Rebound and Reseeding Stress Test¶
Forward, adversarial stress test — instantiates Sanctuary-Aware Source Control
Before declaring victory, deliberately imagines the surviving source rebounding and reseeding the cleared zones — to see whether the barrier holds and to harden the contingency plan for when it doesn't.
The dangerous moment in a source-control campaign is the one just before standing down, when the sinks look clean and everyone wants to call it done. Rebound and Reseeding Stress Test attacks that moment on purpose: it assumes the low-contestation source survives — because in this archetype it usually does — and plays its comeback forward, asking what the fastest path back is, whether the reseeding barrier actually holds against it, and whether the contingency plan fires in time. Its defining move is that it is hypothetical and adversarial: unlike a monitor, which reports the observed present, this test manufactures the worst plausible future and pressure-tests the campaign against it before committing to declare success. What it produces is a hardened rebound plan and a real specification for the barrier — the reseeding rate that barrier must actually be built to withstand.
Example¶
A coalition preparing to take down a credential-stealing botnet is about to seize its command-and-control (C2) domains and sinkhole the infected machines — the sinks. The Rebound and Reseeding Stress Test runs before the takedown, as a red-team exercise. Its starting assumption is uncomfortable: the operators' actual source — a bulletproof-hosting foothold in a jurisdiction no one in the coalition can reach — will survive the takedown intact. So the team plays the rebound. How fast can the operators re-seed a new C2? They walk the fastest paths: a domain-generation algorithm (DGA) that rolls fresh domains daily, a fast-flux fallback, a hard-coded backup channel. The sobering finding is that under current plans the operators could stand up working C2 again within ≈72 hours, faster than the registrar takedowns could keep pace — the sinkhole barrier leaks.
That result does two things. It sets the barrier's real spec: to matter, the domain-seizure barrier has to pre-empt the DGA space and hold for at least the weeks it would take to actually reach the hosting source, not just clip today's domains. And it hardens the rebound plan into something rehearsed — pre-registered DGA domains, standby takedown authority, and a re-seize trigger wired to the surveillance signal — so that when reseeding starts, the response is a drill, not an improvisation. The test doesn't run the takedown or build the sinkhole; it makes sure both are built for the rebound that the surviving source guarantees.
How it works¶
- Assume the source survives. Take as given that the low-contestation source persists, and refuse the comfortable premise that clean sinks mean the campaign is over.
- Play the reseed forward. Exercise the plausible reseeding pathways from source back into the cleared zones, using the source–sink reseeding model as the terrain — fastest path first.
- Pressure-test the barrier. Subject candidate barrier designs to the modeled reseeding load and find where they leak; derive the specification the barrier must meet to hold long enough.
- Harden the contingency plan. Turn each surviving failure into a rehearsed rebound response with explicit triggers, so a real reseed fires a drilled plan rather than an argument.
Tuning parameters¶
- Adversary aggressiveness — how capable and motivated you assume the surviving source is. Conservative assumptions make a harder test and a more robust plan; optimistic ones flatter a fragile one.
- Scenario breadth — a single worst-case path versus a portfolio of reseeding routes. Breadth catches more, but dilutes depth on any one path.
- Rebound-speed assumption — how fast reseeding is modeled to occur. Faster demands a tighter barrier and a pre-positioned response.
- Pass bar — what counts as surviving the test (barrier holds ≥ N months? rebound plan fires within T?). Set the bar to the time it actually takes to reach and neutralize the source.
- Tabletop versus live-fire — a pre-mortem walkthrough or an actual limited rebound drill. Live-fire is more realistic but costs more and carries its own risk.
When it helps, and when it misleads¶
Its strength is that it surfaces the whack-a-mole failure before the campaign commits to it. The reason sanctuary-aware campaigns collapse is almost always an un-modeled reseed from a source that was never reachable; this is the step where that path is found, the barrier is given a spec that can actually hold it, and the contingency plan is rehearsed into a reflex rather than left to improvisation under pressure.
