Combating DDoS Cyberattacks in the Energy Sector
Digitalization of infrastructures with the use of information technologies for efficient intelligent management of power systems and their having rather poor cybersecurity are factors provoking a growing number of cyberattacks in the energy sector. At the same time, the energy sector structural units are critically important facilities malfunctioning of which compromises the national security. The problem has become so serious that cyberattacks on the energy sector infrastructural facilities are seen by the governments of many states as real threats leading to malfunctioning of the fuel and energy complex facilities. There is a steady growth of distributed denial-of-service (DDoS) attacks targeted on energy sector facilities. Electric energy building and control automation systems and call centers of power generating companies are attacked, causing power supply to entire regions become upset for a long period of time. At present, there are no reliable and universal technologies capable to block DDoS attacks. The article describes a method for combating DDoS attacks in power systems based on non-semantic filtering of traffic. The article also presents a new approach to combating DDoS attacks, which protects servers and traffic bandwidth. The proposed approach is based on the interaction of users with server equipment by dynamically changing the IP addresses of the attacked resources according to a pseudo-randomly generated schedule. The developed technology for filtering the network traffic makes it possible to combat DDoS attacks, reducing their intensity by about 92 %. As a result, the loss of legitimate packets, which is unavoidable in implementing any DDoS combating technology, makes less than 2 %.
Исследование выполнено за счет гранта РНФ (проект № 20-19-00541).
The study was carried out at the expense of the RGNF grant (Project No. 20-19-00541).