DocumentCode
2519494
Title
Detecting Anomaly Traffic using Flow Data in the real VoIP network
Author
Son, Hyeongu ; Lee, Youngseok
Author_Institution
Dept. of Comput. Eng., Chungnam Nat. Univ., Daejeon, South Korea
fYear
2010
fDate
19-23 July 2010
Firstpage
253
Lastpage
256
Abstract
As wireless LANs as well as the high-speed broadband Internet service are widely deployed, the VoIP service has become popular. Generally, a lot of commercial VoIP services use SIP and RTP for signaling and voice transport protocols. Most commercial VoIP service providers employ only simple security functions such as basic authentication without packet encryption because of fast implementation and deployment. Therefore, the VoIP service is highly vulnerable to several threats and attacks, because secure protocols for carrying VoIP packets are not fully utilized. For instance, unencrypted SIP packets including authentication messages could be easily forged to be exploited for generating anomaly traffic by malicious users. In this paper, we propose a flow-based VoIP anomaly traffic detection method that could find three representative VoIP anomaly attacks of SIP CANCEL, BYE DoS and RTP flooding that could be easily exploited in the real VoIP network. Our scheme uses the IETF IPFIX standard for monitoring VoIP calls in flow units. From the experiments with the commercial SIP phones in the real VoIP network, we show that SIP CANCEL, BYE DoS and RTP flooding attacks are easily generated and that they could be detected effectively by our proposed method.
Keywords
Internet telephony; cryptographic protocols; signalling protocols; telecommunication security; telecommunication traffic; transport protocols; wireless LAN; BYE DoS; IETF IPFIX standard; RTP flooding; SIP CANCEL; VoIP network; anomaly traffic detection; message authentication; packet encryption; voice transport protocols; wireless LAN; Authentication; IEEE 802.11 Standards; Monitoring; Protocols; Wireless LAN; Wireless communication; IPFIX; SIP; VoIP; anomaly flow;
fLanguage
English
Publisher
ieee
Conference_Titel
Applications and the Internet (SAINT), 2010 10th IEEE/IPSJ International Symposium on
Conference_Location
Seoul
Print_ISBN
978-1-4244-7526-1
Electronic_ISBN
978-0-7695-4107-5
Type
conf
DOI
10.1109/SAINT.2010.108
Filename
5598131
Link To Document