Detection of TCP and MQTT-Based DoS/DDoS Attacks on MUD IoT Networks
Nut Aroon, Luke Kane, Vicky Liu, Yuefeng Li · Electronics · 2025
Mitigating cyberattacks on IoT networks is critical and remains a significant challenge, as such attacks can cause severe damage to the network systems and services. Moreover, the large volume of devices in IoT networks presents another challenge in managing security to reduce the risk of attacks. The Manufacturer Usage Description (MUD) is a standard for limiting attack risks on IoT networks. However, MUD has limitations, as it relies solely on pre-defined access control list (ACL) rules to allow permitted traffic and block unknown traffic. This can lead to false-negative filtering, where malicious traffic may still be allowed by MUD, compromising an entire IoT network. This study presents the implementation of a network behaviour analysis (NBA) system for DoS/DDoS attack detection in MUD-based IoT networks. We designed a set of algorithms to enhance the effectiveness of malicious traffic detection compared to using MUD alone. The NBA system groups related traffic and detects a variety of DoS/DDoS attacks that utilise TCP and MQTT protocols. Our evaluation demonstrates that the NBA system achieves high detection accuracy, effectively identifying attacks that MUD alone would not be able to detect, thereby enhancing the effectiveness of attack detection in MUD-based IoT networks.