{"authors":[{"id":null,"fullName":"Amir Javadpour 0001","name":null,"surname":null,"rank":1,"pid":null},{"id":null,"fullName":"Forough Ja'fari","name":null,"surname":null,"rank":2,"pid":null},{"id":"orcid_______::8a08851b5dde7c6f7b06a5c546c82d9d","fullName":"Tarik Taleb","name":null,"surname":null,"rank":3,"pid":{"id":{"scheme":"orcid","value":"0000-0003-1119-1239"},"provenance":null}},{"id":null,"fullName":"Chafika Benzaïd","name":null,"surname":null,"rank":4,"pid":null}],"openAccessColor":"hybrid","publiclyFunded":false,"eoscIfGuidelines":null,"type":"publication","language":{"code":"eng","label":"English"},"countries":null,"subjects":[{"subject":{"scheme":"FOS","value":"0202 electrical engineering, electronic engineering, information engineering"},"provenance":null},{"subject":{"scheme":"FOS","value":"02 engineering and technology"},"provenance":null}],"mainTitle":"Detecting malicious nodes using game theory and reinforcement learning in software-defined networks","subTitle":null,"descriptions":["<jats:title>Abstract</jats:title>           <jats:p>Mafia, or Werewolf, is a strategic game where two teams compete to eliminate each other’s players through deception and hidden roles. The game dynamics and role interactions share notable similarities with adversarial behaviors in network security, making it a valuable framework for modeling cyber threats, particularly botnet detection. In this paper, we introduce a novel game-theoretic approach to botnet detection, leveraging the strategic deception dynamics of the Mafia game to model adversarial behavior in cybersecurity. We present a mathematical model for Mafia games, formulating winning strategies for different roles using linear relations and reinforcement learning techniques. Furthermore, we establish a direct mapping between Mafia game roles and network security components, illustrating how botnet attack patterns align with hidden-role game mechanics. Our proposed detection strategies are applied to real-world network attack scenarios, demonstrating their effectiveness in mitigating botnet threats. We evaluate the model using applicable security metrics and compare the results with existing detection methodologies to validate the approach. Our findings indicate that the suggested strategies improve detection accuracy by 12% over conventional methods. Additionally, we conduct network emulations using Mininet, simulating Mirai botnet infections. The results show that the true positive and true negative detection rates for a network modeled by the Mafia game framework reach 71% and 91%, respectively. These insights provide a foundation for integrating deception-based modeling into modern intrusion detection systems, enhancing network resilience against adaptive cyber threats.</jats:p>"],"publicationDate":"2025-04-19","publisher":"Springer Science and Business Media LLC","embargoEndDate":null,"sources":["Crossref"],"formats":null,"contributors":null,"coverages":null,"bestAccessRight":{"code":"c_abf2","label":"OPEN","scheme":"http://vocabularies.coar-repositories.org/documentation/access_rights/"},"container":{"name":"International Journal of Information Security","issnPrinted":"1615-5262","issnOnline":"1615-5270","issnLinking":null,"ep":null,"iss":null,"sp":null,"vol":"24","edition":null,"conferencePlace":null,"conferenceDate":null},"documentationUrls":null,"codeRepositoryUrl":null,"programmingLanguage":null,"contactPeople":null,"contactGroups":null,"tools":null,"size":null,"version":null,"geoLocations":null,"id":"doi_dedup___::5ab67a88eefe894b170eb2d1d4b9017e","originalIds":["1026","10.1007/s10207-025-01026-y","50|doiboost____|5ab67a88eefe894b170eb2d1d4b9017e","50|dblp________::eb2588a7d174f3cc7d4b189635c6cc0e","50|researchfi__::e18783583b49d3771749f5322a867b67"],"pids":[{"scheme":"doi","value":"10.1007/s10207-025-01026-y"}],"dateOfCollection":null,"lastUpdateTimeStamp":null,"indicators":{"citationImpact":{"citationCount":2.0,"influence":2.3897433E-9,"popularity":3.7191885E-9,"impulse":2.0,"citationClass":"C5","influenceClass":"C5","impulseClass":"C5","popularityClass":"C4"}},"projects":[{"id":"corda_____he::3d36c3bda6313daa7fe06802d9bff5af","code":"101095933","acronym":"RIGOUROUS","title":"secuRe desIGn and deplOyment of trUsthwoRthy cOntinUum computing 6G Services","funder":"European Commission","pids":[{"scheme":"doi","value":"10.3030/101095933"}]}],"organizations":[{"legalName":"Ruhr University Bochum","acronym":"RUB","id":"openorgs____::190faa05a2a184ca66a0b87dadbb1c40","pids":[{"scheme":"FundRef","value":"501100006551"},{"scheme":"FundRef","value":"501100007200"},{"scheme":"Wikidata","value":"Q309948"},{"scheme":"mag_id","value":"904495901"},{"scheme":"wikidata","value":"Q309948"},{"scheme":"OrgReg","value":"DE0071"},{"scheme":"fundref","value":"501100008835"},{"scheme":"FundRef","value":"501100006254"},{"scheme":"PIC","value":"999988812"},{"scheme":"FundRef","value":"501100008835"},{"scheme":"fundref","value":"501100006254"},{"scheme":"fundref","value":"501100007200"},{"scheme":"ISNI","value":"000000040490981X"},{"scheme":"OrgRef","value":"246889"},{"scheme":"GRID","value":"grid.5570.7"},{"scheme":"ROR","value":"https://ror.org/04tsk2644"},{"scheme":"fundref","value":"501100006551"},{"scheme":"RRID","value":"RRID:SCR_011505"}]},{"legalName":"University