ERINDA: A novel framework for Enhancing the Resilience of Industrial Networks against DDoS Attacks with adaptive recovery

被引:0
|
作者
Alrumaih, Thuraya N. I. [1 ]
Alenazi, Mohammed J. F. [2 ]
机构
[1] Princess Nourah Bint Abdulrahman Univ, Coll Comp & Informat Sci, Dept Informat Technol, POB 11671, Riyadh 84428, Saudi Arabia
[2] King Saud Univ, Coll Comp & Informat Sci, Dept Comp Engn, Riyadh, Saudi Arabia
关键词
Critical infrastructure; Cyber resilience; Industrial control system (ICS); Cybersecurity; Distributed denial-of-service (DDoS) attacks; CONTROL-SYSTEMS; MITIGATION; SECURITY; IOT;
D O I
10.1016/j.aej.2025.02.042
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The increasing threat of distributed denial-of-service (DDoS) attacks targeting the availability of critical infrastructure systems controlled by industrial control systems (ICS). DDoS attacks endanger the high-reliability requirements ICSs by overloading network and system resources, causing malfunction or ceasing operations. Recognizing the severe consequences of service disruptions in these environments, we present a novel framework for Enhancing the Resilience of Industrial Networks against DDoS Attacks (ERINDA), designed to minimize downtime and maintain functionality. It consists of a two-phase approach that combines proactive and reactive strategies to efficiently mitigate DDoS attacks while minimizing service disruptions. First, network traffic is continuously monitored to detect any anomalies indicating potential attacks. Second, response mechanisms are activated upon an actual attack identification to quickly neutralize the threat and restore the integrity of the network. Experimental results, obtained using ns-3 network simulations mimicking a smallscale industrial network topology, demonstrate that, by integrating real-time monitoring, situation reporting, and rapid adaptive response mechanisms, ERINDA improves key performance metrics. Under a DDoS attack, ERINDA recovered approximately 88 % of normal throughput at 25 % channel utilization, compared to a 77 % reduction without ERINDA. Furthermore, ERINDA consistently restored packet delivery ratio and round-trip delay values close to normal operational conditions across various traffic loads.
引用
收藏
页码:248 / 262
页数:15
相关论文
共 50 条
  • [31] Enhancing resilience: implementing resilience building policies against major industrial accidents
    Labaka, Leire
    Hernantes, Josune
    Lauge, Ana
    Maria Sarriegi, Jose
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2013, 9 (1-2) : 130 - 147
  • [32] Enhancing the security of LTE networks against jamming attacks
    Jover, Roger Piqueras
    Lackey, Joshua
    Raghavan, Arvind
    EURASIP JOURNAL ON INFORMATION SECURITY, 2014, Springer International Publishing (01):
  • [33] Accountable File Indexing against DDoS Attacks in Peer-to-Peer Networks
    Lou, Xiaosong
    Hwang, Kai
    Hu, Yue
    GLOBECOM 2009 - 2009 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-8, 2009, : 2504 - +
  • [34] Scheme of defending against DDoS attacks in large-scale ISP networks
    Wu, Zhi-jun
    Zhang, Dong
    NETWORK AND PARALLEL COMPUTING, PROCEEDINGS, 2007, 4672 : 296 - +
  • [35] Recovery-Key Attacks against TMN-family Framework for Mobile Wireless Networks
    Phuc, Tran Song Dat
    Shin, Yong-Hyeon
    Lee, Changhoon
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2021, 15 (06): : 2148 - 2167
  • [36] Securing IoT Networks Against DDoS Attacks: A Hybrid Deep Learning Approach
    Ul Ain, Noor
    Sardaraz, Muhammad
    Tahir, Muhammad
    Abo Elsoud, Mohamed W.
    Alourani, Abdullah
    SENSORS, 2025, 25 (05)
  • [37] Research on the detection and defense systems against DDoS attacks in ad hoc networks
    Jing, Huang
    Wen, Wushao
    INFORMATION SCIENCE AND MANAGEMENT ENGINEERING, VOLS 1-3, 2014, 46 : 1161 - 1167
  • [38] Using selective, short-term memory to improve resilience against DDoS exhaustion attacks
    Liao, Qi
    Cieslak, David A.
    Striegel, Aaron D.
    Chawla, Nitesh V.
    SECURITY AND COMMUNICATION NETWORKS, 2008, 1 (04) : 287 - 299
  • [39] A Study of the Resilience of the Mosquitto MQTT Broker Running on Raspberry Pi Against Fuzzy DDoS Attacks
    Patel, Jhanvi
    Gamess, Eric
    PROCEEDINGS OF THE 2024 LATIN AMERICA NETWORKING CONFERENCE, LANC 2024, 2024, : 18 - 25
  • [40] A novel optimization-driven deep learning framework for the detection of DDoS attacks
    Batchu, Raj Kumar
    Bikku, Thulasi
    Thota, Srinivasarao
    Seetha, Hari
    Ayoade, Abayomi Ayotunde
    SCIENTIFIC REPORTS, 2024, 14 (01):