SIP Protector: Defense Architecture Mitigating DDoS Flood Attacks Against SIP servers

被引:0
|
作者
Stanek, Jan [1 ]
Kencl, Lukas [1 ]
机构
[1] Czech Tech Univ, Res & Dev Ctr Mobile Applicat RDC, Prague 16627 6, Czech Republic
来源
2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC) | 2012年
关键词
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
As Voice-over-IP becomes a commonly used technology, the need to keep it secure and reliable has grown. Session Initiation Protocol (SIP) is most often used to deploy VoIP and therefore SIP servers, the base components of SIP, are the most obvious targets of potential attacks. It has been demonstrated, that SIP servers are highly prone to DDoS flood attacks, yet no generally accepted defense solution mitigating these attacks is available. We propose a novel defense architecture against SIP DDoS floods, based upon a redirection mechanism and a combination of source and destination traffic filtering, exploiting the combined advantage of all the three techniques. We show that the proposed solution effectively mitigates various types of SIP DDoS flood attacks, discuss its strengths and weaknesses and propose its potential usability for other protocols. We also provide results of performance evaluation of the defense solution deployed in a SIP testbed.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] CPU-based DoS attacks against SIP servers
    Luo, Ming
    Peng, Tao
    Leckie, Christopher
    2008 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, VOLS 1 AND 2, 2008, : 41 - 48
  • [2] An intelligent cyber security system against DDoS attacks in SIP networks
    Semerci, Murat
    Cemgil, Ali Taylan
    Sankur, Bulent
    COMPUTER NETWORKS, 2018, 136 : 137 - 154
  • [3] An Approach to Resisting Malformed and Flooding Attacks on SIP Servers
    Su, Ming-Yang
    Tsai, Chen-Han
    JOURNAL OF NETWORKS, 2015, 10 (02) : 77 - 84
  • [4] Distributed SIP DDoS Defense with P4
    Febro, Aldo
    Xiao, Hannan
    Spring, Joseph
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [5] SOS: An architecture for mitigating DDoS attacks
    Keromytis, AD
    Misra, V
    Rubenstein, D
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2004, 22 (01) : 176 - 188
  • [6] Leveraging the SIP Load balancer to detect and mitigate DDos attacks
    Akbar, Abdullah
    Basha, S. Mahaboob
    Sattar, Syed Abdul
    2015 INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND INTERNET OF THINGS (ICGCIOT), 2015, : 1204 - 1208
  • [7] Study on Auto Detecting Defence Mechanisms against Application Layer Ddos Attacks in SIP Server
    Alam, Muhammad Morshed
    Arafat, Muhammad Yeasir
    Ahmed, Feroz
    JOURNAL OF NETWORKS, 2015, 10 (06) : 344 - 352
  • [8] Collaborative Defense Method Against DDoS Attacks on SDN-Architected Cloud Servers
    Zhang, Yiying
    Xu, Yao
    Han, Longzhe
    Liang, Kun
    Li, Wenjing
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IV, ICIC 2024, 2024, 14865 : 362 - 370
  • [9] Survey of Countering DoS/DDoS Attacks on SIP Based VoIP Networks
    Nazih, Waleed
    Elkilani, Wail S.
    Dhahri, Habib
    Abdelkader, Tamer
    ELECTRONICS, 2020, 9 (11) : 1 - 21
  • [10] IoT standard platform architecture that provides defense against DDoS attacks
    Lee, Yun-kyung
    Kim, Young-ho
    Kim, Jeong-nyeo
    2021 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS-ASIA (ICCE-ASIA), 2021,