of Oulu","acronym":"University of Oulu","id":"openorgs____::cebd8a3c6b4278ad200788d0e8df8a36","pids":[{"scheme":"Wikidata","value":"Q1357517"},{"scheme":"fundref","value":"501100006196"},{"scheme":"GRID","value":"grid.10858.34"},{"scheme":"FundRef","value":"501100006196"},{"scheme":"fundref","value":"501100005734"},{"scheme":"fundref","value":"501100020019"},{"scheme":"fundref","value":"501100012682"},{"scheme":"FundRef","value":"501100006432"},{"scheme":"FundRef","value":"501100012682"},{"scheme":"OrgRef","value":"267975"},{"scheme":"FundRef","value":"501100018871"},{"scheme":"FundRef","value":"501100008488"},{"scheme":"fundref","value":"501100006432"},{"scheme":"fundref","value":"501100008488"},{"scheme":"ISNI","value":"0000000109414873"},{"scheme":"fundref","value":"501100018871"},{"scheme":"wikidata","value":"Q1357517"},{"scheme":"FundRef","value":"501100005734"},{"scheme":"ROR","value":"https://ror.org/03yj89h83"},{"scheme":"FundRef","value":"501100020019"}]},{"legalName":"Sharif University of Technology","acronym":"SUT","id":"openorgs____::ec543340be254f436c7e6019c4db0a07","pids":[{"scheme":"FundRef","value":"501100002398"},{"scheme":"FundRef","value":"501100006723"},{"scheme":"GRID","value":"grid.412553.4"},{"scheme":"fundref","value":"501100006674"},{"scheme":"ROR","value":"https://ror.org/024c2fq17"},{"scheme":"Wikidata","value":"Q2096604"},{"scheme":"ISNI","value":"0000000107409747"},{"scheme":"wikidata","value":"Q2096604"},{"scheme":"fundref","value":"501100006723"},{"scheme":"OrgRef","value":"453155"},{"scheme":"fundref","value":"501100002398"},{"scheme":"mag_id","value":"133529467"},{"scheme":"FundRef","value":"501100006674"}]}],"communities":[{"code":"uarctic","label":"UArctic","provenance":null}],"collectedFrom":[{"key":"openaire____::ddcdf7dcef98c2a7626bbb11d1a7b534","value":"Research.fi"},{"key":"openaire____::081b82f96300b6a6e3d282bad31cb6e2","value":"Crossref"},{"key":"openaire____::d8b68cc0a53121f6f896883a7d60c1db","value":"DBLP"}],"instances":[{"pids":[{"scheme":"doi","value":"10.1007/s10207-025-01026-y"}],"license":"CC BY","accessRight":{"code":"c_abf2","label":"OPEN","scheme":"http://vocabularies.coar-repositories.org/documentation/access_rights/","openAccessRoute":"hybrid"},"type":"Article","urls":["https://doi.org/10.1007/s10207-025-01026-y"],"publicationDate":"2025-04-19","refereed":"peerReviewed","hostedBy":{"key":"issn___print::7d916c0ca8f0e138a9f4d96886c006e7","value":"International Journal of Information Security"},"collectedFrom":{"key":"openaire____::081b82f96300b6a6e3d282bad31cb6e2","value":"Crossref"}},{"alternateIdentifiers":[{"scheme":"doi","value":"10.1007/s10207-025-01026-y"}],"type":"Article","urls":["https://doi.org/10.1007/s10207-025-01026-y"],"publicationDate":"2025-01-01","refereed":"nonPeerReviewed","hostedBy":{"key":"openaire____::d8b68cc0a53121f6f896883a7d60c1db","value":"DBLP"},"collectedFrom":{"key":"openaire____::d8b68cc0a53121f6f896883a7d60c1db","value":"DBLP"}},{"alternateIdentifiers":[{"scheme":"doi","value":"10.1007/s10207-025-01026-y"}],"license":"CC BY","accessRight":{"code":"c_abf2","label":"OPEN","scheme":"http://vocabularies.coar-repositories.org/documentation/access_rights/","openAccessRoute":null},"type":"Article","urls":["https://doi.org/10.1007/s10207-025-01026-y"],"publicationDate":"2025-04-30","refereed":"peerReviewed","hostedBy":{"key":"openaire____::ddcdf7dcef98c2a7626bbb11d1a7b534","value":"Research.fi"},"collectedFrom":{"key":"openaire____::ddcdf7dcef98c2a7626bbb11d1a7b534","value":"Research.fi"}}],"links":[{"header":{"relationType":"resultProject","relationClass":"isProducedBy","relatedIdentifier":"corda_____he::3d36c3bda6313daa7fe06802d9bff5af","relatedRecordType":"project","relationProvenance":"iis","trust":"0.897"},"collectedfrom":[{"dsId":"openaire____::3f264f93cf3b0cfc4ede188a6300455c","dsName":"CORDA - COmmon Research DAta Warehouse - Horizon Europe"}],"projectTitle":"secuRe desIGn and deplOyment of trUsthwoRthy cOntinUum computing 6G Services","code":"101095933","funding":{"funder":{"id":"ec__________::EC","shortname":"EC","name":"European Commission","jurisdiction":{"code":"EU","label":"European Union"},"pid":null},"level0":{"id":"ec__________::EC::HE","description":"Horizon Europe Framework Programme","name":"HE"},"level1":{"id":"ec__________::EC::HE::HORIZON-JU-RIA","description":"HORIZON JU Research and Innovation Actions","name":"HORIZON-JU-RIA"},"level2":{"id":null,"description":null,"name":null}},"startDate":"2023-01-01","endDate":"2025-12-31"}],"otherTitles":null,"inDiamondJournal":false,"green":false,"isGreen":false,"isInDiamondJournal":false}