Detecting Denial of Service Message Flooding Attacks in SIP based Services

Detecting Denial of Service Message Flooding Attacks in SIP based Services
复制标题

检测基于 SIP 的服务中的拒绝服务消息洪泛攻击

DOI:
10.22060/eej.2012.44
复制
发表时间:
2012
期刊:
--
影响因子:
--
通讯作者:
B. Raahemi
B. Raahemi
中科院分区:
--
文献类型:
--
作者:
Zoha Asgharian;Hassan Asgharian;A. Akbari;B. Raahemi

文献摘要

被引文献

相似文献

下一代网络和VoIP系统的主要信令协议‎是会话初始协议‎‎的主要信令协议。会话初始协议的固有弱点、相关组件的错误配置及其实现‎在基于会话初始协议的基础设施中引起了一些安全担忧。开发了新的攻击,目标是这些相关的‎设置中的底层sip协议。为了检测这类攻击,我们结合了基于‎和基于规范的入侵检测技术。在我们提出的解决方案中,我们利用了SIP状态机‎(根据RFC3261)。我们还为‎服务构建和配置了一个真实的测试平台,以生成正常和假想的攻击流量。我们使用这个真实测试台的转储流量验证和评估了我们的入侵检测‎,并使用了另一个特定的可用数据集来进行更多的‎评估。实验结果表明,该方法对不同情况下的正常流量和‎流量的分类是有效的。在最终的‎结果上应用接收器工作特性(ROC)分析来选择我们系统的工作点(设置相关阈值)。‎
Increasing the popularity of SIP based services (VoIP, IPTV, IMS infrastructure) lead to concerns about its ‎The main signaling protocol of next generation networks and VoIP systems is Session Initiation Protocol ‎‎Inherent vulnerabilities of SIP, misconfiguration of its related components and also its implementation ‎cause some security concerns in SIP based infrastructures. New attacks are developed that target ‎the underlying SIP protocol in these related SIP setups. To detect such kinds of attacks we combined ‎-based and specification-based intrusion detection techniques. We took advantages of the SIP state machine ‎(according to RFC 3261) in our proposed solution. We also built and configured a real test-bed for SIP ‎services to generate normal and assumed attack traffics. We validated and evaluated our intrusion detection ‎with the dump traffic of this real test-bed and we also used another specific available dataset to have a more ‎evaluation. The experimental results show that our approach is effective in classifying normal and ‎traffic in different situations. The Receiver Operating Characteristic (ROC) analysis is applied on final ‎results to select the working point of our system (set related thresholds). ‎