...
首页> 外文期刊>Computers & Security >Protecting from Cloud-based SIP flooding attacks by leveraging temporal and structural fingerprints
【24h】

Protecting from Cloud-based SIP flooding attacks by leveraging temporal and structural fingerprints

机译:通过利用时间和结构指纹来防御基于云的SIP泛洪攻击

获取原文
获取原文并翻译 | 示例
           

摘要

The session initiation protocol (SIP) is among the most popular voice over IP (VoIP) signaling protocols. Like other Internet protocols, deployment in live scenarios showed its vulnerability to flooding attacks. These attacks are very similar to those against TCP protocol but have emerged at the application level of the Internet architecture. In this paper, we present a new approach to protect SIP devices from flooding attacks. Our proposed approach is mainly composed of two algorithms: 1) a detection algorithm that takes into consideration the temporal characteristics of SIP protocol as well as the fingerprints of its messages and 2) a mitigation algorithm that filters SIP messages based on a fingerprint whitelist database. We evaluate our approach through an extensive set of experimental tests using widely distributed virtual machines in the cloud and compare to similar approaches found in the literature. The experiments emulate a large flooding attack launched from mutually distant geographic data centers. The results report short detection time, low sensibility to false alarms and high effectiveness in reducing the computational resources.
机译:会话发起协议(SIP)是最流行的IP语音(VoIP)信令协议。像其他Internet协议一样,在实时场景中进行部署也显示出它容易遭受洪泛攻击。这些攻击与针对TCP协议的攻击非常相似,但已出现在Internet体系结构的应用程序级别。在本文中,我们提出了一种保护SIP设备免受洪泛攻击的新方法。我们提出的方法主要由两种算法组成:1)一种考虑SIP协议的时间特性及其消息指纹的检测算法,以及2)一种基于指纹白名单数据库过滤SIP消息的缓解算法。我们通过使用广泛分布的虚拟机在云中进行广泛的实验测试来评估我们的方法,并与文献中发现的类似方法进行比较。实验模拟了从相互远离的地理数据中心发动的大规模洪水攻击。结果表明检测时间短,对误报的敏感性低以及在减少计算资源方面具有很高的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号