首页> 外文会议>IEEE Network Operations and Management Symposium >CPU-based DoS Attacks Against SIP Servers
【24h】

CPU-based DoS Attacks Against SIP Servers

机译:基于CPU的DOS攻击SIP服务器

获取原文

摘要

A key component of VoIP networks is the SIP signaling infrastructure. The reliance of public SIP servers on the Internet has opened up this critical infrastructure to a range of attacks. In particular, Denial of Service (DoS) attacks pose a serious security threat to the quality, reliability and availability of VoIP operations. In this paper, we investigate the impact of DoS attacks on SIP infrastructure, using a popular open source SIP server as a test bed. We have identified four attack scenarios that can exploit vulnerabilities in existing SIP authentication protocols, and we demonstrate the practical impact of these attacks on the target server. In response to these vulnerabilities, we have proposed several countermeasures to defend against each attack scenario. Our experimental results show that the current SIP implementation is highly vulnerable to DoS attacks and countermeasures are needed to make these servers more resilient. More importantly, we prove that authentication alone is no defence against DoS attacks in this context, and can actually increase the vulnerability of target servers instead of solving the problem of DoS attacks.
机译:VoIP网络的一个关键组件是SIP信令基础架构。公共SIP服务器对互联网上的依赖已将此关键基础架构开辟了一系列攻击。特别是,拒绝服务(DOS)攻击对VoIP操作的质量,可靠性和可用性构成严重的安全威胁。在本文中,我们使用流行的开源SIP服务器作为测试床来调查DOS攻击对SIP基础设施的影响。我们已经确定了四种攻击方案,可以利用现有SIP身份验证协议中的漏洞,并且我们展示了这些攻击对目标服务器的实际影响。为应对这些漏洞,我们提出了若干对策来防御每个攻击情景。我们的实验结果表明,目前的SIP实施非常容易受到DOS攻击的影响,并且需要对策来使这些服务器更具弹性。更重要的是,我们证明了单独的身份验证在此上下文中,无法防范DOS攻击,实际上可以提高目标服务器的漏洞,而不是解决DOS攻击问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号