Location Hiding Architecture for Mitigating DDoS Attacks in SCADA Systems
DOI:
https://doi.org/10.70454/JRICST.2026.030303Keywords:
Cyber-Attack, Distributed Denial of Service, SCADA, ProtectionAbstract
Distributed Denial of Service (DDoS) attacks are posing an increasing threat to SCADA systems, which are the core infrastructure for power grids, water treatment, oil and gas pipelines, and many other critical infrastructure systems. The growing connectivity of such systems and their dependence on legacy communication protocols make them quite susceptible to large-scale disruptions. This paper introduces a novel Location Hiding Architecture (LHA) for the protection of SCADA systems to improve the security and availability by hiding the real network location of the interested entity. The proposed architecture employs a multi-layer proxy mechanism with two types of proxies - setup and data. The system design keeps the public access interface separate from the SCADA core and ensures that an attacker can never directly see critical assets, much less target them. With dynamic proxy allocation, hidden routing paths, and anycast-based proxy distribution, we achieve scalability, resilience, and fast removal of compromised nodes from the system. Furthermore, it has adaptive traffic filtering and controlled access for reducing bad interactions. Simulation results show that a proxy density of 0. 5% can successfully block more than 93% of the DDoS traffic even when malicious nodes constitute as much as 10% of the network. The presented LHA framework enables a strong, scalable, defensive layer to effectively secure modern SCADA against evolving cyber threats.
Downloads
References
[1] E. Söğüt and O. A. Erdem, “A multi-model proposal for classification and detection of DDoS attacks on SCADA systems,” Applied Sciences, vol. 13, no. 10, p. 5993, 2023, doi: 10.3390/app13105993.
[2] F. Alenezi, S. Almowuena, A. Alenezi, and M. J. F. Alenazi, “CIDS: A collaborative intrusion detection system approach for SDN-based distributed industrial plants,” Transactions on Emerging Telecommunications Technologies, vol. 37, no. 1, p. e70327, 2026, doi: 10.1002/ett.70327.
[3] C. Hjaiji, B. Ouni, and M.-S. Alouini, “Cybersecurity of high-altitude platform stations: Threat taxonomy, attacks and defenses with standards mapping—DDoS attack use case,” IEEE Open Journal of the Communications Society, vol. 7, pp. 328–352, 2026, doi: 10.1109/OJCOMS.2025.3650132.
[4] Microsoft 365, “Top 5 most famous DDoS attacks,” Feb. 17, 2023. [Online]. Available: https://www.microsoft.com/en-us/microsoft-365-life-hacks/privacy-and-safety/top-5-most-famous-ddos-attacks
[5] A. S. Athamnih et al., “AI-driven cybersecurity for SCADA-integrated microgrids: A real-time detection framework,” in Proc. IEEE 5th Int. Conf. AI in Cybersecurity (ICAIC), Houston, TX, USA, 2026, pp. 1–6, doi: 10.1109/ICAIC67076.2026.11395662.
[6] M. Hassan, A. Gumaei, S. Huda, and A. Almogren, “Increasing the trustworthiness in the industrial IoT networks through a reliable cyberattack detection model,” IEEE Transactions on Industrial Informatics, vol. 16, no. 9, pp. 6154–6162, 2020.
[7] F. Reegu, W. Khan, S. Daud, Q. Arshad, and N. Armi, “A reliable public safety framework for industrial internet of things (IIoT),” in Proc. Int. Conf. Radar, Antenna, Microwave, Electronics, and Telecommunications (ICRAMET), Serpong, Indonesia, 2020, pp. 189–193.
[8] Swati, S. Roy, J. Singh, et al., “Design and analysis of DDoS mitigating network architecture,” International Journal of Information Security, vol. 22, pp. 333–345, 2023, doi: 10.1007/s10207-022-00635-1.
[9] S. Oyucu, O. Polat, M. Türkoğlu, H. Polat, A. Aksöz, and M. T. Ağdaş, “Ensemble learning framework for DDoS detection in SDN-based SCADA systems,” Sensors, vol. 24, no. 1, p. 155, 2024, doi: 10.3390/s24010155.
[10] H. Li and G. Xiang, “Research on DDoS attack detection based on SDN architecture,” in Proc. 4th Int. Conf. Cryptography, Network Security and Communication Technology (CNSCT), New York, NY, USA, 2025, pp. 75–79, doi: 10.1145/3723890.3723903.
[11] X. Zhang, Y. Song, and C. Ge, “A DDoS attack detection and mitigation system in SDN,” in Proc. 14th Int. Conf. Computer Engineering and Networks (CENet 2024), Lecture Notes in Electrical Engineering, vol. 1387, Singapore: Springer, 2025, doi: 10.1007/978-981-96-4245-8_9.
[12] J. A. Pérez-Díaz, I. A. Valdovinos, K.-K. R. Choo, and D. Zhu, “A flexible SDN-based architecture for identifying and mitigating low-rate DDoS attacks using machine learning,” IEEE Access, vol. 8, pp. 155859–155872, 2020, doi: 10.1109/ACCESS.2020.3019330.
[13] M. Revathi and S. K. Devi, “Hybrid architecture for mitigating DDoS and other intrusions in SDN-IoT using MHDBN-W deep learning model,” International Journal of Machine Learning and Cybernetics, vol. 16, pp. 6997–7018, 2025, doi: 10.1007/s13042-024-02147-x.
[14] R. Swami, M. Dave, and V. Ranga, “Mitigation of DDoS attack using moving target defense in SDN,” Wireless Personal Communications, vol. 131, pp. 2429–2443, 2023, doi: 10.1007/s11277-023-10544-8.
[15] S. Kautish, R. A, and A. Vidyarthi, “SDMTA: Attack detection and mitigation mechanism for DDoS vulnerabilities in hybrid cloud environment,” IEEE Transactions on Industrial Informatics, vol. 18, no. 9, pp. 6455–6463, Sep. 2022, doi: 10.1109/TII.2022.3146290.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Deepak Sharma, Raj Kamal (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
This is an Open Access article distributed under the term's of the Creative Common Attribution 4.0 International License permitting all use, distribution, and reproduction in any medium, provided the work is properly cited.













