Network Security Lab
Computer and Information Sciences
University of Delaware
28 W. Delaware Ave. Newark, DE, 19716

 


DefCOM DefCOM: Defensive Cooperative Overlay Mesh harvest the strengths of existing defenses by organizing them into a collaborative overlay, and loading them with communication and collaboration functionalities. Nodes collaborate during the attack to spread alerts and recognize and protect legitimate traffic, while rate limiting the attack. DefCOM can accommodate a large variety of existing defenses, provide synergistic response to attacks and naturally lead to Internet-wide response to DDoS threat.
ICR Internet Credit Report (ICR) is an Internet-wide reputation system. The ICR system monitors Internet-wide activities and assign each host a reputation score based on its behaving history. The reputation score represents a long-term evaluation of the host's behaviors and can be used as knowledge for predicting the host's future reliability. Another goal in ICR project is to model the Internet traffic and further understand the general communication patterns.
Self-Healing Networks
PAWS PAWS is a time discrete packet-level simulator. Compared with other worm modeling and simulations, PAWS replicates more details of the Internet environment and has less simplification on worm characteristics and vulnerable hosts behaviors. PAWS simulates a realistic Internet model and the background traffic load, enabling investigation of possible congestion effects and sufferings of legitimate traffic during worm spread. PAWS further supports various user-customizable parameters that enables testing of different worm characteristics, host and network diversity models.
DDOS Benchmarks The benchmark suite defines all the necessary elements to recreate relevant DDoS attack scenarios in a test bedsetting. These relevant scenarios are divided into three categories: (1) typical attacks observed in today's internet. (2) future attacks that have been proposed by researchers and that are more complex than existing attacks and (3) stress attacks that aim to create a ripple effect in the target network by hitting a critical service for this network's operation(e.g Routing)