Detecting Denial of Service Message Flooding Attacks in SIP based Services
Detecting Denial of Service Message Flooding Attacks in SIP based Services
复制标题
检测基于 SIP 的服务中的拒绝服务消息洪泛攻击
DOI:
10.22060/eej.2012.44
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
B. Raahemi
中科院分区:
文献类型:
--
作者:
Zoha Asgharian;Hassan Asgharian;A. Akbari;B. Raahemi
Increasing the popularity of SIP based services (VoIP, IPTV, IMS infrastructure) lead to concerns about its The main signaling protocol of next generation networks and VoIP systems is Session Initiation Protocol Inherent vulnerabilities of SIP, misconfiguration of its related components and also its implementation cause some security concerns in SIP based infrastructures. New attacks are developed that target the underlying SIP protocol in these related SIP setups. To detect such kinds of attacks we combined -based and specification-based intrusion detection techniques. We took advantages of the SIP state machine (according to RFC 3261) in our proposed solution. We also built and configured a real test-bed for SIP services to generate normal and assumed attack traffics. We validated and evaluated our intrusion detection with the dump traffic of this real test-bed and we also used another specific available dataset to have a more evaluation. The experimental results show that our approach is effective in classifying normal and traffic in different situations. The Receiver Operating Characteristic (ROC) analysis is applied on final results to select the working point of our system (set related thresholds).