International Journal of Electrical and Computer Engineering
Vol 10, No 2: April 2020

SIEM-based detection and mitigation of IoT-botnet DDoS attacks

Basheer Al-Duwairi (Jordan University of Science & Technology)
Wafaa Al-Kahla (Jordan University of Science & Technology)
Mhd Ammar AlRefai (Jordan University of Science & Technology)
Yazid Abedalqader (Jordan University of Science & Technology)
Abdullah Rawash (Jordan University of Science & Technology)
Rana Fahmawi (Jordan University of Science & Technology)



Article Info

Publish Date
01 Apr 2020

Abstract

The Internet of Things (IoT) is becoming an integral part of our daily life including health, environment, homes, military, etc. The enormous growth of IoT in recent years has attracted hackers to take advantage of their computation and communication capabilities to perform different types of attacks. The major concern is that IoT devices have several vulnerabilities that can be easily exploited to form IoT botnets consisting of millions of IoT devices and posing significant threats to Internet security. In this context, DDoS attacks originating from IoT botnets is a major problem in today’s Internet that requires immediate attention. In this paper, we propose a Security Information and Event Management-based IoT botnet DDoS attack detection and mitigation system. This system detects and blocks DDoS attack traffic from compromised IoT devices by monitoring specific packet types including TCP SYN, ICMP and DNS packets originating from these devices. We discuss a prototype implementation of the proposed system and we demonstrate that SIEM based solutions can be configured to accurately identify and block malicious traffic originating from compromised IoT devices.

Copyrights © 2020






Journal Info

Abbrev

IJECE

Publisher

Subject

Computer Science & IT Electrical & Electronics Engineering

Description

International Journal of Electrical and Computer Engineering (IJECE, ISSN: 2088-8708, a SCOPUS indexed Journal, SNIP: 1.001; SJR: 0.296; CiteScore: 0.99; SJR & CiteScore Q2 on both of the Electrical & Electronics Engineering, and Computer Science) is the official publication of the Institute of ...