Stateful Virtual Proxy for SIP Message Flooding Attack Detection

被引:2
作者
Yun, Ha-Na [1 ]
Hong, Sung-Chan [2 ]
Lee, Hyung-Woo [1 ]
机构
[1] Hanshin Univ, Sch Comp Engn, Osan, Gyyunggi, South Korea
[2] Hanshin Univ, Div Informat & Telecommun, Osan, Gyyunggi, South Korea
来源
KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS | 2009年 / 3卷 / 03期
关键词
SIP; SIP message flooding attack; attack detection; SIP state diagram; VoIP;
D O I
10.3837/tiis.2009.03.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
VoIP service is the transmission of voice data using SIP protocol on an IP-based network. The SIP protocol has many advantages, such as providing IP-based voice communication and multimedia service with low communication cost. Therefore, the SIP protocol disseminated quickly. However, SIP protocol exposes new forms of vulnerabilities to malicious attacks, such as message flooding attack. It also incurs threats from many existing vulnerabilities as occurs for IP-based protocol. In this paper, we propose a new virtual proxy to cooperate with the existing Proxy Server to provide state monitoring and detect SIP message flooding attack with IP/MAC authentication. Based on a proposed virtual proxy, the proposed system enhances SIP attack detection performance with minimal latency of SIP packet transmission.
引用
收藏
页码:251 / 265
页数:15
相关论文
共 16 条
[1]  
[Anonymous], 2008, TRANSPORT LAYER SECU
[2]  
[Anonymous], 2617 IETF RFC
[3]  
Chang CC, 2005, LECT NOTES COMPUT SC, V3391, P669
[4]  
DUSSE S, 1999, 2633 IETF RFC
[5]  
Endler David., 2007, Hacking Exposed VoIP
[6]  
FERNANDEZ E, 2005, P NORD PATT LANG PRO
[7]  
MEHTA PC, 2001, MSCIS0131 U PENNS
[8]  
NICCOLINI S, 2007, VOIP SECURI IN PRESS
[9]  
Ormazabal G, 2008, LECT NOTES COMPUT SC, V5310, P107
[10]  
Rosenberg J, 2002, 3261 IETF RFC