SD-CED: Detecting Compromised Devices in Software Defined Consumer Electronics Environment

Chandan Kumar, Bipal Khanal, Md. Sarfaraj Alam Ansari · IEEE Transactions on Consumer Electronics · 2025

The technological evolution of networking paradigms transforms traditional Consumer Electronics (CE) by integrating Software Defined Networking (SDN) into a next-generation framework called SDN-CE. The transformation enhances the CE device’s intelligence, connectivity, and provides flexible management capabilities. However, advancements have introduced certain vulnerabilities to the SDN-CE infrastructure. Malicious users can exploit these to gain unauthorized access and breach the SDN-CE integrity. This scientific study proposes a novel method called Software Defined Consumer Electronics Compromised Device Detection (SD-CED) to address these vulnerabilities and maintain system integrity. The SD-CED method utilizes intrusive alerts generated by Intrusion Detection Systems (IDS) to determine the status of a device, identifying whether it is compromised or operating normally. In the event of an attack, the stream of alerts produced by the IDS contains latent states. The SD-CED derives these states by calculating the E-Step and M-Step using the Baum-Welch algorithm. These steps encode a device’s forward and backward transitions to decode the device’s hidden state using the Viterbi algorithm. The SD-CED is evaluated by analysing the device’s state observation sequences and its transitioning behaviour. The findings indicate that the likelihood of a device transitioning from an intrusive alert to a compromised state is highest in the case of a Portscan attack at 94% and a Slowloris attack at 82%. In contrast, when facing a DoS attack, the device has a significantly higher likelihood, approximately 78%, of operating normally.

Read the paper · More papers on PaperTik