DocumentCode
2522288
Title
Exploiting SIP for botnet communication
Author
Berger, Andreas ; Hefeeda, Mohamed
Author_Institution
ftw. Telecommun. Res. Center Vienna, Vienna, Austria
fYear
2009
fDate
13-13 Oct. 2009
Firstpage
31
Lastpage
36
Abstract
The Session Initiation Protocol (SIP) implements methods for generic service discovery and versatile messaging. It is, therefore, expected to be a key component in many telecommunication and Internet services. For example, the 3GPP IP Multimedia Subsystem relies heavily on SIP. Given its critical role, ensuring the security of SIP is clearly a crucial task. In this paper, we analyze the SIP protocol and show that it can easily be exploited to mount effective and large-scale botnets. We do this by scrutinizing the details of the SIP protocol and show how it offers a variety of ways to conceal botnet traffic within legitimate-looking SIP traffic. Using our analysis, we implement a SIP bot and present experimental results from a real testbed network. In addition, we employ traffic statistics collected from a large telecommunication provider and discuss the implications for both botnet design and detection. Finally, we present a software tool (called autosip) to generate synthetic traffic that resembles actual SIP traffic with different controllable characteristics. The proposed tool is quite useful for researchers working in the area who may not have access to traffic dumps from actual telecommunication providers.
Keywords
Internet; invasive software; signalling protocols; telecommunication security; telecommunication traffic; 3GPP IP multimedia subsystem; Internet service; SIP intrusion detection system; SIP protocol security; botnet communication; botnet traffic detection; experimental result; generic service discovery; legitimate-looking SIP traffic; malicious software control; session initiation protocol; software tool; telecommunication provider; traffic statistics; versatile message; Character generation; Communication system traffic control; Large-scale systems; Protocols; Security; Software tools; Statistics; Telecommunication traffic; Testing; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Secure Network Protocols, 2009. NPSec 2009. 5th IEEE Workshop on
Conference_Location
Princeton, NJ
Print_ISBN
978-1-4244-4866-1
Electronic_ISBN
978-1-4244-4865-4
Type
conf
DOI
10.1109/NPSEC.2009.5342244
Filename
5342244
Link To Document