Detecting Flood-based Attacks against SIP Proxy Servers and Clients using Engineered Feature Sets

Detecting Flood-based Attacks against SIP Proxy Servers and Clients using Engineered Feature Sets
复制标题

使用工程功能集检测针对 SIP 代理服务器和客户端的基于洪水的攻击

DOI:
--
复制
发表时间:
2016
期刊:
--
影响因子:
--
通讯作者:
B. Raahemi
B. Raahemi
中科院分区:
--
文献类型:
--
作者:
Hassan Asgharian;A. Akbari;B. Raahemi

文献摘要

被引文献

相似文献

SIP (Session Initiation Protocol)是下一代网络的主要信令协议。基于sip的实体(即代理服务器和客户端)的安全问题直接影响终端用户在多媒体会话中的感知体验质量。本文重点研究了IP泛洪攻击,包括拒绝服务攻击和分布式拒绝服务攻击。在对各种类型的SIP攻击根据其来源进行分类之后,我们根据其攻击组的规范提取了四个特征集,以及RFC 3261中规定的SIP状态机的正常行为。然后,我们最小化每个集合中派生特征的数量,以减少我们提出的方法的计算复杂性。这有助于在基于S ip的嵌入式设备(如手机和智能电视)中使用经过设计的功能集。我们评估了所提出的特征集在检测SIP攻击序列方面的性能。为此,我们为基于sip的服务设计并实现了一个真实的测试平台,以生成正常流量和攻击流量。实验结果表明,所设计的特征集在各种攻击场景下对良性流量和异常流量进行分类时,在检测准确率和虚警率方面表现良好。
Session Initiation Protocol (SIP) is the main signaling protocol of the next generation networks. The security issues of SIP-based entities (i.e. proxy servers and clients) have a direct impact on the perceived quality of experience of end users in multimedia sessions. In this paper, our focus is on the S IP flooding attacks including denial of service and distributed denial of service attacks. After classifying various types of SIP attacks based on their sources, we extract four feature sets based on the specification of its attack group, as well as the normal behavior of the SIP state machine specified in RFC 3261. We then minimize the number of derived features in each set to reduce the computational complexity of our proposed approach. This facilitates employing the engineered feature sets in embedded S IP-based devices such as cell phones and smart TVs. We evaluate the performance of the proposed feature sets in detecting SIP attack sequence. For this, we design and implement a real test-bed for SIP-based services to generate normal and attack traffics. The experimental results confirm that the engineered feature sets perform well in terms of detection accuracy and false alarm rates in classifying benign and anomaly traffic in various attack scenarios.