• DocumentCode
    2519494
  • Title

    Detecting Anomaly Traffic using Flow Data in the real VoIP network

  • Author

    Son, Hyeongu ; Lee, Youngseok

  • Author_Institution
    Dept. of Comput. Eng., Chungnam Nat. Univ., Daejeon, South Korea
  • fYear
    2010
  • fDate
    19-23 July 2010
  • Firstpage
    253
  • Lastpage
    256
  • Abstract
    As wireless LANs as well as the high-speed broadband Internet service are widely deployed, the VoIP service has become popular. Generally, a lot of commercial VoIP services use SIP and RTP for signaling and voice transport protocols. Most commercial VoIP service providers employ only simple security functions such as basic authentication without packet encryption because of fast implementation and deployment. Therefore, the VoIP service is highly vulnerable to several threats and attacks, because secure protocols for carrying VoIP packets are not fully utilized. For instance, unencrypted SIP packets including authentication messages could be easily forged to be exploited for generating anomaly traffic by malicious users. In this paper, we propose a flow-based VoIP anomaly traffic detection method that could find three representative VoIP anomaly attacks of SIP CANCEL, BYE DoS and RTP flooding that could be easily exploited in the real VoIP network. Our scheme uses the IETF IPFIX standard for monitoring VoIP calls in flow units. From the experiments with the commercial SIP phones in the real VoIP network, we show that SIP CANCEL, BYE DoS and RTP flooding attacks are easily generated and that they could be detected effectively by our proposed method.
  • Keywords
    Internet telephony; cryptographic protocols; signalling protocols; telecommunication security; telecommunication traffic; transport protocols; wireless LAN; BYE DoS; IETF IPFIX standard; RTP flooding; SIP CANCEL; VoIP network; anomaly traffic detection; message authentication; packet encryption; voice transport protocols; wireless LAN; Authentication; IEEE 802.11 Standards; Monitoring; Protocols; Wireless LAN; Wireless communication; IPFIX; SIP; VoIP; anomaly flow;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Applications and the Internet (SAINT), 2010 10th IEEE/IPSJ International Symposium on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-1-4244-7526-1
  • Electronic_ISBN
    978-0-7695-4107-5
  • Type

    conf

  • DOI
    10.1109/SAINT.2010.108
  • Filename
    5598131