Research on detecting SIP message flooding attacks

Qibo Sun, Shuang Qian · China-Ireland International Conference on Information and Communications Technologies (CIICT 2008) · 2008

As the session initial protocol (SIP) gains more and more acceptances in the VoIP market, DOS (Denial of Service) attacks that involve flooding SIP entities with invalid SIP messages, such as INVITE and REGISTER will become one of the most severe security threats against SIP systems. In this paper, we propose a scheme to protect the SIP systems from such flooding attack. Firstly, we analyse the principle of flooding attacks using SIP INVITE messages and extract the detection rules on a statistic base. Then we suggest a method to detect such flooding attack using the recursive non- parametric cumulative sum (CUSUM) algorithm. Finally, we give the result of simulation experiments.

Read the paper · More papers on PaperTik