DocumentCode :
2658515
Title :
Intrusion Detection System for IP Multimedia Subsystem using K-Nearest Neighbor classifier
Author :
Farooqi, Ashfaq Hussain ; Munir, Ali
Author_Institution :
Dept. of Comput. Sci., Nat. Univ. of Comput. & Emerging Sci., Islamabad
fYear :
2008
fDate :
23-24 Dec. 2008
Firstpage :
423
Lastpage :
428
Abstract :
IP multimedia subsystem (IMS) is a new next generation networking architecture that will provide better quality of service, charging infrastructure and security. The basic idea behind IMS is convergence; providing a single interface to different traditional or modern networking architectures allowing better working environment for the end users. IMS is still not commercially adopted and used but research is in progress to explore it. IMS is an IP based overlay next generation network architecture. It inherent number of security threats of session initiation protocol (SIP), TCP, UDP etc as it uses SIP and IP protocols. Some of them can degrade the performance of IMS seriously and may cause DoS or DDoS attacks. The paper presents a new approach keeping a vision of secure IMS based on intrusion detection system (IDS) using k-nearest neighbor (KNN) as classifier. The KNN classifier can effectively detect intrusive attacks and achieve a low false positive rate. It can distinguish between the normal behavior of the system or abnormal. In this paper, we have focused on the key element of IMS core known as proxy call session control function (PCSCF). Network based anomaly detection mechanism is proposed using KNN as anomaly detector. Experiments are performed on OpenIMS core and the result shows that IMS is vulnerable to different types of attacks such as UDP flooding, IP spoofing that can cause DoS. KNN classifier effectively distinguishes the behavior of the system as normal or intrusive and achieve low false positive rate.
Keywords :
3G mobile communication; IP networks; multimedia communication; pattern classification; quality of service; security of data; transport protocols; 3GPP; IP multimedia subsystem; IP protocols; IP spoofing; OpenIMS core; TCP; UDP flooding; intrusion detection system; k-nearest neighbor classifier; overlay next generation network architecture; proxy call session control function; quality of service; session initiation protocol; Computer crime; Convergence; Degradation; Detectors; Intrusion detection; Multimedia systems; Next generation networking; Protocols; Quality of service; TCPIP; 3GPP; DoS; IDS; IMS; KNN; PCSCF;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Multitopic Conference, 2008. INMIC 2008. IEEE International
Conference_Location :
Karachi
Print_ISBN :
978-1-4244-2823-6
Electronic_ISBN :
978-1-4244-2824-3
Type :
conf
DOI :
10.1109/INMIC.2008.4777775
Filename :
4777775
Link To Document :
بازگشت