Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (5)

Search Parameters:
Keywords = IP fragmentation attack

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
24 pages, 8172 KB  
Article
Innovative Testbed Configurations and Interfacing Techniques for Real-Time Digital Simulation of Cyber-Physical Energy and Power Systems
by Al Hussein Dabashi, Dongmeng Qiu, Xin Zhang and Gareth Taylor
Electronics 2026, 15(16), 3705; https://doi.org/10.3390/electronics15163705 - 19 Aug 2026
Viewed by 310
Abstract
Testbed configurations and interfacing methods for real-time digital simulation of cyber-physical power systems (CPPS) remain complex and fragmented across the literature, limiting the clarity with which researchers can compare tools, reproduce testbeds, and select suitable platforms for communication-aware control and cyber security studies. [...] Read more.
Testbed configurations and interfacing methods for real-time digital simulation of cyber-physical power systems (CPPS) remain complex and fragmented across the literature, limiting the clarity with which researchers can compare tools, reproduce testbeds, and select suitable platforms for communication-aware control and cyber security studies. This paper addresses this issue by first comparing the latest works with particular focus on the method of interfacing and configuration architecture, and second, by showcasing two representative testbeds, used for analysing the impact of cyber events on distribution system and microgrid operation. The first testbed interfaces HYPERSIM (OPAL-RT Technologies) with MATLAB (version R2025a) using Modbus over TCP/IP for data exchange. This testbed configuration is capable of capturing the impacts of communication delays on Volt-VAR control in a modified IEEE 13-node test feeder. The second testbed uses two real-time power simulators, OPAL-RT and Typhoon HIL, both interfaced with the discrete-event simulator (DES) EXata Network Modelling (by Keysight Technologies) through modular Python-based scripts. This interfacing effectively enables the simulation of cyber attacks in microgrids. These testbeds show how recent advances in real-time simulation are enabling more practical cross-domain analysis of communication effects, control performance, and cyber vulnerabilities, while informing the design of more capable and future-ready CPPS simulation environments. Full article
(This article belongs to the Special Issue Cyber-Physical Systems: Recent Developments and Emerging Trends)
►▼ Show Figures

Figure 1

22 pages, 2107 KB  
Article
Hybrid Post-Quantum IKEv2 on Embedded Automotive Platforms: Design, Implementation, and Evaluation
by Ahmed Ayman Bahaa-Eldin, Mohamed Watheq El-Kharashi and Bassem Abdullah
Electronics 2026, 15(15), 3340; https://doi.org/10.3390/electronics15153340 - 28 Jul 2026
Cited by 1 | Viewed by 439
Abstract
The Internet Key Exchange Protocol Version 2 (IKEv2) underpins Internet Protocol Security (IPsec) by establishing secure associations and negotiating cryptographic keys. Its reliance on classical public-key primitives such as Elliptic Curve Diffie–Hellman (ECDH) renders it vulnerable to quantum attacks, as Shor’s algorithm can [...] Read more.
The Internet Key Exchange Protocol Version 2 (IKEv2) underpins Internet Protocol Security (IPsec) by establishing secure associations and negotiating cryptographic keys. Its reliance on classical public-key primitives such as Elliptic Curve Diffie–Hellman (ECDH) renders it vulnerable to quantum attacks, as Shor’s algorithm can break these schemes once large-scale quantum computers become available. To address this challenge, we integrate post-quantum cryptography into IKEv2 using a hybrid key exchange combining ECDH over P-384 with the ML-KEM-768 parameter set of the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM), following Request for Comments (RFC) 9370 and RFC 9242. We present a Fragmentation Boundary Model that identifies when post-quantum payloads approach or exceed the non-fragmenting IKE_SA_INIT payload budget across ML-KEM parameter sets, Internet Protocol (IP) versions, and effective path maximum transmission units (PMTUs). We implemented the hybrid design on a Texas Instruments TM4C1294 microcontroller running FreeRTOS and CycloneTCP, and measured its execution time, memory footprint, and network overhead. Across 150 successful handshakes per configuration, mean Security Association establishment time increased from 3390.4 to 3488.6 ms, an overhead of 98.2 ms (2.9%). Flash use increased by 8%, random-access memory (RAM) use by 5%, and total IKEv2 traffic size by 42%, while no IP fragmentation was observed under the evaluated Internet Protocol version 4 (IPv4) conditions. These findings establish the feasibility of the evaluated hybrid configuration on the TM4C1294 platform and provide a platform-specific baseline for further evaluation of quantum-resilient IPsec on embedded automotive architectures. Full article
►▼ Show Figures

