Modern communication networks, particularly in the context of the Industrial Internet of Things (IIoT), are increasingly vulnerable to cyber-attacks aimed at disrupting physical processes and sabotaging infrastructure, such as Denial of Service (DoS) attacks. This study assesses the feasibility of a non-invasive approach for identifying such attacks, reinterpreting electromagnetic (EM) side-channel analysis as the basis for a defensive Intrusion Detection System (IDS). By monitoring EM emissions near the power terminals of common network devices using a low-cost hardware setup, scenarios of legitimate traffic and scenarios compromised by MAC Flood, ICMP Flood, and SYN Flood attacks were analysed. Utilising a moving-window downsampling protocol and extracting 17 features in the time and frequency domains, the metrological incompatibility between the different operational states was measured. The results show that the use of robust metrics (such as RMS value, Hjorth mobility, spectral energy, and peak frequency), combined with the optimization of the observation window width and coverage factor, demonstrates a promising ability to distinguish between normal conditions and network anomalies. These results represent a preliminary feasibility study and suggest the potential use of the proposed approach to support the future development of intrusion detection systems (IDS) based on physical principles.

Feasibility analysis of DoS attacks identification based on low-cost hardware–enabled electromagnetic side-channel measurements

Capriglione, D.;Cerro, G.;
2026-01-01

Abstract

Modern communication networks, particularly in the context of the Industrial Internet of Things (IIoT), are increasingly vulnerable to cyber-attacks aimed at disrupting physical processes and sabotaging infrastructure, such as Denial of Service (DoS) attacks. This study assesses the feasibility of a non-invasive approach for identifying such attacks, reinterpreting electromagnetic (EM) side-channel analysis as the basis for a defensive Intrusion Detection System (IDS). By monitoring EM emissions near the power terminals of common network devices using a low-cost hardware setup, scenarios of legitimate traffic and scenarios compromised by MAC Flood, ICMP Flood, and SYN Flood attacks were analysed. Utilising a moving-window downsampling protocol and extracting 17 features in the time and frequency domains, the metrological incompatibility between the different operational states was measured. The results show that the use of robust metrics (such as RMS value, Hjorth mobility, spectral energy, and peak frequency), combined with the optimization of the observation window width and coverage factor, demonstrates a promising ability to distinguish between normal conditions and network anomalies. These results represent a preliminary feasibility study and suggest the potential use of the proposed approach to support the future development of intrusion detection systems (IDS) based on physical principles.
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11695/162570
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact