Nothing Special   »   [go: up one dir, main page]

skip to main content
10.1145/1655925.1656137acmotherconferencesArticle/Chapter ViewAbstractPublication PagesicisConference Proceedingsconference-collections
research-article

Design and implementation of SIP-aware DDoS attack detection system

Published: 24 November 2009 Publication History

Abstract

SIP is a signaling protocol used for establishing, modifying, terminating sessions in multimedia services such as VoIP, instant messaging, and video conferencing. Existing IP network security solutions can not detect new SIP specified network threats because they can not reflect characteristics of SIP. In this paper, we propose SIP-aware DDoS Attack Detection System that can monitor SIP signaling flow and detect SIP-aware DDoS attack. The proposed system collects attributes of SIP traffic, and executes anlaysing and detecting based on statistic and behavior.

References

[1]
J. Rosenberg, H. Schulzrinne, G. Camarillo, A. Johnston, J. Peterson, R. Sparks, M. Handley and E. Schooler, "SIP: Session Initiation Protocol", RFC 3261, June 2002.
[2]
H. Schulzrinne, S. Casner, R. Frederick and V. Jacobsonm, "RTP: A Transport Protocol for Real-Time Applications", RFC 1889, January, 1996
[3]
D. Geneiatakis, G. Kambourakis, T. Dagiuklas, C. Lambrinoudakis and S. Gritzalis, "A Framework for Detecting Malformed Messages in SIP Networks", the 14th IEEE Workshop on Local and Metropolitan Area Networks LANMAN), Greece, September 2005
[4]
Y. Wu, S. Bagchi, S. Garg, N. Singh and T. Tsai, SCIDIVE: A Stateful and Cross Protocol Intrusion Detection Architecture for Voice-over-IP Environments", 2004 International Conference on Dependable Systems and Networks (DSN'04), Florence, Italy, 2004
[5]
H. Kang, Z. Zhang, S. Ranjan and A. Nucci, "SIP-based VoIP Traffic Behavior Profiling and its Application", MineNet'07, San Diego, USA, June 2007.

Cited By

View all
  • (2012)SIP Protector: Defense architecture mitigating DDoS flood attacks against SIP servers2012 IEEE International Conference on Communications (ICC)10.1109/ICC.2012.6364674(6733-6738)Online publication date: Jun-2012
  • (2011)SIPp-DD: SIP DDoS Flood-Attack Simulation Tool2011 Proceedings of 20th International Conference on Computer Communications and Networks (ICCCN)10.1109/ICCCN.2011.6005946(1-7)Online publication date: Jul-2011

Index Terms

  1. Design and implementation of SIP-aware DDoS attack detection system

      Recommendations

      Comments

      Please enable JavaScript to view thecomments powered by Disqus.

      Information & Contributors

      Information

      Published In

      cover image ACM Other conferences
      ICIS '09: Proceedings of the 2nd International Conference on Interaction Sciences: Information Technology, Culture and Human
      November 2009
      1479 pages
      ISBN:9781605587103
      DOI:10.1145/1655925
      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      Sponsors

      • AICIT
      • ETRI
      • KISTI

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      Published: 24 November 2009

      Permissions

      Request permissions for this article.

      Check for updates

      Author Tags

      1. DDoS
      2. IP telephony security
      3. session initiation protocol

      Qualifiers

      • Research-article

      Conference

      ICIS '09
      Sponsor:

      Contributors

      Other Metrics

      Bibliometrics & Citations

      Bibliometrics

      Article Metrics

      • Downloads (Last 12 months)7
      • Downloads (Last 6 weeks)1
      Reflects downloads up to 24 Nov 2024

      Other Metrics

      Citations

      Cited By

      View all
      • (2012)SIP Protector: Defense architecture mitigating DDoS flood attacks against SIP servers2012 IEEE International Conference on Communications (ICC)10.1109/ICC.2012.6364674(6733-6738)Online publication date: Jun-2012
      • (2011)SIPp-DD: SIP DDoS Flood-Attack Simulation Tool2011 Proceedings of 20th International Conference on Computer Communications and Networks (ICCCN)10.1109/ICCCN.2011.6005946(1-7)Online publication date: Jul-2011

      View Options

      Login options

      View options

      PDF

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader

      Media

      Figures

      Other

      Tables

      Share

      Share

      Share this Publication link

      Share on social media