ERINDA: A novel framework for Enhancing the Resilience of Industrial Networks against DDoS Attacks with adaptive recovery

被引:0
|
作者
Alrumaih, Thuraya N. I. [1 ]
Alenazi, Mohammed J. F. [2 ]
机构
[1] Princess Nourah Bint Abdulrahman Univ, Coll Comp & Informat Sci, Dept Informat Technol, POB 11671, Riyadh 84428, Saudi Arabia
[2] King Saud Univ, Coll Comp & Informat Sci, Dept Comp Engn, Riyadh, Saudi Arabia
关键词
Critical infrastructure; Cyber resilience; Industrial control system (ICS); Cybersecurity; Distributed denial-of-service (DDoS) attacks; CONTROL-SYSTEMS; MITIGATION; SECURITY; IOT;
D O I
10.1016/j.aej.2025.02.042
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The increasing threat of distributed denial-of-service (DDoS) attacks targeting the availability of critical infrastructure systems controlled by industrial control systems (ICS). DDoS attacks endanger the high-reliability requirements ICSs by overloading network and system resources, causing malfunction or ceasing operations. Recognizing the severe consequences of service disruptions in these environments, we present a novel framework for Enhancing the Resilience of Industrial Networks against DDoS Attacks (ERINDA), designed to minimize downtime and maintain functionality. It consists of a two-phase approach that combines proactive and reactive strategies to efficiently mitigate DDoS attacks while minimizing service disruptions. First, network traffic is continuously monitored to detect any anomalies indicating potential attacks. Second, response mechanisms are activated upon an actual attack identification to quickly neutralize the threat and restore the integrity of the network. Experimental results, obtained using ns-3 network simulations mimicking a smallscale industrial network topology, demonstrate that, by integrating real-time monitoring, situation reporting, and rapid adaptive response mechanisms, ERINDA improves key performance metrics. Under a DDoS attack, ERINDA recovered approximately 88 % of normal throughput at 25 % channel utilization, compared to a 77 % reduction without ERINDA. Furthermore, ERINDA consistently restored packet delivery ratio and round-trip delay values close to normal operational conditions across various traffic loads.
引用
收藏
页码:248 / 262
页数:15
相关论文
共 50 条
  • [41] A measure of resilience against denial of service attacks in computer networks
    Sharafat, AR
    Fallah, MS
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2002, 17 (4-5): : 259 - 267
  • [42] Securing IIoT systems against DDoS attacks with adaptive moving target defense strategies
    Swati
    Roy, Sangita
    Singh, Jawar
    Mathew, Jimson
    SCIENTIFIC REPORTS, 2025, 15 (01):
  • [43] Optimal Specifications for a Protective Framework Against HTTP-based DoS and DDoS Attacks
    Saleh, Mohammed A.
    Manaf, Azizah Abdul
    2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 263 - 267
  • [44] A novel sensitive DDoS attacks against statistical test in network traffic fusion
    Kulandaivel, Madhumitha
    Kumar, Ganesh
    Sathiyamoorthi, Velayutham
    Gupta, Sachin Kumar
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2023, 34 (12)
  • [45] A novel architecture for detecting and defending against flooding-based DDoS attacks
    Shi, Y
    Yang, XY
    COMPUTATIONAL INTELLIGENCE AND SECURITY, PT 2, PROCEEDINGS, 2005, 3802 : 364 - 374
  • [46] Sustainable lending strategies: a framework for enhancing climate resilience in industrial loan portfoliosSustainable lending strategies: a framework for enhancing climate resilience in industrial loan portfoliosNeha Chhabra Roy
    Neha Chhabra Roy
    Asia Europe Journal, 2024, 22 (4) : 423 - 462
  • [47] Novel Probabilistic Resilience Assessment Framework of Transportation Networks against Extreme Weather Events
    Nogal, Maria
    O'Connor, Alan
    Martinez-Pastor, Beatriz
    Caulfield, Brian
    ASCE-ASME JOURNAL OF RISK AND UNCERTAINTY IN ENGINEERING SYSTEMS PART A-CIVIL ENGINEERING, 2017, 3 (03):
  • [48] Adaptive Bubble Burst (ABB): Mitigating DDoS Attacks in Software-Defined Networks
    Sattar, Danish
    Matrawy, Ashraf
    Adeojo, Olufemi
    2016 17TH INTERNATIONAL TELECOMMUNICATIONS NETWORK STRATEGY AND PLANNING SYMPOSIUM (NETWORKS), 2016, : 50 - 55
  • [49] A Mathematical Framework to Optimize Critical Infrastructure Resilience against Intentional Attacks
    Ouyang, Min
    Fang, Yiping
    COMPUTER-AIDED CIVIL AND INFRASTRUCTURE ENGINEERING, 2017, 32 (11) : 909 - 929
  • [50] XAI enhancing cyber defence against adversarial attacks in industrial applications
    Makridis, Georgios
    Theodoropoulos, Spyros
    Dardanis, Dimitrios
    Makridis, Ioannis
    Separdani, Maria Margarita
    Fatouros, Georgios
    Kyriazis, Dimosthenis
    Koulouris, Panagiotis
    2022 IEEE 5TH INTERNATIONAL CONFERENCE ON IMAGE PROCESSING APPLICATIONS AND SYSTEMS, IPAS, 2022,