VoIP Intrusion Detection System with Snort

Pavol Ciz, Ondrej Lábaj, Pavol Podhradský, Juraj Londák · Proceedings ELMAR-2012 · 2012

In this paper we introduce some attack types, which can be led against VoIP traffic and we present protection forms against them. We have performed an experiment on the proposed protection model, which was focused on signaling DoS attack with aim to cause malfunction of the software exchange Asterisk. For attack we have used software tool SIPp as messages generator to flood the exchange with a huge amount of INVITE messages. Software tool Snort, used as IDS system, logged an alert in case of the running attack to notify administrator of malicious activity. Subsequently the administrator has to analyze logged event.

Read the paper · More papers on PaperTik