Securing SCADA System from DDoS Attack
Animesh Srivastava, Parveen Kumar Saini, Shweta Tiwari, Vikash Sawan, Navin Garg · 2024
Emergency response systems, water treatment facilities, wastewater collection systems, Oil and gas pipelines, electrical power transmission systems, wind farms, defence networks, and large-scale communication networks are all vulnerable to the increasing prevalence of this threat. of distributed denial of service (DDoS) attacks. A dynamic proxy defence method is required because static thresholds cannot protect a critical SCADA system from DDoS attacks. This proposed way to protect these services from attacks is by masking their IP addresses hidden behind the proxies. This technique allows for the swift removal of misbehaving or attacked proxies by having the service generate hidden paths on the fly. By removing the attacker's cover, this technique creates a secure network that is only accessible to authorized users. An attacker doesn't need to know the data proxy to disrupt ongoing client communications because it is hidden. This DDOS prevention architecture is a useful addition to existing DDoS defences, and it can be effectively implemented in SCADA systems, data servers, and data centres. Even when they only occupy 10% of the network, a dynamic proxy density of 0.5% is sufficient to suppress over 93% of attackers.