Title :
Mitigating performance degradation of network-based control systems under denial of service attacks
Author :
Long, Men ; Wu, Chwan-Hwa John ; Hung, John Y. ; Irwin, J. David
Author_Institution :
Dept. of Electr. & Comput. Eng., Auburn Univ., Alabarna, AL, USA
Abstract :
One obstacle for the widespread deployment of network-based control systems (NBCS) is the stochastic delay induced by the underlying shared and open networks. Denial of service (DoS) attacks cause significant disruptions to the Internet, compounding the delay jitter and loss of packets that are used to transmit sensor measurements and control signals. Existing works have mainly focused on controller design under network normal operation, which might be inadequate to the threats of DoS attacks. In this paper, the authors present two mitigation measures from the viewpoint of network intrusion detection and response. The basic idea is that the routers close to the attack sources actively drop the attack traffic or lower-priority traffic to protect the resource for the legitimate application traffic. The simulation results indicate that the proposed defense measures are effective for ameliorating the NBCS performance degradation. We suggest that a plausible direction for the security of NBCS may combine the proposed network defense measures with specific controller design to compensate for delay jitter/packet loss.
Keywords :
Internet; authorisation; control system synthesis; delays; jitter; microcontrollers; quality of service; telecommunication network routing; telecommunication security; telecommunication traffic; Internet; control signal transmission; delay jitter; denial of service attack; mitigating performance; network defense; network intrusion detection; network router; network traffic; network-based control system security; sensor measurement; stochastic delay; Communication system traffic control; Computer crime; Control systems; Degradation; Jitter; Loss measurement; Niobium compounds; Stochastic systems; Traffic control; Web and internet services;
Conference_Titel :
Industrial Electronics Society, 2004. IECON 2004. 30th Annual Conference of IEEE
Print_ISBN :
0-7803-8730-9
DOI :
10.1109/IECON.2004.1432165