Figure 1

22 pages, 1014 KB  
Article
A Deterministic, Rule-Based Framework for Detecting Anomalous IP Packet Fragmentation
by Maksim Iavich, Vladimer Svanadze and Oksana Kovalchuk
Future Internet 2026, 18(1), 19; https://doi.org/10.3390/fi18010019 - 29 Dec 2025
Cited by 2 | Viewed by 3845
Abstract
Anomalous IP packet fragmentation, whether caused by evasion attacks, misconfigurations, or network policy interference, presents a measurable threat to network integrity and intrusion detection systems. This paper introduces a lightweight, rule-based framework for detecting and classifying fragmented IP traffic. Unlike complex machine learning [...] Read more.
Anomalous IP packet fragmentation, whether caused by evasion attacks, misconfigurations, or network policy interference, presents a measurable threat to network integrity and intrusion detection systems. This paper introduces a lightweight, rule-based framework for detecting and classifying fragmented IP traffic. Unlike complex machine learning models that operate as “black boxes,” our model leverages the deterministic semantics of RFC 791 to inspect structural packet characteristics—such as offset alignment, Time-to-Live (TTL) consistency, and payload regularity—and classifies traffic into three transparent categories: normal (NONE), misconfigured (MISCONFIG), and adversarial (ATTACK). We generate an open-source and synthetic dataset of 10,000 packets, meticulously engineered to simulate a wide spectrum of benign and malicious fragmentation scenarios. Evaluation demonstrates high accuracy (99.23% overall) on this controlled dataset. Crucially, validation on the CIC-IDS-2017 real-world dataset confirms the model’s practical utility, showing a low false-positive rate (0.8%) on normal traffic and a significant increase in detectable anomalies during attack periods. This work provides a reproducible, interpretable, and efficient tool for forensic analysis and intrusion detection, enabling the precise diagnostics of packet-level fragmentation anomalies in operational networks. Full article
►▼ Show Figures

Figure 1

17 pages, 5528 KB  
Article
Protection Schemes for DDoS, ARP Spoofing, and IP Fragmentation Attacks in Smart Factory
by Tze Uei Chai, Hock Guan Goh, Soung-Yue Liew and Vasaki Ponnusamy
Systems 2023, 11(4), 211; https://doi.org/10.3390/systems11040211 - 20 Apr 2023
Cited by 7 | Viewed by 6091
Abstract
Industry Revolution 4.0 connects the Internet of Things (IoT) resource-constrained devices to Smart Factory solutions and delivers insights. As a result, a complex and dynamic network with a vulnerability inherited from the Internet becomes an attractive target for hackers to attack critical infrastructures. [...] Read more.
Industry Revolution 4.0 connects the Internet of Things (IoT) resource-constrained devices to Smart Factory solutions and delivers insights. As a result, a complex and dynamic network with a vulnerability inherited from the Internet becomes an attractive target for hackers to attack critical infrastructures. Therefore, this paper selects three potential attacks with the evaluation of the protections, namely (1) distributed denial of service (DDoS), (2) address resolution protocol (ARP) spoofing, and (3) Internet protocol (IP) fragmentation attacks. In the DDoS protection, the F1-score, accuracy, precision, and recall of the four-feature random forest with principal component analysis (RFPCA) model are 95.65%, 97%, 97.06%, and 94.29%, respectively. In the ARP spoofing, a batch processing method adopts the entropy calculated in the 20 s window with sensitivity to network abnormalities detection of various ARP spoofing scenarios involving victims’ traffic. The detected attacker’s MAC address is inserted in the block list to filter malicious traffic. The proposed protection in the IP fragmentation attack is implementing one-time code (OTC) and timestamp fields in the packet header. The simulation shows that the method detected 160 fake fragments from attackers among 2040 fragments. Full article
(This article belongs to the Topic SDGs 2030 in Buildings and Infrastructure)
►▼ Show Figures

Figure 1

12 pages, 567 KB  
Article
Fungal Communities Vectored by Ips sexdentatus in Declining Pinus sylvestris in Ukraine: Focus on Occurrence and Pathogenicity of Ophiostomatoid Species
by Kateryna Davydenko, Rimvydas Vasaitis, Malin Elfstrand, Denys Baturkin, Valentyna Meshkova and Audrius Menkis
Insects 2021, 12(12), 1119; https://doi.org/10.3390/insects12121119 - 14 Dec 2021
Cited by 16 | Viewed by 3949
Abstract
Drought-induced stress and attacks by bark beetle Ips sexdentatus currently result in a massive dieback of Pinus sylvestris in eastern Ukraine. Limited and fragmented knowledge is available on fungi vectored by the beetle and their roles in tree dieback. The aim was to [...] Read more.
Drought-induced stress and attacks by bark beetle Ips sexdentatus currently result in a massive dieback of Pinus sylvestris in eastern Ukraine. Limited and fragmented knowledge is available on fungi vectored by the beetle and their roles in tree dieback. The aim was to investigate the fungal community vectored by I. sexdentatus and to test the pathogenicity of potentially aggressive species to P. sylvestris. Analysis of the fungal community was accomplished by combining different methods using insect, plant, and fungal material. The material consisted of 576 beetles and 96 infested wood samples collected from six sample plots within a 300 km radius in eastern Ukraine and subjected to fungal isolations and (beetles only) direct sequencing of ITS rDNA. Pathogenicity tests were undertaken by artificially inoculating three-to-four-year-old pine saplings with fungi. For the vector test, pine logs were exposed to pre-inoculated beetles. In all, 56 fungal taxa were detected, 8 exclusively by isolation, and 13 exclusively by direct sequencing. Those included nine ophiostomatoids, five of which are newly reported as I. sexdentatus associates. Two ophiostomatoid fungi, which exhibited the highest pathogenicity, causing 100% dieback and mortality, represented genera Graphium and Leptographium. Exposure of logs to beetles resulted in ophiostomatoid infections. In conclusion, the study revealed numerous I. sexdentatus-vectored fungi, several of which include aggressive tree pathogens. Full article
(This article belongs to the Section Insect Pest and Vector Management)
►▼ Show Figures

Figure 1

Back to TopTop