• DocumentCode
    1704104
  • Title

    Evaluating DoS Attacks against Sip-Based VoIP Systems

  • Author

    Rafique, M. Zubair ; Akbar, M. Ali ; Farooq, Muddassar

  • Author_Institution
    Next Generation Intell. Networks Res. Center (nexGIN RC), FAST Nat. Univ. of Comput. & Emerging Sci. (NUCES), Islamabad, Pakistan
  • fYear
    2009
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    The multimedia communication is rapidly converging towards Voice over Internet - commonly known as Voice over Internet Protocol (VoIP). Session Initiation Protocol (SIP) is the standard used for session signaling in VoIP. Crafty attackers can launch a number of Denial of Service (DoS) attacks on a SIP based VoIP infrastructure that can severely compromise its reliability. In contrast, little work is done to analyze the robustness and reliability of SIP severs under DoS attacks. In this paper, we show that the robustness and reliability of generic SIP servers is inadequate than commonly perceived. We have done our study using a customized analysis tool that has the ability to synthesize and launch different types of attacks. We have integrated the tool in a real SIP test bed environment to measure the performance of SIP servers. Our measurements show that a standard SIP server can be easily overloaded by sending simple call requests. We define the performance metrics to measure the effects of flooding attacks on real time services - VoIP in SIP environment - and show the results on different SIP server implementations. Our results also provide insight into resources´ usage by SIP servers under flooding attacks. Moreover, we show that how a well known open source SIP server can be crashed through ´INVITE of Death´ - a malformed SIP packet maliciously crafted by our tool.
  • Keywords
    Internet telephony; multimedia communication; signalling protocols; telecommunication network reliability; DoS attacks; INVITE of Death; SIP-based VoIP systems; Voice over Internet Protocol; denial of service; malformed SIP packet; multimedia communication; reliability; session initiation protocol; Computer crime; Floods; Internet telephony; Measurement; Protection; Protocols; Robustness; Storage area networks; Testing; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Telecommunications Conference, 2009. GLOBECOM 2009. IEEE
  • Conference_Location
    Honolulu, HI
  • ISSN
    1930-529X
  • Print_ISBN
    978-1-4244-4148-8
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2009.5426247
  • Filename
    5426247