Check out the new USENIX Web site.

USENIX Home . About USENIX . Events . membership . Publications . Students
Steps to Reducing Unwanted Traffic on the Internet Workshop — Abstract

Pp. 69–75 of the Proceedings

Adaptive Defense Against Various Network Attacks

Cliff C. Zou, University of Massachusetts Amherst; Nick Duffield, AT&T—Labs Research; Don Towsley and Weibo Gong, University of Massachusetts Amherst


In defending against various network attacks, such as Distributed Denial-of-Service (DDoS) attacks or worm attacks, a defense system needs to deal with various network conditions and dynamically changing attacks. In this paper, we introduce an ``adaptive defense" principle based on cost minimization -- a defense system adaptively adjusts its configurations according to the network condition and attack severity in order to minimize the combined cost introduced by false positives (misidentify normal traffic as attack) and false negatives (misidentify attack traffic as normal) at any time. In this way, the adaptive defense system generates fewer false alarms in normal situations (or under light attacks) with relaxed defense configurations, while protecting a network or a server more vigorously under severe attacks. Specifically, we present detailed adaptive defense system designs for defending against two major network attacks: SYN flood DDoS attack and Internet worm infection. The adaptive defense is a high-level system design that can be built on top of various non-adaptive detection and filtering algorithms, which makes it applicable for a wide range of security defenses.
  • View the full text of this paper in HTML and PDF, or the talk slides in PDF.

    Click here if you have forgotten your password Until July 2006, you will need your USENIX membership identification in order to access the full papers. The Proceedings are published as a collective work, © 2005 by the USENIX Association. All Rights Reserved. Rights to individual papers remain with the author or the author's employer. Permission is granted for the noncommercial reproduction of the complete work for educational or research purposes. USENIX acknowledges all trademarks within this paper.

  • If you need the latest Adobe Acrobat Reader, you can download it from Adobe's site.
To become a USENIX Member, please see our Membership Information.

?Need help? Use our Contacts page.

Last changed: 18 Aug. 2005 ch
Technical Program
SRUTI '05 Home