VoIPFD: Voice over IP flooding detection

Diksha Golait, Neminath Hubballi · 2016 Twenty Second National Conference on Communication (NCC) · 2016

Session Initiation Protocol (SIP) is a popularly used signaling protocol to manage connections between different user agents of a Voice over IP (VoIP) communication. SIP being a text based protocol is vulnerable to flooding, one of the popularly known Denial of Service (DoS) attacks. This attack can render VoIP servers unusable with depletion of CPU and memory resources. Given the accessibility of tools to generate these attacks and the ease with which these attacks can be launched, it is important to detect them. In this paper, we describe VoIPFD, an anomaly detector for detecting VoIP flooding attacks on SIP. Like any other anomaly detector, VoIPFD generates the normal profile of SIP messages as a probability distribution. We identify and generate Poisson distribution models for few SIP messages in order to detect specific flooding attacks. We simulate an enterprise VoIP communication and experiment with varied rates of flooding and report the detection performance of VoIPFD.

Read the paper · More papers on PaperTik