Testbed for Network-Scale Countermeasure Evaluation

Award #: N/A
Amount Awarded: $45,938
Sponsoring Organization: Cisco
Grant Period: 2005-2006
Primary Investigator(s): Patrick McDaniel


Network-scale attacks are an increasing source of instability. Such attacks target entire networks or the larger Internet. Routing insecurities, forged domain names, worms, and DDoS attacks have all led to widespread outages and data compro- mise. Recent attempts to address these vulnerabilities have failed largely because of a lack of balance between security, performance, reliability, and manageabil- ity in the countermeasure designs. This work proposes a metrics-based platform for network-scale security evaluation. A range of countermeasures will be tested in several experimental environments, and general conclusions and optimizations identified. The results of this analysis will deeply inform efforts within the general network community and ongoing standards processes.

