Skip to content
Conference

Enhancing Security in Automotive Mobile Ad-Hoc Networks: Mitigating DDoS Attacks Through Integrated SIEM, NDR, and SOAR Solutions

Jul 2026 · European Conference on Artificial Intelligence · pp. 1-14 · 0 citations · 20 references

Abstract

The increasing connectivity of automotive systems through Vehicle-to-Everything (V2X) communication and Mobile Ad Hoc Networks (MANETs) has created new vulnerabilities to Distributed Denial of Service (DDoS) attacks, threatening the availability of safety-critical vehicle communications and infrastructure services. This research addresses the challenge of protecting MANET-based automotive infrastructure by developing an integrated security architecture combining Network Detection and Response (NDR), Security Information and Event Management (SIEM), and Security Orchestration, Automation, and Response (SOAR) capabilities. Risk analysis was conducted using the NIST Cybersecurity Framework 2.0, mapping security controls across its six core functions. A laboratory proof of concept validated the architecture using CYBERQUEST (SIEM) and NETALERT (NDR) platforms to detect and automatically mitigate a simulated volumetric DDoS attack against a static network node. The integrated detection chain successfully identified abnormal connection volumes, correlated alerts across multiple sources, and executed automated blacklisting responses without human intervention. The results demonstrate that commercially available security platforms can be effectively adapted for MANET environments when properly integrated, providing rapid automated response capabilities aligned with European regulatory requirements including the NIS2 Directive and UNECE Regulation No. 155.

View source

Similar papers

Open access Jul 2026

Security Assurance in 5G-Advanced (3GPP Release 18): Protecting Edge Computing, Network Automation, and Non-Public Networks

5G-Advanced (3GPP Release 18) architectural changes include multi-access edge computing (MEC) architectural changes, network automation, and non-public networks (NPNs). It is important to note that even though these advancements provide substantial performance advantages, they destroy fixed-perimeter security models, providing a distributed attack surface. The use of current security assessment strategies, which are usually non-fluid and isolated, is inadequate to offer the required runtime security health assurance needed in such fluid environments. This study presents a new security assurance framework (SAF) that would be used to provide ongoing evidence-based protection on core, edge, and private network domains. This framework employs a four-layer architecture, including monitoring, analytics (LM), policy engine, and enforcement, to convert security periodically audited to a dynamic threat-control-metric evidence chain. A 96% attack detection rate and a 99.8% reduction in response time (with a mean of 20.1 s) are proven by validation on an emulated 5G-Advanced testbed (approximating Release 18 features using Open5GS (v2.7.2 Rel-17, community developed, Seoul, Republic of Korea and custom extensions) based on a design science research (DSR) paradigm. Although the overhead (13% CPU, 21.4% memory) is manageable, the findings prove that all-time, multi-domain assurance is crucial to the healthy functioning of 5G-Advanced and is a key roadmap to autonomous 6G security.

E. Egho-Promise, Ekereuke Udoh, Edita Gashi et al. · 0 citations
2026

CROSS-TEE: A Distributed Trusted Execution Environment Architecture for Cross-Module Automotive Security

The rapid development of intelligent, connected, and electrified automotive technologies has significantly enhanced convenience, driving substantial growth in the intelligent connected vehicle (ICV) market, and accelerating the replacement of traditional fuel-powered vehicles. However, these advancements have introduced new attack surfaces, giving rise to emerging security threats such as malicious injection attacks on the controller area network (CAN) bus and eavesdropping attacks on in-vehicle Ethernet communications. Existing security solutions face limitations such as lack of holistic defense, insufficient application isolation, absence of security checks for CAN bus invocation requests, and plaintext Ethernet data transmission, which undermine ICV security. To address these problems, we propose CROSS-TEE, the first cross-module distributed customizable trusted execution environment (TEE) architecture designed to manage the interaction between different system modules (e.g., domain controller, central gateway, etc.) in vehicles. CROSS-TEE consists of two levels: one type of Level-1 TEE and three types of Level-2 TEEs, tailored to different application and security requirements. We design a trusted house mechanism to isolate trusted applications (TAs) and a pre-transmission protocol to enable secure data transmission. CROSS-TEE only allows direct CAN bus invocation requests from TAs, while requiring similar requests from applications in the normal world to pass security checks by either secure monitor (SM) or trusted operating system (OS) before approving them. The prototype of CROSS-TEE is built using Renesas RA6M5 and Raspberry Pi 3 Model B development boards. Experimental results demonstrate the effectiveness of CROSS-TEE’s security mechanisms against remote attacks (e.g., arbitrary CAN bus message injections, unauthorized invocations of security-critical applications, and malicious access to in-vehicle Ethernet networks), with average time overheads of approximately 7.8% for CAN bus communication and $1.73\times $ for encrypted Ethernet communication, indicating an acceptable security-performance trade-off.

