Protecting IoT Servers Against Flood Attacks with the Quasi Deterministic Transmission Policy

06/19/2023
by   Erol Gelenbe, et al.
0

IoT Servers that receive and process packets from IoT devices should meet the QoS needs of incoming packets, and support Attack Detection software that analyzes the incoming traffic to identify and discard packets that may be part of a Cyberattack. Since UDP Flood Attacks can overwhelm IoT Servers by creating congestion that paralyzes their operation and limits their ability to conduct timely Attack Detection, this paper proposes and evaluates a simple architecture to protect a Server that is connected to a Local Area Network, using a Quasi Deterministic Transmission Policy Forwarder (SQF) at its input port. This Forwarder shapes the incoming traffic, sends it to the Server in a manner which does not modify the overall delay of the packets, and avoids congestion inside the Server. The relevant theoretical background is briefly reviewed, and measurements during a UDP Flood Attack are provided to compare the Server performance, with and without the Forwarder. It is seen that during a UDP Flood Attack, the Forwarder protects the Server from congestion allowing it to effectively identify Attack Packets. On the other hand, the resulting Forwarder congestion can also be eliminated at the Forwarder with "drop" commands generated by the Forwarder itself, or sent by the Server to the Forwarder.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/17/2023

Measurement Based Evaluation and Mitigation of Flood Attacks on a LAN Test-Bed

The IoT's vulnerability to network attacks has motivated the design of i...
research
09/14/2017

REMOTEGATE: Incentive-Compatible Remote Configuration of Security Gateways

Imagine that a malicious hacker is trying to attack a server over the In...
research
01/26/2018

Simulation for L3 Volumetric Attack Detection

The detection of a volumetric attack involves collecting statistics on t...
research
11/09/2021

Classifying DNS Servers based on Response Message Matrix using Machine Learning

Improperly configured domain name system (DNS) servers are sometimes use...
research
07/18/2019

Prioritized Multi-stream Traffic in Uplink IoT Networks: Spatially Interacting Vacation Queues

Massive Internet of Things (IoT) is foreseen to introduce plethora of ap...
research
06/12/2022

Exploration of Enterprise Server Data to Assess Ease of Modeling System Behavior

Enterprise networks are one of the major targets for cyber attacks due t...
research
08/15/2022

A novel approach for FPGA-to-server data transmission over an Ethernet-based network using the eXpress Data Path technology

In the context of the upgrade of the Large Hadron Collider at CERN for h...

Please sign up or login with your details

Forgot password? Click here to reset