首页> 外文会议>IEEE International Conference on Communications Workshops >Quick Detection of Stealthy SIP Flooding Attacks in VoIP Networks
【24h】

Quick Detection of Stealthy SIP Flooding Attacks in VoIP Networks

机译:在VoIP网络中快速检测隐秘的SIP泛滥攻击

获取原文

摘要

Denial of Service (DoS) attacks such as the SIP flooding pose great threats to normal operations of VoIP networks, and can bear various forms to elude detection. In this paper, we address the stealthy SIP flooding attack, where intelligent attackers deliberately increase the flooding rates in a slow pace. As the attack only gradually influences the traffic, it can effectively be disguised from previous SIP flooding detection methods. In order to identify the stealthy attack in its early stage for timely response, we propose a detection scheme based on the signal processing technique wavelet, which is able to quickly expose the changes induced by the attack. In particular, we monitor the percentage of energy corresponding to the detail signal obtained from the wavelet analysis as an indication of the attack. Also, considering the scalability of the proposed scheme, we resort to the sketch technique, which can summarize the traffic observations to a fixed-size hash table to provide raw traffic signals for the wavelet analysis regardless of how many users exist in the VoIP network. We validate the performance of the proposed scheme through computer simulation and demonstrate its ability to quickly and accurately detect the attacks.
机译:拒绝服务(DOS)攻击,如SIP洪水对VoIP网络的正常操作构成了巨大的威胁,并且可以承担各种形式以避开检测。在本文中,我们解决了隐身的SIP洪水攻击,智能攻击者故意以缓慢的步伐提高洪水速率。由于攻击逐渐影响流量,因此可以有效地伪造以前的SIP泛滥检测方法。为了在其早期阶段确定隐身攻击及时响应,我们提出了一种基于信号处理技术小波的检测方案,能够快速暴露攻击引起的变化。特别地,我们监测与从小波分析获得的细节信号相对应的能量的百分比作为攻击的指示。此外,考虑到所提出的方案的可扩展性,我们采用了草图技术,可以将交通观测总结到固定尺寸的哈希表,为小波分析提供原始交通信号,无论VoIP网络中存在多少用户。我们通过计算机模拟验证所提出的方案的性能,并展示其快速准确地检测攻击的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号