Simulate network attacks and defences
NetSim provides a framework to model and simulate network attacks. You can observe how an attack, and its countermeasures, affect network performance. The simulation is packet-level, so you study an attack through its effect on protocol behaviour and on end-to-end throughput, delay and loss.
NetSim has a modular format. Its components are also called Technology Libraries or Toolboxes, and each component covers a set of networking technologies. See the list of libraries in NetSim.
Looking for power-system cyberattacks?
This page covers attack simulation in the general networking libraries. For cyberattacks on power-grid Cyber-Physical Power Systems, see the NetSim Cyber product. It covers protocols such as IEEE C37.118, IEC 61850 GOOSE/SV, Modbus, DNP3 and IEC 60870-5-104.
Attack and defence projects by technology
Each worked example models an attack, then measures its effect on the network.
Internet of Things
RPL, LEACH and DDoS attacks on IoT and WSN deployments.
- DIO Suppression Attack in IoT A malicious node suppresses RPL DIO control messages so neighbours cannot maintain or repair routes.
- RPL DIS Flooding An attacker floods DIS messages, forcing nodes to reset trickle timers and waste energy on repeated DIO broadcasts.
- Sinkhole Attack in RPL A node advertises a falsely favourable rank to draw routes and traffic through itself.
- Sinkhole Attack in LEACH A compromised cluster head attracts sensor traffic in a LEACH-based wireless sensor network.
- Intrusion Detection System for LEACH A detection scheme identifies malicious nodes in a LEACH cluster.
- DDoS Attacks: botnet, bit-and-piece Distributed denial-of-service attacks hit an IoT network, with botnet and bit-and-piece flooding.
Internetworks
Data integrity, encryption and Wi-Fi MAC attacks.
- False Data Injection Attack An attacker injects false data into the network to mislead receivers and corrupt application state.
- Implementing a new encryption algorithm Add a custom cipher (MISTY) to the protocol stack to secure traffic.
- Backoff Attack in Wi-Fi A node manipulates the 802.11 contention backoff to seize an unfair share of the channel.
MANET
Routing attacks and defences for ad hoc networks.
- Sinkhole Attack in DSR A node falsifies route replies to attract traffic in a DSR-routed MANET.
- Sinkhole Attack in AODV A node advertises false route metrics to pull traffic through itself in an AODV network.
- Secure AODV A hardened AODV variant authenticates routing messages to resist tampering.
- Intrusion Detection System for MANETs A detection scheme flags malicious routing behaviour in a mobile ad hoc network.
Cognitive Radio
Spectrum-access attacks on secondary users.
- Primary User Emulation (PUE) Attack An attacker mimics primary-user signals so secondary users vacate the band and lose spectrum access.
Vehicular Ad hoc Network
Attacks and detection for VANETs.
- Sinkhole Attack A vehicle advertises false routes to attract traffic in a VANET.
- Intrusion Detection System for VANET A detection scheme identifies malicious vehicles in a VANET.
Network Emulation
Attacks against real applications through the emulator.
- SlowHTTPtest DoS Attack The NetSim emulator drives a slow-HTTP denial-of-service attack against a real server.
Extend the protocol stack
NetSim ships with protocol source code in C. Modify the stack to model new attacks, build countermeasures, and develop your own security protocols.