• DocumentCode
    1114554
  • Title

    Testing a Collaborative DDoS Defense In a Red Team/Blue Team Exercise

  • Author

    Mirkovic, Jelena ; Reiher, Peter ; Papadopoulos, Christos ; Hussain, Alefiya ; Shepard, Marla ; Berg, Michael ; Jung, Robert

  • Author_Institution
    USC Inf. Sci. Inst., Marina del Rey, CA
  • Volume
    57
  • Issue
    8
  • fYear
    2008
  • Firstpage
    1098
  • Lastpage
    1112
  • Abstract
    Testing security systems is challenging because a system´s authors have to play the double role of attackers and defenders. Red team/blue team exercises are an invaluable mechanism for security testing. They partition researchers into two competing teams of attackers and defenders, enabling them to create challenging and realistic test scenarios. While such exercises provide valuable insight into vulnerabilities of security systems, they are very expensive and thus rarely performed. In this paper we describe a red team/blue team exercise, sponsored by DARPA´s FTN program, and performed October 2002 --- May 2003. The goal of the exercise was to evaluate a collaborative DDoS defense, comprised of a distributed system, COSSACK, and a stand-alone defense, D-WARD. The role of the blue team was played by developers of the tested systems from USC/ISI and UCLA, the red team included researchers from Sandia National Laboratory, and all the coordination, experiment execution, result collection and analysis was performed by the white team from BBN Technologies. This exercise was of immense value to all involved --- it uncovered significant vulnerabilities in tested systems, pointed out desirable characteristics in DDoS defense systems (e.g., avoiding reliance on timing mechanisms), and taught us many lessons about testing of DDoS defenses.
  • Keywords
    groupware; program testing; security of data; COSSACK; D-WARD; collaborative DDoS defense; denial of service; distributed system; security system testing; Collaboration; Documentation; Information security; Intersymbol interference; Laboratories; Performance analysis; Performance evaluation; Robustness; System testing; Timing; Certification; Network-level security and protection; Testing; and Licensing;
  • fLanguage
    English
  • Journal_Title
    Computers, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9340
  • Type

    jour

  • DOI
    10.1109/TC.2008.42
  • Filename
    4479443