Detecting Denial of Service Message Flooding Attacks in SIP based Services

Zoha Asgharian, Hassan Asgharian, Ahmad Akbari, Bijan Raahemi · 2012

Increasing the popularity of SIP based services (VoIP, IPTV, IMS infrastructure) lead to concerns about its ‎The main signaling protocol of next generation networks and VoIP systems is Session Initiation Protocol ‎‎Inherent vulnerabilities of SIP, misconfiguration of its related components and also its implementation ‎cause some security concerns in SIP based infrastructures. New attacks are developed that target ‎the underlying SIP protocol in these related SIP setups. To detect such kinds of attacks we combined ‎-based and specification-based intrusion detection techniques. We took advantages of the SIP state machine ‎(according to RFC 3261) in our proposed solution. We also built and configured a real test-bed for SIP ‎services to generate normal and assumed attack traffics. We validated and evaluated our intrusion detection ‎with the dump traffic of this real test-bed and we also used another specific available dataset to have a more ‎evaluation. The experimental results show that our approach is effective in classifying normal and ‎traffic in different situations. The Receiver Operating Characteristic (ROC) analysis is applied on final ‎results to select the working point of our system (set related thresholds). ‎

Read the paper · More papers on PaperTik