On the detection of signaling DoS attacks on 3G/WiMax wireless networks

On the detection of signaling DoS attacks on 3G/WiMax wireless networks
复制标题

DOI:
10.1016/j.comnet.2009.05.008
复制
发表时间:
2009-10
期刊:
Comput. Networks
影响因子:
--
通讯作者:
P. Lee;T. Bu;Thomas Y. C. Woo
P. Lee;T. Bu;Thomas Y. C. Woo
中科院分区:
其他
文献类型:
--
作者:
P. Lee;T. Bu;Thomas Y. C. Woo

文献摘要

被引文献

相似文献

基于CDMA 2000和UMTS标准的第三代(3G)无线网络现在正越来越多地在全世界部署。由于其复杂的信令和相对有限的带宽,这些3G网络通常比有线网络更容易受到攻击,从而为新的攻击提供了肥沃的土壤。在本文中,我们确定和研究一种新的拒绝服务(DoS)攻击,称为信令攻击,利用独特的漏洞,在3G无线网络中的信令/控制平面。使用由真实的痕迹驱动的模拟,我们能够证明信令攻击的影响。具体来说,我们展示了如何一个适时的低容量信令攻击可能会超载的控制平面和恶意影响的关键要素在3G无线基础设施。信号攻击的低容量特性使其能够避免现有入侵检测算法的检测,这些算法通常是基于签名或容量的。作为对策,我们提出并评估了一个在线早期检测算法的基础上的统计的统计量的方法。通过使用广泛的跟踪驱动的模拟,我们证明了该算法是强大的,可以识别攻击在其开始,在重大损害之前。除了3G网络,我们还表明,许多新兴的广域网,如802.16/WiMax共享相同的漏洞,我们的解决方案也可以适用。
Third generation (3G) wireless networks based on the CDMA2000 and UMTS standards are now increasingly being deployed throughout the world. Because of their complex signaling and relatively limited bandwidth, these 3G networks are generally more vulnerable than their wireline counterparts, thus making them fertile ground for new attacks. In this paper, we identify and study a novel denial of service (DoS) attack, called signaling attack, that exploits the unique vulnerabilities of the signaling/control plane in 3G wireless networks. Using simulations driven by real traces, we are able to demonstrate the impact of a signaling attack. Specifically, we show how a well-timed low-volume signaling attack can potentially overload the control plane and detrimentally affect the key elements in a 3G wireless infrastructure. The low-volume nature of the signaling attack allows it to avoid detection by existing intrusion detection algorithms, which are often signature or volume-based. As a counter-measure, we present and evaluate an online early detection algorithm based on the statistical CUSUM method. Through the use of extensive trace-driven simulations, we demonstrate that the algorithm is robust and can identify an attack in its inception, before significant damage is done. Apart from 3G networks, we also show that many emerging wide-area networks such as 802.16/WiMax share the same vulnerability and our solution can also apply.