ERINDA: A novel framework for Enhancing the Resilience of Industrial Networks against DDoS Attacks with adaptive recovery

被引:0
|
作者
Alrumaih, Thuraya N. I. [1 ]
Alenazi, Mohammed J. F. [2 ]
机构
[1] Princess Nourah Bint Abdulrahman Univ, Coll Comp & Informat Sci, Dept Informat Technol, POB 11671, Riyadh 84428, Saudi Arabia
[2] King Saud Univ, Coll Comp & Informat Sci, Dept Comp Engn, Riyadh, Saudi Arabia
关键词
Critical infrastructure; Cyber resilience; Industrial control system (ICS); Cybersecurity; Distributed denial-of-service (DDoS) attacks; CONTROL-SYSTEMS; MITIGATION; SECURITY; IOT;
D O I
10.1016/j.aej.2025.02.042
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The increasing threat of distributed denial-of-service (DDoS) attacks targeting the availability of critical infrastructure systems controlled by industrial control systems (ICS). DDoS attacks endanger the high-reliability requirements ICSs by overloading network and system resources, causing malfunction or ceasing operations. Recognizing the severe consequences of service disruptions in these environments, we present a novel framework for Enhancing the Resilience of Industrial Networks against DDoS Attacks (ERINDA), designed to minimize downtime and maintain functionality. It consists of a two-phase approach that combines proactive and reactive strategies to efficiently mitigate DDoS attacks while minimizing service disruptions. First, network traffic is continuously monitored to detect any anomalies indicating potential attacks. Second, response mechanisms are activated upon an actual attack identification to quickly neutralize the threat and restore the integrity of the network. Experimental results, obtained using ns-3 network simulations mimicking a smallscale industrial network topology, demonstrate that, by integrating real-time monitoring, situation reporting, and rapid adaptive response mechanisms, ERINDA improves key performance metrics. Under a DDoS attack, ERINDA recovered approximately 88 % of normal throughput at 25 % channel utilization, compared to a 77 % reduction without ERINDA. Furthermore, ERINDA consistently restored packet delivery ratio and round-trip delay values close to normal operational conditions across various traffic loads.
引用
收藏
页码:248 / 262
页数:15
相关论文
共 50 条
  • [1] An Adaptive Approach for Defending against DDoS Attacks
    Li, Muhai
    Li, Ming
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2010, 2010
  • [2] Framework for statistical filtering against DDoS attacks in MANETs
    Tan, HX
    Seah, WKG
    ICESS 2005: SECOND INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2005, : 456 - 463
  • [3] Cooperative security management enhancing survivability against DDoS attacks
    Kim, SK
    Min, YJ
    Jung, JC
    Yoo, SH
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2005, PT 1, 2005, 3480 : 252 - 260
  • [4] Detection and Reaction against DDoS Attacks in Cellular Networks
    Rekhis, Slim
    Chouchane, Alaaedine
    Boudriga, Noureddine
    2008 3RD INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGIES: FROM THEORY TO APPLICATIONS, VOLS 1-5, 2008, : 2520 - 2525
  • [5] PETRAK: A solution against DDoS attacks in vehicular networks
    Verma, Amandeep
    Saha, Rahul
    Kumar, Gulshan
    Conti, Mauro
    COMPUTER COMMUNICATIONS, 2024, 221 : 142 - 154
  • [6] Enhancing SDN resilience against DDoS attacks through dynamic virtual controller deployment and attack level detection algorithm
    Florance G.
    R J Anandhi
    International Journal of Information Technology, 2024, 16 (7) : 4701 - 4712
  • [7] An Enhancing Security Research of Tor Anonymous Communication to Against DDos Attacks
    Feng, Tao
    Zhao, Ming-Tao
    4TH ANNUAL INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND APPLICATIONS (ITA 2017), 2017, 12
  • [8] Enhancing DNS resilience against denial of service attacks
    Pappas, Vasileios
    Massey, Dan
    Zhang, Lixia
    37TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2007, : 450 - +
  • [9] Framework for enhancing the operational resilience of cyber-manufacturing systems against cyber-attacks
    Espinoza-Zelaya, Carlos
    Moon, Young Bai
    MANUFACTURING LETTERS, 2023, 35 : 843 - 850
  • [10] Framework for enhancing the operational resilience of cyber-manufacturing systems against cyber-attacks
    Espinoza-Zelaya, Carlos
    Moon, Young Bai
    MANUFACTURING LETTERS, 2023, 35 : 843 - 850