首页> 外文OA文献 >Security of VoIP : Analysis, Testing and Mitigation of SIP-based DDoS attacks on VoIP Networks
【2h】

Security of VoIP : Analysis, Testing and Mitigation of SIP-based DDoS attacks on VoIP Networks

机译:VoIP的安全性:VoIP网络上基于SIP的DDoS攻击的分析,测试和缓解

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Voice over IP (VoIP) is gaining more popularity in today‟s communications. The Session Initiation Protocol (SIP) is becoming one of the dominant VoIP signalling protocol[1, 2], however it is vulnerable to many kinds of attacks. Among these attacks, flood-based denial of service attacks have been identified as the major threat to SIP. Even though a great deal of research has been carried out to mitigate denial of service attacks, only a small proportion has been specific to SIP. This project examines the way denial of service attacks affect the performance of a SIP-based system and two evolutionary solutions to this problem that build on each other are proposed with experimental results to demonstrate the effectiveness of each solution. In stage one, this project proposes the Security-Enhanced SIP System (SESS), which contains a security-enhanced firewall, which evolved from the work of stage one and a security-enhanced SIP proxy server. This approach helps to improve the Quality-of-Service (QoS) of legitimate users during the SIP flooding attack, while maintaining a 100 percent success rate in blocking attack traffic. However, this system only mitigates SIP INVITE and REGISTER floods. In stage two, this project further advances SESS, and proposes an Improved Security-Enhanced SIP System (ISESS). ISESS advances the solution by blocking other SIP request floods, for example CANCEL, OK and BYE flood. JAIN Service Logic Execution Environment (JAIN SLEE) is a java-based application server specifically designed for event-driven applications. JAIN SLEE is used to implement enhancements of the SIP proxy server, as it is becoming a popular choice in implementing communication applications. The experimental results show that during a SIP flood, ISESS cannot only drop all attack packets but also the call setup delay of legitimate users can be improved substantially compared to and unsecured VoIP system.
机译:IP语音(VoIP)在当今的通信中越来越受欢迎。会话发起协议(SIP)成为主要的VoIP信令协议之一[1,2],但是它容易受到多种攻击。在这些攻击中,基于洪水的拒绝服务攻击已被确定为SIP的主要威胁。尽管已经进行了大量研究来减轻拒绝服务攻击,但只有一小部分专门针对SIP。该项目研究了拒绝服务攻击如何影响基于SIP的系统的性能,并针对此问题提出了两种相互进化的解决方案,并通过实验结果证明了每种解决方案的有效性。在第一阶段,该项目提出了一个安全增强型SIP系统(SESS),该系统包含一个安全增强型防火墙,该防火墙是从第一阶段的工作和一个安全性增强型SIP代理服务器发展而来的。这种方法有助于在SIP泛洪攻击期间提高合法用户的服务质量(QoS),同时在阻止攻击流量方面保持100%的成功率。但是,此系统仅减轻了SIP INVITE和REGISTER洪水。在第二阶段,该项目进一步推进了SESS,并提出了改进的安全性增强SIP系统(ISESS)。 ISESS通过阻止其他SIP请求洪泛(例如CANCEL,OK和BYE洪泛)来推进解决方案。 JAIN服务逻辑执行环境(JAIN SLEE)是基于Java的应用程序服务器,专门用于事件驱动的应用程序。 JAIN SLEE用于实现SIP代理服务器的增强功能,因为它已成为实现通信应用程序的一种流行选择。实验结果表明,与不安全的VoIP系统相比,在SIP泛洪期间,ISSESS不仅可以丢弃所有攻击数据包,而且可以大大改善合法用户的呼叫建立延迟。

著录项

  • 作者

    Deng Xianglin;

  • 作者单位
  • 年度 2008
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号