Title :
SIP intrusion detection and prevention: recommendations and prototype implementation
Author :
Niccolini, S. ; Garroppo, R.G. ; Giordano, S. ; Risi, G. ; Ventura, S.
Author_Institution :
NEC Europe Ltd., Heidelberg, Germany
Abstract :
As VoIP deployment are expected to grow, intrusion problems similar to those of which data networks experience will become very critical. In the early stages of deployment, the intrusion and security problems have not been seriously considered, although they could have a negative impact on VoIP deployment. In the paper, SIP intrusion detection and prevention requirements are analyzed and an IDS/IPS architecture is proposed. A prototype of the proposed architecture was implemented using as a basis the very popular open-source software Snort, a network-based intrusion detection and prevention system. The prototype of the proposed architecture extends the basic functionality of Snort, making use of the preprocessing feature that permits analyzing protocols of layers above the TCP/UDP one. The preprocessors block is a very powerful one since it permits to implement both knowledge and behavior based intrusion detection and prevention techniques in Snort that basically adopts a network based technique. An important requirement of an IPS is that legitimate traffic should be forwarded to the recipient with no apparent disruption or delay of service. Hence, the performance of the proposed architecture has been evaluated in terms of impact that its operation has on the QoS experienced by the VoIP users.
Keywords :
Internet telephony; public domain software; quality of service; security of data; transport protocols; IDS-IPS architecture; QoS; SIP intrusion detection; TCP; UDP; VoIP deployment; data network; network-based intrusion detection; open-source software Snort; prevention technique; protocol analysis; quality of service; session initiation protocol; transmission control protocol; user datagram protocol; Communication system security; Computer architecture; Data security; Delay; Internet telephony; Intrusion detection; Protocols; Prototypes; Quality of service; Switches;
Conference_Titel :
VoIP Management and Security, 2006. 1st IEEE Workshop on
Print_ISBN :
1-4244-0144-5
DOI :
10.1109/VOIPMS.2006.1638122