• DocumentCode
    2845567
  • Title

    Artemisa: An open-source honeypot back-end to support security in VoIP domains

  • Author

    Carmo, Rodrigo Do ; Nassar, Mohamed ; Festor, Olivier

  • Author_Institution
    Blas Pascal Univ., Cordoba, Argentina
  • fYear
    2011
  • fDate
    23-27 May 2011
  • Firstpage
    361
  • Lastpage
    368
  • Abstract
    Voice over IP (VoIP) and the Session Initiation Protocol (SIP) are establishing themselves as strong players in the field of multimedia communications over IP, leveraged by low cost services and easy management. Nevertheless, the security aspects are not yet fully mastered. In this paper we present an open-source implementation of a VoIP SIP-specific honeypot named Artemisa. The honeypot is designed to connect to a VoIP enterprise domain as a back-end user-agent in order to detect malicious activity at an early stage. Moreover, the honeypot can play a role in the real-time adjustment of the security policies of the enterprise domain where it is deployed. We aim, by this contribution, to encourage the deployment of such honeypots at large scale and the collection of attack traces. We test the capacity of the honeypot to handle a series of known SIP attacks and present results from diverse scenarios.
  • Keywords
    Internet telephony; computer network security; public domain software; signalling protocols; Artemisa; VoIP domain security; Voice over IP; enterprise domain; open source honeypot back end; session initiation protocol; Computer crime; Context; Fingerprint recognition; Floods; IP networks; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Integrated Network Management (IM), 2011 IFIP/IEEE International Symposium on
  • Conference_Location
    Dublin
  • Print_ISBN
    978-1-4244-9219-0
  • Electronic_ISBN
    978-1-4244-9220-6
  • Type

    conf

  • DOI
    10.1109/INM.2011.5990712
  • Filename
    5990712