首页> 外文期刊>International Journal on Critical Infrastructure Protection >A dependable architecture to mitigate distributed denial of service attacks on network-based control systems
【24h】

A dependable architecture to mitigate distributed denial of service attacks on network-based control systems

机译:可靠的体系结构可缓解基于网络的控制系统上的分布式拒绝服务攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Today, the Internet has become a promising platform for network-based control systems (NBCS), where packets are used to transmit feedback and control signals between a plant and controllers. On the other hand, today's distributed denial of service (DDoS) attacks cause significant disruption to the Internet, which threaten the operation of NBCS. This paper proposes an architecture called Fosel (filtering with the help of an overlay security layer) to protect NBCS from DDoS attacks. Fosel is a DoS defense technique that drops excess traffic effectively, thus reducing the overhead at the victim. The Fosel architecture is constructed using a combination of access point proxies, packet authentications, routing via onion tunnels, secret green nodes, rate limiter routers and a selective filter. For performance evaluation of Fosel, we use a networked proportional integral (PI) controller and a second-order plant (dc motor speed) as a case study. Emulab machines are used to implement the Fosel architecture. Real DoS toolkits are used to attack the plant's server and the Fosel architecture. Empirical results show that the Fosel architecture significantly reduces the likelihood of successful DDoS attacks to negligible levels. Practical results indicate that the Fosel architecture keeps communication alive between controllers and the plant.
机译:如今,互联网已成为基于网络的控制系统(NBCS)的有前途的平台,在该系统中,数据包用于在工厂和控制器之间传输反馈和控制信号。另一方面,当今的分布式拒绝服务(DDoS)攻击对Internet造成了严重破坏,从而威胁到NBCS的运行。本文提出了一种称为Fosel(借助覆盖安全层进行过滤)的体系结构,以保护NBCS免受DDoS攻击。 Fosel是一种DoS防御技术,可以有效地丢弃多余的流量,从而减少受害者的开销。 Fosel体系结构是通过结合使用访问点代理,数据包身份验证,通过洋葱隧道进行路由,秘密绿色节点,速率限制器路由器和选择性过滤器来构建的。对于Fosel的性能评估,我们以网络比例积分(PI)控制器和二阶工厂(直流电动机速度)为例进行研究。 Emulab机器用于实现Fosel体系结构。 Real DoS工具包用于攻击工厂的服务器和Fosel架构。实证结果表明,Fosel体系结构将成功进行DDoS攻击的可能性大大降低到可以忽略的水平。实际结果表明,Fosel体系结构使控制器与工厂之间的通信保持活跃。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号