A Scalable Cyber Security Framework for the Experimentation of DDoS Attacks of Things
Davi Daniel Gemmer, Bruno Henrique Meyer, Emerson Ribeiro de Mello, Marcos Schwarz, Michelle Silva Wangham, Michele Nogueira · 2023
The Internet of Things (IoT) has amplified cyber security challenges for governments, businesses, and individuals. IoT is a straightforward attack target once it comprises resource-constrained and heterogeneous devices that often present security vulnerabilities easily exploited in different attack vectors. Recent Distributed Denial of Service (DDoS) attacks leverage thousands of IoT devices connected to the Internet called DDoS of things (a.k.a. DoT). DoT requires systematic cyber security research, but advancing the state-of-the-art depends on methods and tools that jointly manage scalability and performance. Experimentation is an essential and well-known tool for scientific research. However, experimental environments for investigating DoT are challenging, given limitations in scale and IoT heterogeneity. Hence, the main contribution of this work lies in presenting a cyber security framework for DoT experimentation that manages scalability and performance in scenarios under attack. It is the first initiative to create a framework of reference to assist in implementing cyber security testbeds. Hence, this work also presents an instantiation of this framework, called the MENTORED testbed, and the results of a case study using it.