Title of article :
Detecting Denial of Service Message Flooding Attacks in SIP based Services
Author/Authors :
Asgharian، Zoha نويسنده Computer Engineering Department , , Asgharian، Haasan نويسنده Computer Engineering Department , , Akbari، Ahmad نويسنده , , Raahemi ، Bijan نويسنده University of Ottawa ,
Issue Information :
دوفصلنامه با شماره پیاپی 0 سال 2012
Abstract :
Increasing the popularity of SIP based services (VoIP, IPTV, IMS infrastructure) lead to concerns about its security. The main signaling protocol of next generation networks and VoIP systems is Session Initiation Protocol (SIP). Inherent vulnerabilities of SIP, misconfiguration of its related components and also its implementation deficiencies cause some security concerns in SIP based infrastructures. New attacks are developed that target directly the underlying SIP protocol in these related SIP setups. To detect such kinds of attacks we combined anomaly-based and specification-based intrusion detection techniques. We took advantages of the SIP state machine concept (according to RFC 3261) in our proposed solution. We also built and configured a real test-bed for SIP based services to generate normal and assumed attack traffics. We validated and evaluated our intrusion detection system with the dump traffic of this real test-bed and we also used another specific available dataset to have a more comprehensive evaluation. The experimental results show that our approach is effective in classifying normal and anomaly traffic in different situations. The Receiver Operating Characteristic (ROC) analysis is applied on final extracted results to select the working point of our system (set related thresholds).
Journal title :
Amirkabir International Journal of Electrical and Electronics Engineering
Journal title :
Amirkabir International Journal of Electrical and Electronics Engineering