. This paper presents a practical in-band SDN model and an optimization method that jointly accounts for control-plane delay and device power consumption to place controllers and configure switches. We formulate the problem as a binary integer programming (BIP) that decides controller locations, which switches remain active, and port bit-rates and routes. Experiments on a large WAN topology (Janos-US) show the approach can cut total network energy by up to 15% while keeping control-plane delays within required bounds, offering network operators a straightforward way to trade responsiveness for energy savings.
Automated and intelligent systems now manage networks, unlike in the past when static protocols and manual configuration dominated the field. This review looks at the transformations network management has undergone, starting from manual methods to evolving to Policy-Based Network Management (PBNM), Software-Defined Networking (SDN), and eventually Intent-Based Networking (IBN). It also analyzes the key enabling technologies, foundational architectures, and representative implementations of each network management system. By presenting the operational strategies, technological shifts, and motivations for each network management phase, the article articulates the reasons change happens in the approach taken to manage a network. This review also focuses on the advantages of SDN and IBN, especially concerning automation, threat management, policy enforcement, and scalability. Furthermore, the review explores emerging trends like AI-powered networks, Zero Trust security, integration of 5G-6G, blockchain uses, and the possibilities offered by quantum networking. By synthesizing technological insights and real-world adoption scenarios, the paper offers a comprehensive perspective on the future trajectory of intelligent and autonomous network management systems.
The convergence of cloud computing, machine learning (ML), and network function virtualization (NFV) offers significant opportunities for advancing network infrastructure management by providing efficient, flexible, and scalable resource utilization. This study aims to provide a comprehensive review of the primary challenges and explores state-of-the-art solutions in cloud computing for resource allocation (RA) specific to NFV environments. The paper highlights the importance of adopting multifaceted strategies to optimize RA and enhance the efficiency, and adaptability of cloud systems that handle RA without ML, and with ML in NFV settings. In addition, gap identification is also discussed, emphasizing many needs: (1) the need for extending the NFV RA in the case of wireless networks; (2) the need for enhanced security protocols to fully harness the potential of ML within resource function virtualization (RFV) environments, ensuring that network infrastructures are not only efficient but also resilient and secure; and (3) the need to develop more efficient ML-based RA for NFV, considering the trade-off between performance and accuracy.
Cryptocurrencies represent a significantly utilized class of digital assets, encompassing a diverse array of tokens and coins available for trading purposes. In this study, the integration of machine learning algorithms with an arbitrage trading strategy across cryptocurrency exchanges is explored. The objective is to scrutinize prominent cryptocurrency pairs characterized by high volatility, vulnerability to speculation, regulatory gaps, liquidity constraints, and heavy-tail distribution, with the intention of training the model to predict the potential for arbitrage. To differentiate from competitors who await rare arbitrage opportunities, a novel approach is introduced to enhance arbitrage profitability. The primary innovation of this study lies in demonstrating the capability to predict profitable arbitrage opportunities in discrete intervals in advance, by incorporating sophisticated confidence level metrics to initiate arbitrage trades only when the model's predictions demonstrate substantial certainty. The findings indicate that the profitability of the entire strategy exceeds 100% within a 1-week timeframe.
In recent years, the emergence of new network architectures has seen substantial growth. Among these advancements, distributed server architectures and server load balancing have gradually become key areas of focus. This paper introduces a mechanism called consistent hashing with congestion awareness (CHCA), designed to optimize load balancing. CHCA enhances traditional algorithms by minimizing data migration when servers are added or removed. Additionally, this mechanism incorporates the least connections method to prevent certain servers from becoming overloaded due to persistent traffic, thereby mitigating server hotspots. Aiming to support this mechanism, two custom headers, the forward header and the MRI header, are introduced using P4 switches. The forward header allows P4 switches to make dynamic packet forwarding decisions based on optimal paths at runtime, eliminating the need for a static routing table. Meanwhile, the MRI header records the load information from all traversed P4 switches, enabling the load balancing forwarding strategy to adapt in real time based on current network conditions.
The demands of today's 5G mobile network, especially low latency and high bandwidth, are a big challenge for the 5G Core (5GC) provider. The most critical user data packet handler in the 5GC network function (NF) is the user plane function (UPF), which is responsible for moving data from the user equipment to the destination data network, and vice versa. Existing work mainly focuses on implementing UPF using the key technologies of high‐speed data processing. In this paper, with a mobile core provider called free5GC for a stand‐alone (SA) 5G network, we share our experience with the implementation of UPF by using a programmable hardware appliance, which can offer more Tbps compared with the implementation of software UPF that can offer only a few hundred Gbps. For that, we demonstrate how to build up a more flexible architecture of UPF by using the software‐defined networking (SDN) concept due to the opacity of protocol specification. We split the UPF control signal implementation into a software application and user data packet processing into a programmable hardware appliance. We also show how to integrate a number of current UPF data plane free5GC implementations, such as Data Plane Development Kit (DPDK), Linux kernel module, and SmartNIC. Furthermore, we analyze and make use of microservices to support the specific features of the UPF data plane that cannot be implemented in a programmable hardware appliance. We tested our free5GC mobile network and the new UPF design architecture that can run on a real programmable hardware appliance from Accton CSP‐7551. The evaluation results show that our programmable user plane can reach the line rate.
The core of IPv6 active address discovery lies in identifying operational network devices, which serve as the foundation for various network applications. However, the vast address space of IPv6 presents significant challenges to network discovery, including inefficiencies of traditional scanning tools (such as ZMap and Masscan), uncertainties arising from dynamic address allocation, sparsity in address distribution, and limitations of current discovery techniques in regions lacking seed addresses. To address these challenges, researchers have developed various address discovery methods aimed at maximizing the identification of active IPv6 addresses within constrained resource budgets. This paper summarizes and analyzes existing active address discovery methods and evaluates their performance in real-world environments. Our work includes classifying detection techniques and outlining the current research landscape for address discovery in regions without seed addresses. Through experiments conducted in real network environments, we evaluate and contrast different probing algorithms using four performance metrics: hit rate, hierarchical prefix coverage, aliased addresses, and address discovery rate. Furthermore, we discuss the challenges faced by current IPv6 active address discovery methods in practical applications. Despite numerous advancements, the field of IPv6 active address discovery still requires further research and exploration.