DocumentCode :
2075689
Title :
Improved detection and correlation of multi-stage VoIP attack patterns by using a Dynamic Honeynet System
Author :
Hoffstadt, Dirk ; Wolff, Niels ; Monhof, Stefan ; Rathgeb, Erwin
Author_Institution :
Comput. Networking Technol. Group, Univ. of Duisburg-Essen, Essen, Germany
fYear :
2013
fDate :
9-13 June 2013
Firstpage :
1968
Lastpage :
1973
Abstract :
Security issues like service misuse and fraud are well-known problems of SIP-based networks. To develop effective countermeasures, it is important to know how these attacks are launched in reality. For gathering the required data, a specialized SIP Honeynet System has been running since January 2009 and has recorded over 58 million SIP messages. The analyses have shown that SIP-based misuse is typically performed as a multistage attack and the IP address of the attacker changes before the actual Toll Fraud calls. To be able to correlate all attack stages despite intermediate changes of the attacker´s IP address we developed the new Dynamic Honeynet System (DHS), which reacts according to the attackers´ behaviour and uses a dynamic Honeypot configuration in real-time to significantly improve the detection efficiency. We present the architecture and new features such as dynamic reconfiguration and demonstrate its attack correlation capabilities. We developed a Sensor component to realize this system. The Sensor provides active monitoring based on signatures to detect attacks in real-time and controls the dynamic Honeypot.
Keywords :
Internet telephony; computer network security; fraud; signalling protocols; DHS; IP address; SIP honeynet system; SIP messages; SIP-based misuse; SIP-based networks; active monitoring; attack correlation; attackers behaviour; dynamic honeynet system; dynamic honeypot configuration; dynamic reconfiguration; multistage VoIP attack patterns; sensor component; session initiation protocol; toll fraud calls; Authentication; Correlation; IP networks; Monitoring; Real-time systems; Registers; Servers; SIP; VoIP; attacks; fraud; honeynet; misuse; security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications (ICC), 2013 IEEE International Conference on
Conference_Location :
Budapest
ISSN :
1550-3607
Type :
conf
DOI :
10.1109/ICC.2013.6654812
Filename :
6654812
Link To Document :
بازگشت