2026· Euromicro Conference on Real-Time Systems· pp. 12:1-12:23· 0 citations· 24 references
Computer Science
TL;DR
A novel schedule-based attack that synchronizes malicious traffic to exploit predictability in TSN’s GCL schedule and causes an adversarial blocking in which low-priority traffic delays higher-priority traffic without being detected using a rate-based IDS is presented.
High-speed programmable data planes provide opportunities to implement data-driven fast reroute systems that quickly adapt to varying network conditions (e.g., congestion, failures) and improve network performance. The core of these systems has packet-processing algorithms running in the data plane that continuously look for traffic patterns (e.g., too many retransmissions) specific to a network condition (e.g., link failure) and take appropriate action (e.g., reroute). Despite their benefits, they also increase the potential attack surface. Adversaries can generate malicious traffic patterns resembling those anticipated by a fast reroute system and trick the system. Doing so would lead to poor network performance due to incorrect reroute decisions. In this paper, we propose a mechanism to detect whether the fast reroute systems are under the influence of malicious traffic patterns. Our key idea is to model the expected behavior using benign traffic features and use the model as a reference to determine whether the system is under the influence of adversaries. Using realistic attack traces, we demonstrate attacks on two fast reroute systems and successfully detect those attacks using the proposed detection mechanism.
S. A. Harish, S. Vignesh, Divya Pathak et al.· IEEE Transactions on Network...· 0 citations
A 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN is proposed.
Kun-Lin Tsai, Shih-Ting Chiu, Chihhsiong Shih et al.· Computer Modeling in Enginee...· 0 citations
Distributed Denial-of-Service (DDoS) attacks continue to threaten the availability of networked services by overwhelming server resources with malicious traffic. Among the different attack vectors, TCP flooding attacks remain particularly critical because TCP forms the backbone of reliable Internet services, such as web applications, cloud back-end systems, enterprise platforms, and many blockchain-based applications. Although several benchmark datasets exist for DDoS attack detection, most of them are flow-based and primarily support attack classification, offering a limited scope for analyzing how an ongoing attack impacts server health over time. This data article introduces TSD-DDoS, a time-series dataset specifically developed to fill a crucial gap in the detection of TCP flooding attacks and assessment of their severity in relation to server health. Unlike conventional flow-level datasets, TSD-DDoS organizes network traffic into fixed 5-second intervals. This temporal aggregation enables continuous monitoring of traffic patterns and provides direct insights into the progression and impact of TCP flooding on server performance and availability. By capturing the evolving nature of attacks over time, TSD-DDoS opens new avenues for research into time-aware detection mechanisms and server health monitoring, areas that are underrepresented in existing benchmark datasets. The dataset was constructed using packet capture (PCAP) files from the CICDDoS2019 benchmark dataset. The selected PCAP files were replayed at network speeds of up to 20 Gbps using the tcpreplay tool, whereas traffic capture was performed using Wireshark, a widely recognized packet analysis tool. The collected traffic was divided into successive 5-second intervals, and for each window, aggregated TCP statistics were extracted, specifically the counts of TCP-SYN, TCP-SYN-ACK, TCP-ACK, TCP-RST, and total TCP packets. Each interval was labeled as either normal or attack traffic, with an additional annotation indicating the server health status: Good, Fair, Serious, or Critical. These labels allowed for a clear temporal analysis of both the presence of attacks and the progression of severity. By offering structured, labelled, and time-indexed TCP traffic data, TSD-DDoS enables the development and evaluation of ML-based intrusion detection systems, time-sensitive server health monitoring tools, and adaptive resource management strategies. This is especially valuable in cloud and virtualized environments, where effective mitigation and scaling decisions rely on understanding how attacks evolve over time rather than on isolated flow-level metrics.
Sajja Ratan Kumar, Valli Kumari Vatsavayi· Data in Brief· 0 citations
Growing network speeds, with 100GbE line rates becoming common in modern enterprise networks, pose challenges to operators and security applications, as they struggle to scale their operational efficiency accordingly, without relying on costly hardware, excessive sampling, or complex distributed deployments. Unintentional loss due to stochastic packet sampling often produces low-quality traffic, further risking missed detection of critical security incidents, particularly those hidden in typically low-rate traffic, such as APT/malware command-and-control communications. In this paper, we introduce XNET, a system that monitors traffic at line rate using commodity hardware and applies dynamic sampling to amplify the visibility of high security value traffic. XNET leverages Linux's XDP technology to process packets efficiently, classify them based on their security value, and sample them as per configured policies. The outcome is a reduced packet stream in which the security-relevant portion of the traffic is amplified at the expense of less interesting traffic segments. XNET is a highly flexible, scalable and dynamic system that can be adapted based on a network's needs. We deployed XNET in a large real-world network using only commodity hardware, where our results show that XNET can achieve up to 84% traffic reduction with no packet loss while increasing the visibility of otherwise negligible traffic fivefold. With controlled stress tests, we further demonstrate XNET's scalability up to 100Gbps. Additionally, we show that XNET sampling led to a detection rate of 99.6% in an IDS application.
Thomas Papastergiou, Karthika Subramani, Joseph W. Reilly et al.· 0 citations
Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates the effectiveness of Machine Learning (ML) algorithms in detecting and addressing these attacks in real time. Using the Ryu controller, Mininet network emulator, and OpenFlow protocol, a realistic experimental environment was created to provide an accurate replica of the dynamic SDN behaviour under adverse circumstances. Empirical studies have demonstrated that distributed DDoS attacks, such as SYN, UDP, and ICMP flooding, substantially degrade network performance by reducing throughput, increasing packet loss, and exhausting switch flow table resources. To mitigate these effects, a suite of supervised machine learning classifiers, including Decision Tree, Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), and Naïve Bayes (NB), was instantiated and evaluated using traffic features captured on the emulated platform. The key performance indicators used to evaluate the classifiers included accuracy, precision, recall, and F1-score. The findings indicate that the Decision Tree and KNN models achieved detection rates above the 99% mark, with strong precision and recall scores, which in turn highlights their suitability for implementation in SDN-based security systems. This study provides experimental evidence that ML-based intrusion detection mechanisms can significantly enhance the resilience of SDNs to volumetric attacks. These results promote the implementation of adaptive and responsive security modules in SDN controllers, thereby increasing network resilience, particularly in large and dynamically programmable networks.
Kamal Singh, B. Kumar· international journal of eng...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.