One of the easiest ways to take down an organization’s IT system is through a distributed denial of service (DDoS), in which attackers flood the network with requests causing it to crash.
The Department of Homeland Security is trying out new ways to prevent and mitigate such attacks and awarded a $1.7 million contract to Galois to build a collaboration platform to help the agency do just that.
The system — which Galois calls the DDoS Defense for a Community of Peers (3DCoP) — uses peer-to-peer information sharing to reduce the time from detection to action, a major factor in limiting the impact of a DDoS attack.
“Current DDoS defense systems are proving ineffective because they operate in isolation, which introduces delays in the detection, reporting and response to a DDoS attack,” said Adam Wick, research lead for mobile security and systems software at Galois. “This delay is critical. It provides positive feedback to the attacker, who will continue to send more and more traffic at the target network. Our solution advances the state of DDoS defense by providing new tools that allow multiple defenders to coordinate their response, resulting in earlier detection and faster DDoS mitigation.”
When a DDoS attack occurs, organizations have to contact the Internet Service Provider to adjust how traffic flows into the network. By merging how DHS components’ — and eventually the entire federal government — view and communicate these attacks, they gain the ability to act in concert.
“As a result, rather than having a single, small entity requesting a rule change of a major ISP, we create a large virtual organization that acts with consensus,” Wick explained. “Using our tools, organizations will be able to respond more rapidly to large dynamic attacks and employ mitigation strategies before reaching complete network saturation.”
Wick said the 3DCoP program will help organizations like DHS reduce the time to detection by 25 percent and the time it takes to mitigate the effects of an attack by 50 percent. Once those mitigation efforts begin, they can reduce the traffic load by 75 to 90 percent, allowing legitimate users to continue accessing the system.
“Underlying our implementation is a unique traffic flow monitoring capability, which observes traffic flows and finds patterns of interest,” he added. “The mechanism doesn’t only detect the DDoS attacks, it also helps stop them.”