Sisi Li, Kun Yang, Hongliang Tian et al. · 0 citations
Review Aug 2026

Intrusion detection systems for the internet of vehicles: a systematic survey of techniques and challenges across CAN bus and vehicular networks

This paper presents a comprehensive and systematic review of deep learning techniques applied to cyber intrusion detection within IoV systems, conducted in accordance with the PRISMA framework across 83 selected studies published between 2020 and 2025.

Duygu Kayaoğlu, Eyup Emre Ulku, Onder Demir · 0 citations
Conference Jul 2026

Simulating Cyber Attacks and Countermeasures in Vehicular Ad-Hoc Networks Using Cyber Operations Research Gym (CybORG)

Vehicular Ad-Hoc Networks (VANETs) enable realtime communication for safety-critical applications including collision avoidance and traffic control. Their decentralized, dynamic architecture, however, makes them vulnerable to multiple attack classes, including Sybil, spoofing, Denial-of-Service (DoS), and other cyber threats. Existing defenses typically address cyber and physical layers independently, limiting their ability to capture the interplay between mobility patterns and attack propagation. This paper presents a cyber-physical simulation framework integrating vehicular mobility with the CybORG environment for multi-class attack mitigation. A Road Side Unit (RSU) acts as the infrastructure-based defender, monitoring vehicle behavior, maintaining trust scores, and executing defense actions via a Dueling Double Deep Q-Network with Prioritized Experience Replay (D3QN-PER). The agent learns optimal policies through environment interaction rather than static labeled data. Evaluation against two unsupervised baselines, Exponentially Weighted Moving Average (EWMA) and Trust-Gated Isolation Forest, demonstrates perfect detection performance (Recall = 100%, $\mathbf{F} \mathbf{1} \boldsymbol{=} \mathbf{1. 0 0 0 0})$ with zero false positives and zero false negatives, compared to 95.12% recall (EWMA) and 84.95% recall (Isolation Forest). The framework handles up to six concurrent attackers within the RSU's 200 m range with sub-millisecond latency, establishing a foundation for intelligent, adaptive security in vehicular networks.

Fasna Nadeera Irumpidamkandiyil Pocker, Farsana Ansari, Alexandre dos Santos Roque et al. · 0 citations
Conference Jul 2026

SDN-based DDoS Attack Detection and Mitigation in IoT Networks

The rapid proliferation of Internet of Things (IoT) devices has fundamentally transformed global network infrastructure while simultaneously creating an expanding attack surface for advanced Distributed Denial of Service (DDoS) threats. IoT endpoints are inherently resource-constrained, making them vulnerable to exploitation as botnet nodes for large-scale DDoS campaigns. Conventional security mechanisms including statically configured firewalls and signature-based intrusion detection systems are insufficiently scalable and adaptive for heterogeneous IoT environments. This paper proposes a lightweight, hybrid Software-Defined Networking (SDN)-based framework for real-time DDoS detection and automated mitigation. The proposed system integrates Shannon entropy-based traffic anomaly detection at the data plane with a Random Forest (RF) classifier deployed at the Ryu SDN controller. Training and evaluation are performed on the CICDDoS2019 benchmark dataset, and end-to-end validation is conducted using Mininet network simulation. Experimental results demonstrate an average detection accuracy of 98.2%, a mean false positive rate (FPR) of 1.6%, a mean F1-score of 98.2%, and a mean mitigation time of 43 ms across four DDoS attack categories: UDP Flood, TCP SYN Flood, ICMP Flood, and HTTP Flood. The proposed approach achieves a favorable accuracy-overhead balance and outperforms state-of-the-art baselines in multiple evaluation dimensions.

Xodjayeva Mavluda Sabirovna, Sevinch Jovlieva, Bayjanov Furkat Bakhramovich et al. · 0 citations