首页> 外文期刊>International journal of communication systems >Anomaly‐based DoS detection and prevention in SIP networks by modeling SIP normal traffic
【24h】

Anomaly‐based DoS detection and prevention in SIP networks by modeling SIP normal traffic

机译:通过对SIP正常流量建模来实现SIP网络中基于异常的DoS检测和预防

获取原文
获取原文并翻译 | 示例
       

摘要

Due to the various features of Voice over Internet Protocol (VoIP), this technology has attracted the attention of many users in comparison with the traditional telephony system. However, with the growth of this technology, the security issues and protection of its users against different kinds of threats have been raised as an essential requirement. Session Initiation Protocol is a predominant protocol to initiate and terminate multimedia sessions in VoIP networks that provide simplicity and text-based features. Despite its mentioned advantages, these features impose several vulnerabilities on VoIP networks. Denial of Service attack, as one of the most common attacks against VoIP networks, is also a noted security issue in the Internet Protocol platforms. In such attacks, the attacker tries to prevent service from authorized users by consuming server resources. These attacks can be launched by sending out-of-sequence messages, malformed messages, and flooding different kinds of messages. In this study, a new anomaly-based method is presented for detection and prevention of these attacks. Normal traffic of a VoIP network is modeled by making a finite state machine, which is used for attack detection besides other proposed modules. Furthermore, a whitelist method is implemented using Bloom data structure for attack prevention. The proposed method is completely implemented and tested using different test scenarios. The obtained results show that by using proposed method, attacks can be detected more accurately with lower false ratios and delay in comparison with the existing methods.
机译:由于互联网协议语音(VoIP)的各种功能,与传统电话系统相比,该技术吸引了许多用户的注意力。但是,随着该技术的发展,作为基本要求,已经提出了安全性问题及其针对各种威胁的用户保护。会话发起协议是用于在VoIP网络中发起和终止多媒体会话的主要协议,该协议提供了简单性和基于文本的功能。尽管提到了这些优点,但这些功能在VoIP网络上强加了多个漏洞。拒绝服务攻击是针对VoIP网络的最常见攻击之一,也是Internet协议平台中一个值得注意的安全问题。在此类攻击中,攻击者试图通过消耗服务器资源来阻止来自授权用户的服务。可以通过发送乱序消息,格式错误的消息以及泛洪各种消息来发起这些攻击。在这项研究中,提出了一种新的基于异常的方法来检测和预防这些攻击。 VoIP网络的正常流量是通过制作有限状态机来建模的,除了其他提议的模块外,该状态机还用于攻击检测。此外,使用Bloom数据结构实现了白名单方法以防止攻击。所提出的方法已完全实现并使用不同的测试方案进行了测试。所得结果表明,与现有方法相比,所提出的方法能够以较低的误报率和延迟来更准确地检测攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号