A method of progressive response for invoking and suspending blocking
measures that defend against network anomalies such as malicious network
traffic so that false positives and false negatives are minimized. When
an anomaly is detected, the detector notifies protective equipment such
as a firewall or a router to invoke a blocking measure. The blocking
measure is maintained for an initial duration, after which it is
suspended while another test for the anomaly is made. If the anomaly is
no longer evident, the method returns to the state of readiness.
Otherwise, a loop is executed to re-applying the blocking measure for a
specified duration, then suspend the blocking measure and test again for
the anomaly. If the anomaly is detected, the blocking measure is
re-applied, and its duration is adapted. If the anomaly is no longer
detected, the method returns to the state of readiness.