Procuring the Anomaly Packets and Accountability Detection in the Network
Vimal P. Laxman · IOSR Journal of Computer Engineering · 2013
It is software that will be used to find the anomaly packets in Voice over Internet Protocol (VoIP) devices, such as soft phones and VoIP gateways to the Session Initiation Protocol specifications, and to test the compliance and interoperability of VoIP equipment produced by different manufacturers.Network traffic is often "different" from benign traffic in ways that can be distinguished without knowing the nature of the attack.We describe a two stage anomaly detection system for identifying suspicious traffic.First, we filter traffic to pass only the packets of most interest, e.g. the first few packets of incoming server requests.Second, we model the most common protocols (IP, TCP, telnet, FTP, SMTP, HTTP) at the packet byte level to flag events (byte values) that have not been observed for a long time.Different software's are available on the market to conduct a compliance and interoperability validation phase.However, they often have features limited to packet capturing and decoding, or they are simulation tools that often require a complex developing phase to define the behavior of each test.The proposed tool, instead, can be inserted into an Session Initiation Protocol (SIP) network and is capable of observing and finding, in an automatic way.It executes in three phases.1. SIP messages flowing in the network are captured.2. In charge of grouping SIP messages into transactions and dialog.3. Operates by comparing the message flow with a set of predefined rules.These Rules are classified into two groups.1. Static Rules have been obtained by the direct analysis of SIP specifications.2. Dynamic Rules have been obtained by experience with SIP compliance and interoperability testing.If some rules failed during verification, an output is reported by indicating the rule that failed and a list of possible fault causes.