• DocumentCode
    775903
  • Title

    Adaptive Defense Against Various Network Attacks

  • Author

    Zou, Cliff C. ; Duffield, Nick ; Towsley, Don ; Gong, Weibo

  • Author_Institution
    Sch. of Electr. Eng. & Comput. Sci., Central Florida Univ., Orlando, FL
  • Volume
    24
  • Issue
    10
  • fYear
    2006
  • Firstpage
    1877
  • Lastpage
    1888
  • Abstract
    In defending against various network attacks, such as distributed denial-of-service (DDoS) attacks or worm attacks, a defense system needs to deal with various network conditions and dynamically changing attacks. Therefore, a good defense system needs to have a built-in "adaptive defense" functionality based on cost minimization-adaptively adjusting its configurations according to the network condition and attack severity in order to minimize the combined cost introduced by false positives (misidentify normal traffic as attack) and false negatives (misidentify attack traffic as normal) at any time. In this way, the adaptive defense system can generate fewer false alarms in normal situations or under light attacks with relaxed defense configurations, while protecting a network or a server more vigorously under severe attacks. In this paper, we present concrete adaptive defense system designs for defending against two major network attacks: SYN flood DDoS attack and Internet worm infection. The adaptive defense is a high-level system design that can be built on various underlying nonadaptive detection and filtering algorithms, which makes it applicable for a wide range of security defenses
  • Keywords
    Internet; computer viruses; information filters; telecommunication security; Internet worm infection; SYN flood DDoS attack; adaptive defense system design; distributed denial-of-service; filtering algorithm; high-level system design; nonadaptive detection; security; Adaptive systems; Computer crime; Concrete; Cost function; Filtering algorithms; IP networks; Network servers; Protection; Telecommunication traffic; Web server; Adaptive defense; Internet worm; SYN flood; computer security; distributed denial-of-service (DDoS);
  • fLanguage
    English
  • Journal_Title
    Selected Areas in Communications, IEEE Journal on
  • Publisher
    ieee
  • ISSN
    0733-8716
  • Type

    jour

  • DOI
    10.1109/JSAC.2006.877137
  • Filename
    1705619