Problems of SIP Flooding Attacks Anomaly Detection Algorithms
Housam Al-Allouni, Alaa Eldin Rohiem, Mohamed Hashem, Ali Elmoghazy · The International Conference on Electrical Engineering/The International Conference on Electrical Engineering · 2010
Session Initiation Protocol (SIP) is vulnerable to a wide variety of Denial of Service(DoS) attacks, flooding is the most common, effective and the easiest to generate one.In this paper we present an evaluation study to four well-known anomaly detectionalgorithms, namely: Adaptive Threshold, Cumulative sum (CUSUM), NonParametric Cumulative Sum (NP-CUSUM), and Hellinger Distance (HD). Theevaluation is assisted using simulated traffic dataset. We show that these algorithmssuffer from two main problems, the first is called attack masking and the second isadaptation with attack. In the attack masking, attacker sends preamble followed bythe attack. The preamble changes the tuned parameters of the detection algorithm,these changes mask the attack and keep it undetected. Attacker in the second problemdeviates the detection algorithm parameters gradually, in such a way the attack isconsidered as normal traffic. The paper also shows that NP-CUSUM and HDalgorithms, which utilize the protocol behavior to detect intrusion, suffer from thirdproblem, and they are very simple to con. Attacker simply follows the same protocolbehavior, and its related traffic is considered as normal, and cannot be detected.