首页> 外文期刊>Security and Communications Networks >A comprehensive study of flooding attack consequences and countermeasures in Session Initiation Protocol (SIP)
【24h】

A comprehensive study of flooding attack consequences and countermeasures in Session Initiation Protocol (SIP)

机译:会话发起协议(SIP)中的洪灾攻击后果和对策的综合研究

获取原文
获取原文并翻译 | 示例

摘要

Session Initiation Protocol (SIP) is widely used as a signaling protocol to support voice and video communication in addition to other multimedia applications. However, it is vulnerable to several types of attacks because of its open nature and lack of a clear defense line against the increasing spectrum of security threats. Among these threats, flooding attack, known by its destructive impact, targets both of SIP User Agent Server (UAS) and User Agent Client (UAC), leading to a denial of service in Voice over IP applications. In particular, INVITE message is considered as one of the major root causes of flooding attacks in SIP. This is due to the fact that an attacker may send numerous INVITE requests without waiting for responses from the UAS or the proxy in order to exhaust their respective resources. Most of the devised solutions to cope with the flooding attack are either difficult to deploy in practice or require significant changes in the SIP servers implementation. Apart from these challenges, flooding attacks are much more diverse in nature, which makes the task of defeating them a real challenge. In this survey, we present a comprehensive study of flooding attack against SIP, by addressing its different variants and analyzing its consequences. We also classify the existing solutions according to the different flooding behaviors they are dealing with, their types, and targets. Moreover, we conduct a thorough investigation of the main strengths and weaknesses of these solutions and deeply analyze the underlying assumptions of each of them for better understanding of their limitations. Finally, we provide some recommendations for enhancing the effectiveness of the surveyed solutions and address some open challenges. Copyright (C) 2015 John Wiley & Sons, Ltd.
机译:会话发起协议(SIP)除其他多媒体应用程序外,还广泛用作支持语音和视频通信的信令协议。但是,由于它的开放性和缺乏针对不断增加的安全威胁的明确防御线,因此它容易受到多种类型的攻击。在这些威胁中,泛洪攻击以SIP用户代理服务器(UAS)和用户代理客户端(UAC)为攻击目标,具有破坏性,众所周知,这导致IP语音应用程序中的服务被拒绝。特别是,INVITE消息被认为是SIP中洪泛攻击的主要原因之一。这是由于以下事实:攻击者可以发送大量INVITE请求,而无需等待来自UAS或代理的响应以耗尽其各自的资源。大多数为应对洪泛攻击而设计的解决方案要么在实践中难以部署,要么需要对SIP服务器实现进行重大更改。除了这些挑战之外,洪水攻击的性质也更加多样化,这使克服它们的任务成为真正的挑战。在此调查中,我们通过针对SIP的不同变体并分析其后果,提供了针对SIP的泛洪攻击的全面研究。我们还将根据现有解决方案要处理的不同洪泛行为,其类型和目标来对其进行分类。此外,我们对这些解决方案的主要优缺点进行了透彻的调查,并对每个解决方案的基本假设进行了深入分析,以更好地了解其局限性。最后,我们提供一些建议,以提高被调查解决方案的有效性,并解决一些公开挑战。版权所有(C)2015 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号