• DocumentCode
    2522288
  • Title

    Exploiting SIP for botnet communication

  • Author

    Berger, Andreas ; Hefeeda, Mohamed

  • Author_Institution
    ftw. Telecommun. Res. Center Vienna, Vienna, Austria
  • fYear
    2009
  • fDate
    13-13 Oct. 2009
  • Firstpage
    31
  • Lastpage
    36
  • Abstract
    The Session Initiation Protocol (SIP) implements methods for generic service discovery and versatile messaging. It is, therefore, expected to be a key component in many telecommunication and Internet services. For example, the 3GPP IP Multimedia Subsystem relies heavily on SIP. Given its critical role, ensuring the security of SIP is clearly a crucial task. In this paper, we analyze the SIP protocol and show that it can easily be exploited to mount effective and large-scale botnets. We do this by scrutinizing the details of the SIP protocol and show how it offers a variety of ways to conceal botnet traffic within legitimate-looking SIP traffic. Using our analysis, we implement a SIP bot and present experimental results from a real testbed network. In addition, we employ traffic statistics collected from a large telecommunication provider and discuss the implications for both botnet design and detection. Finally, we present a software tool (called autosip) to generate synthetic traffic that resembles actual SIP traffic with different controllable characteristics. The proposed tool is quite useful for researchers working in the area who may not have access to traffic dumps from actual telecommunication providers.
  • Keywords
    Internet; invasive software; signalling protocols; telecommunication security; telecommunication traffic; 3GPP IP multimedia subsystem; Internet service; SIP intrusion detection system; SIP protocol security; botnet communication; botnet traffic detection; experimental result; generic service discovery; legitimate-looking SIP traffic; malicious software control; session initiation protocol; software tool; telecommunication provider; traffic statistics; versatile message; Character generation; Communication system traffic control; Large-scale systems; Protocols; Security; Software tools; Statistics; Telecommunication traffic; Testing; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Secure Network Protocols, 2009. NPSec 2009. 5th IEEE Workshop on
  • Conference_Location
    Princeton, NJ
  • Print_ISBN
    978-1-4244-4866-1
  • Electronic_ISBN
    978-1-4244-4865-4
  • Type

    conf

  • DOI
    10.1109/NPSEC.2009.5342244
  • Filename
    5342244