ERINDA: A novel framework for Enhancing the Resilience of Industrial Networks against DDoS Attacks with adaptive recovery

被引:0
|
作者
Alrumaih, Thuraya N. I. [1 ]
Alenazi, Mohammed J. F. [2 ]
机构
[1] Princess Nourah Bint Abdulrahman Univ, Coll Comp & Informat Sci, Dept Informat Technol, POB 11671, Riyadh 84428, Saudi Arabia
[2] King Saud Univ, Coll Comp & Informat Sci, Dept Comp Engn, Riyadh, Saudi Arabia
关键词
Critical infrastructure; Cyber resilience; Industrial control system (ICS); Cybersecurity; Distributed denial-of-service (DDoS) attacks; CONTROL-SYSTEMS; MITIGATION; SECURITY; IOT;
D O I
10.1016/j.aej.2025.02.042
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The increasing threat of distributed denial-of-service (DDoS) attacks targeting the availability of critical infrastructure systems controlled by industrial control systems (ICS). DDoS attacks endanger the high-reliability requirements ICSs by overloading network and system resources, causing malfunction or ceasing operations. Recognizing the severe consequences of service disruptions in these environments, we present a novel framework for Enhancing the Resilience of Industrial Networks against DDoS Attacks (ERINDA), designed to minimize downtime and maintain functionality. It consists of a two-phase approach that combines proactive and reactive strategies to efficiently mitigate DDoS attacks while minimizing service disruptions. First, network traffic is continuously monitored to detect any anomalies indicating potential attacks. Second, response mechanisms are activated upon an actual attack identification to quickly neutralize the threat and restore the integrity of the network. Experimental results, obtained using ns-3 network simulations mimicking a smallscale industrial network topology, demonstrate that, by integrating real-time monitoring, situation reporting, and rapid adaptive response mechanisms, ERINDA improves key performance metrics. Under a DDoS attack, ERINDA recovered approximately 88 % of normal throughput at 25 % channel utilization, compared to a 77 % reduction without ERINDA. Furthermore, ERINDA consistently restored packet delivery ratio and round-trip delay values close to normal operational conditions across various traffic loads.
引用
收藏
页码:248 / 262
页数:15
相关论文
共 50 条
  • [21] Enhancing resilience of interdependent networks against cascading failures under preferential recovery strategies
    Wu Jia-Jian
    Gong Kai
    Wang Cong
    Wang Lei
    ACTA PHYSICA SINICA, 2018, 67 (08)
  • [22] Enhancing RPL Resilience Against Routing Layer Insider Attacks
    Heurtefeux, Karel
    Erdene-Ochir, Ochirkhand
    Mohsin, Nasreen
    Menouar, Hamid
    2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (IEEE AINA 2015), 2015, : 802 - 807
  • [23] An intelligent cyber security system against DDoS attacks in SIP networks
    Semerci, Murat
    Cemgil, Ali Taylan
    Sankur, Bulent
    COMPUTER NETWORKS, 2018, 136 : 137 - 154
  • [24] Protection of Corporate Networks against DDoS Attacks Using the Arbor Technology
    Jovanovic, Marko Lj
    Koprivica, Mladen
    Neskovic, Natasa
    2018 26TH TELECOMMUNICATIONS FORUM (TELFOR), 2018, : 120 - 123
  • [25] Defense mechanism using overlay against DDoS attacks on converged networks
    Kim, Mihui
    Doh, Inshil
    Chae, Kijoon
    9TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY: TOWARD NETWORK INNOVATION BEYOND EVOLUTION, VOLS 1-3, 2007, : 1539 - +
  • [26] A Novel Framework for DDoS Attacks Detection Using Hybrid LSTM Techniques
    Thangasamy A.
    Sundan B.
    Govindaraj L.
    Computer Systems Science and Engineering, 2023, 45 (03): : 2553 - 2567
  • [27] Resilience of LTE Networks Against Smart Jamming Attacks
    Aziz, Farhan M.
    Shamma, Jeff S.
    Stueber, Gordon L.
    2014 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2014), 2014, : 734 - 739
  • [28] A Distributed Collaborative Entrance Defense Framework Against DDoS Attacks on Satellite Internet
    Guo, Wei
    Xu, Jin
    Pei, Yukui
    Yin, Liuguo
    Jiang, Chunxiao
    Ge, Ning
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (17) : 15497 - 15510
  • [29] A Framework for Measuring Software Obfuscation Resilience Against Automated Attacks
    Banescu, Sebastian
    Ochoa, Martin
    Pretschner, Alexander
    2015 IEEE/ACM 1ST INTERNATIONAL WORKSHOP ON SOFTWARE PROTECTION (SPRO), 2015, : 45 - 51
  • [30] A logical framework for evaluating network resilience against faults and attacks
    Bursztein, Elie
    Goubault-Larrecq, Jean
    ADVANCES IN COMPUTER SCIENCE - ASIAN 2007: COMPUTER AND NETWORK SECURITY, PROCEEDINGS, 2007, 4846 : 212 - 227