• DocumentCode
    2013490
  • Title

    Detection and prevention of SIP flooding attacks in voice over IP networks

  • Author

    Tang, Jin ; Cheng, Yu ; Hao, Yong

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Illinois Inst. of Technol., Chicago, IL, USA
  • fYear
    2012
  • fDate
    25-30 March 2012
  • Firstpage
    1161
  • Lastpage
    1169
  • Abstract
    As voice over IP (VoIP) increasingly gains popularity, traffic anomalies such as the SIP flooding attacks are also emerging and becoming into a major threat to the technology. Thus, detecting and preventing such anomalies is critical to ensure an effective VoIP system. The existing flooding detection schemes are inefficient in detecting low-rate flooding from dynamic background traffic, or may even totally fail when flooding is launched in a multi-attribute manner by simultaneously manipulating different types of SIP messages. In this paper, we develop an online scheme to detect and subsequently prevent the flooding attacks, by integrating a novel three-dimensional sketch design with the Hellinger distance (HD) detection technique. The sketch data structure summarizes the incoming SIP messages into a compact and constant-size data set based on which a separate probability distribution can be established for each SIP attribute. The HD monitors the evolution of the probability distributions and detects flooding attacks when abnormal variations are observed. The three-dimensional design equips our scheme with the advantages of high detection accuracy even for low-rate flooding, robust performance under multi-attribute flooding, and the capability of selectively discarding the offending SIP messages to prevent the attacks. Moreover, we develop an estimation freeze mechanism to protect the detection threshold from being polluted by attacks. Not only do we theoretically analyze the performance of the proposed detection and prevention techniques, but also resort to extensive simulations to thoroughly examine the performance.
  • Keywords
    Internet telephony; data structures; signalling protocols; statistical distributions; telecommunication security; telecommunication traffic; 3D sketch design; Hellinger distance detection technique; SIP flooding attack detection; SIP flooding attack prevention; SIP messages; VoIP system; constant-size data set; detection threshold protection; dynamic background traffic; estimation freeze mechanism; probability distribution evolution; session initiation protocol; sketch data structure; voice over IP networks; Estimation; High definition video; Monitoring; Probability distribution; Protocols; Servers; Training;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM, 2012 Proceedings IEEE
  • Conference_Location
    Orlando, FL
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4673-0773-4
  • Type

    conf

  • DOI
    10.1109/INFCOM.2012.6195475
  • Filename
    6195475