首页> 外文会议>2010 IEEE Global Telecommunications Conference >Detection of Resource-Drained Attacks on SIP-Based Wireless VoIP Networks
【24h】

Detection of Resource-Drained Attacks on SIP-Based Wireless VoIP Networks

机译:基于SIP的无线VoIP网络上资源消耗攻击的检测

获取原文

摘要

The Session Initiation Protocol (SIP) has been widely used in VoIP for session control and management. As the basic SIP specifications do not require the proxy servers to track the states of established sessions, an extension header field "Session-Expires" has been proposed for SIP to allow the proxy server to hold resources for established sessions just within the specified periods. In this paper, we identify a novel denial of service (DoS) attack utilizing this SIP extension to drain resources of the proxy servers in wireless VoIP. In particular, by deliberately setting a large value of the "Session-Expires'' header and then physically disconnecting from the wireless network, attackers can repeatedly hold resources of the proxy server as long as they want. Also, the low-volume nature of the attack allows it to avoid being detected by existing volume-based intrusion detection systems. As a counter-measure, we propose a robust detection scheme based on the statistical Anderson-Darling test. The key insight that leads to the scheme is the changed statistical property of the header values induced by the attack. We validate the performance through computer simulation. The scheme shows its ability to detect the attack and is even more effective when applied against the distributed denial of service (DDoS) attack.
机译:会话发起协议(SIP)已在VoIP中广泛用于会话控制和管理。由于基本SIP规范不需要代理服务器跟踪已建立会话的状态,因此已为SIP提出了扩展头字段“ Session-Expires”,以允许代理服务器仅在指定时间段内保留已建立会话的资源。在本文中,我们确定了一种新颖的拒绝服务(DoS)攻击,利用此SIP扩展来耗尽无线VoIP中的代理服务器资源。特别是,通过有意地设置“ Session-Expires”标头的较大值,然后从物理上断开与无线网络的连接,攻击者可以根据需要反复重复持有代理服务器的资源。作为对策,我们提出了一种基于统计Anderson-Darling检验的健壮的检测方案,这是导致该方案的关键见解,是对统计信息的更改。攻击引起的标头值的属性,我们通过计算机仿真验证了性能,该方案显示了其检测攻击的能力,并且在应对分布式拒绝服务(DDoS)攻击时更加有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号