首页> 外文期刊>International Journal of Information Security >An intrusion detection and prevention system for IMS and VoIP services
【24h】

An intrusion detection and prevention system for IMS and VoIP services

机译:用于IMS和VoIP服务的入侵检测和防御系统

获取原文
获取原文并翻译 | 示例
           

摘要

The Voice Over IP (VoIP) environments and the most contemporary ones such as the IP Multimedia Subsystem (IMS) are deployed in order to provide cheap and at the same time high quality services to their users. Video calls, conferences, and applications can be provided to mobile devices with the lowest possible delay, while the Quality of Service (QoS) remains as the top priority for users and providers. Toward this objective, these infrastructures utilize the Session Initiation Protocol (SIP) for signaling handshakes since it is the most flexible and lightweight protocol available. However, according to many researches, it happens to be vulnerable to many attacks that threaten system's security and availability. In this paper, we introduce a cross-layer mechanism that is able to mitigate in real-time spoofing attacks such as SIP signaling, identity theft, masquerading, and Man in the middle, and also single and distributed source flooding. It consists of three components: the policy enforcer which acts as a black list, and the spoofing and flooding modules. We also introduce a classification of SIP flooding attacks for better representation of the detection coverage. To the best of our knowledge, the proposed detection system is the most complete and accurate in terms of the attack range that is able to deter. Concerning its performance, it does not require computational expensive calculations nor resource demanding security protocols, thus being a lightweight mechanism. The experimental results have demonstrated high detection rates with false alarm rates approaching zero. Finally, it is platform independent and transparent to networks' operations and thus can be deployed in both VoIP and IMS environments.
机译:部署了IP语音(VoIP)环境和最新的IP多媒体子系统(IMS)等环境,以便为其用户提供廉价而高质量的服务。视频呼叫,会议和应用程序可以以最小的延迟提供给移动设备,而服务质量(QoS)仍然是用户和提供商的头等大事。为了实现这一目标,这些基础架构利用会话初始协议(SIP)来进行信号交换,因为它是最灵活,最轻便的协议。但是,根据许多研究,它恰好容易受到许多威胁系统安全性和可用性的攻击。在本文中,我们介绍了一种跨层机制,该机制能够缓解实时的欺骗攻击,例如SIP信号,身份盗用,伪装和中间的Man,以及单个和分布式源泛洪。它由三个部分组成:充当黑名单的策略执行器以及欺骗和泛洪模块。我们还介绍了SIP泛洪攻击的分类,以更好地表示检测范围。据我们所知,所提出的检测系统在能够阻止的攻击范围方面是最完整,最准确的。关于它的性能,它不需要计算昂贵的计算,也不需要资源需求的安全协议,因此是一种轻量级的机制。实验结果证明了较高的检测率,虚警率接近零。最后,它与平台无关,并且对网络操作透明,因此可以部署在VoIP和IMS环境中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号