Its failure mode is that a stress test can only break the scenarios someone imagined — an unmodeled reseeding pathway passes the test untouched, precisely because no one thought to run it — and optimistic adversary assumptions make a brittle plan look sound.[n1] The classic misuse is to run it as theater: a box-checking exercise staged to bless a takedown that was already scheduled, rather than a genuine attempt to break it. The discipline that guards against this is to have an independent red team author the scenarios, carry an explicit "unknown pathway" reserve, and treat any pass as conditional on the assumed adversary — re-running the moment the source proves more capable than modeled.
How it implements the components¶
Rebound and Reseeding Stress Test realizes the resilience-and-contingency side of the archetype — the components that decide whether the win will survive the source's comeback:
relapse_or_rebound_plan— its principal deliverable: the tested, hardened contingency plan, with triggers, for when rebound and reseeding occur.reinfestation_or_reinfection_barrier— it sets the barrier's required specification (the reseeding load it must withstand) and pressure-tests candidate designs; the operational barrier itself is built by the Containment Barrier.
It does not build the source–sink reseeding model it runs scenarios on — that comes from the Source–Sink Network Mapping, which it consumes — nor does it detect an actual rebound in progress (the Sentinel Surveillance Dashboard) or harvest lessons after a real event (the Cross-Boundary After-Action Review).
Related¶
- Instantiates: Sanctuary-Aware Source Control — the test proves, before stand-down, that the campaign can survive the reseed a surviving source guarantees.
- Consumes: Source–Sink Network Mapping supplies the reseeding model whose pathways the test exercises.
- Sibling mechanisms: Sentinel Surveillance Dashboard · Source–Sink Network Mapping · Containment Barrier · Cross-Boundary After-Action Review · Source Reduction Program · Synchronized Campaign Calendar · Sanctuary Reachability Audit · Below-Replacement Confirmation Test · Coordinated Access Protocol · Protected-Zone Exception Review
Editorial Notes¶
Form Classification¶
Form family: Experiment, Test & Rehearsal
Rationale: Rebound and Reseeding Stress Test operates as an active test, trial, simulation, drill, or rehearsal that generates evidence through a deliberate attempt or perturbation because it before declaring victory, deliberately imagines the surviving source rebounding and reseeding the cleared zones — to see whether the barrier holds and to harden the contingency plan for when it doesn't.
Independent corroboration: The frozen evidence defines Rebound and Reseeding Stress Test as 'Before declaring victory, deliberately imagines the surviving source rebounding and reseeding the cleared zones — to see whether the barrier holds and to harden the contingency plan for when it doesn't', so its operative form is Experiment, Test & Rehearsal.
Review outcome: Independent reviewer agreement; high confidence.
Origin Attribution¶
Primary origin: Biology & Ecology
Origin pattern: Convergent development
Present-day reach: Multi-domain
Rationale: Rebound from refugia and reseeding cleared areas are established population-ecology dynamics.
Related originating lineages:
- Agricultural Science & Agronomy — Pest-management practice independently tests reinvasion from untreated sanctuaries.
- Medicine & Healthcare — Infection-control traditions similarly assess residual reservoirs and recurrence.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Independent reviewer agreement; medium confidence.
Notes¶
This test is the forward twin of the retrospective Cross-Boundary After-Action Review: the stress test rehearses the rebound before it happens, while the after-action review harvests the lessons after a real one. It is also worth remembering what a pass certifies — preparation against the imagined adversary, not safety. A campaign that treats a passing stress test as proof the source is gone has made exactly the mistake the archetype warns against.
[n1] Red-teaming is the practice of assigning an independent group to adversarially probe a plan or system by playing the opponent, deliberately surfacing failure paths the owners are motivated to overlook. Its known limit is scenario blindness: it can only exercise the attacks that were imagined, which is why an explicit reserve for unmodeled pathways is part of doing it honestly. ↩