Enhancing Security in Automotive Mobile Ad-Hoc Networks: Mitigating DDoS Attacks Through Integrated SIEM, NDR, and SOAR Solutions
Abstract
The increasing connectivity of automotive systems through Vehicle-to-Everything (V2X) communication and Mobile Ad Hoc Networks (MANETs) has created new vulnerabilities to Distributed Denial of Service (DDoS) attacks, threatening the availability of safety-critical vehicle communications and infrastructure services. This research addresses the challenge of protecting MANET-based automotive infrastructure by developing an integrated security architecture combining Network Detection and Response (NDR), Security Information and Event Management (SIEM), and Security Orchestration, Automation, and Response (SOAR) capabilities. Risk analysis was conducted using the NIST Cybersecurity Framework 2.0, mapping security controls across its six core functions. A laboratory proof of concept validated the architecture using CYBERQUEST (SIEM) and NETALERT (NDR) platforms to detect and automatically mitigate a simulated volumetric DDoS attack against a static network node. The integrated detection chain successfully identified abnormal connection volumes, correlated alerts across multiple sources, and executed automated blacklisting responses without human intervention. The results demonstrate that commercially available security platforms can be effectively adapted for MANET environments when properly integrated, providing rapid automated response capabilities aligned with European regulatory requirements including the NIS2 Directive and UNECE Regulation No. 155.