Measurement Based Evaluation and Mitigation of Flood Attacks on a LAN Test-Bed
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | , , |
|---|---|
| Format: | Preprint |
| Publié: |
2023
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
| _version_ | 1866911767099080704 |
|---|---|
| author | Nasereddin, Mohammed Nakıp, Mert Gelenbe, Erol |
| author_facet | Nasereddin, Mohammed Nakıp, Mert Gelenbe, Erol |
| contents | The IoT is vulnerable to network attacks, and Intrusion Detection Systems (IDS) can provide high attack detection accuracy and are easily installed in IoT Servers. However, IDS are seldom evaluated in operational conditions which are seriously impaired by attack overload. Thus a Local Area Network testbed is used to evaluate the impact of UDP Flood Attacks on an IoT Server, whose first line of defence is an accurate IDS. We show that attacks overload the multi-core Server and paralyze its IDS. Thus a mitigation scheme that detects attacks rapidly, and drops packets within milli-seconds after the attack begins, is proposed and experimentally evaluated. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2305_10565 |
| institution | arXiv |
| publishDate | 2023 |
| record_format | arxiv |
| spellingShingle | Measurement Based Evaluation and Mitigation of Flood Attacks on a LAN Test-Bed Nasereddin, Mohammed Nakıp, Mert Gelenbe, Erol Cryptography and Security Networking and Internet Architecture The IoT is vulnerable to network attacks, and Intrusion Detection Systems (IDS) can provide high attack detection accuracy and are easily installed in IoT Servers. However, IDS are seldom evaluated in operational conditions which are seriously impaired by attack overload. Thus a Local Area Network testbed is used to evaluate the impact of UDP Flood Attacks on an IoT Server, whose first line of defence is an accurate IDS. We show that attacks overload the multi-core Server and paralyze its IDS. Thus a mitigation scheme that detects attacks rapidly, and drops packets within milli-seconds after the attack begins, is proposed and experimentally evaluated. |
| title | Measurement Based Evaluation and Mitigation of Flood Attacks on a LAN Test-Bed |
| topic | Cryptography and Security Networking and Internet Architecture |
| url | https://arxiv.org/abs/2305.10565 |