Title :
Fast Detection of Denial-of-Service Attacks on IP Telephony
Author :
Sengar, Hemant ; Wang, Haining ; Wijesekera, Duminda ; Jajodia, Sushil
Author_Institution :
Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA
Abstract :
Recently voice over IP (VoIP) is experiencing a phenomenal growth. Being a real-time service, VoIP is more susceptible to denial-of-service (DoS) attacks than regular Internet services. Moreover, VoIP uses multiple protocols for call control and data delivery, making it vulnerable to various DoS attacks at different protocol layers. An attacker can easily disrupt VoIP services by flooding TCP SYN packets, UDP-based RTP packets, or SIP-based INVITE messages, which pose a critical threat to IP telephony. In this paper, we present an online statistical detection mechanism, called vFDS, to detect DoS attacks in the context of VoIP. The core of vFDS is based on Hellinger distance method, which computes the variability between two probability measures. Using Hellinger distance, we characterize normal protocol behaviors and then detect the traffic anomalies caused by flooding attacks. Our experimental results show that vFDS achieves fast and accurate detection of DoS attacks
Keywords :
Internet telephony; probability; real-time systems; security of data; telecommunication congestion control; telecommunication security; telecommunication traffic; transport protocols; Hellinger distance; SIP-based INVITE message; TCP SYN packet; UDP-based RTP packet; VOIP; call control; denial-of-service attack; multiple protocol; online statistical detection mechanism; probability measure; real-time service; traffic anomaly; vFDS; voice over IP; Computer crime; Computer science; Educational institutions; Floods; Information systems; Internet telephony; Quality of service; TCPIP; Transport protocols; Web and internet services;
Conference_Titel :
Quality of Service, 2006. IWQoS 2006. 14th IEEE International Workshop on
Conference_Location :
New Haven, CT
Print_ISBN :
1-4244-0476-2
Electronic_ISBN :
1548-615X
DOI :
10.1109/IWQOS.2006.250469