Title :
Analyzing anomalies in anonymized SIP traffic
Author :
Stanek, Jan ; Kencl, L. ; Kuthan, Jiri
Author_Institution :
Czech Tech. Univ. in Prague, Prague, Czech Republic
Abstract :
The Session Initiation Protocol (SIP) is a signaling protocol widely used nowadays for controlling multimedia communication sessions. Thus, understanding and troubleshooting SIP behavior is of utmost importance to network designers and operators. However, SIP traffic traces are hard to come by due to privacy and confidentiality issues. SIP contains a lot of personal information spread within the various SIP messages - IP addresses, names, usernames and domains, e-mail addresses etc. The known IP-address anonymization methods are thus insufficient. We present SiAnTo, an extended anonymization technique that substitutes session-participant information with matching, but nondescript, labels. This allows for SIP traces to be publicly shared, while keeping interesting traffic-session properties intact. We further demonstrate its usefulness by studying the problem of SIP NAT traversal as recorded in the anonymized traces. We analyze properties of the so-called “registration storm” incident and measure the influence of the active NAT traversal techniques on SIP traffic pattern, both only possible thanks to the preservation of session relationships inside the anonymized traces. As further benefit to the research community, we set up a public data-store with both the anonymization module and the anonymized traces available and invite other parties to share further SIP data using these open tools.
Keywords :
signalling protocols; telecommunication traffic; IP addresses; IP-address anonymization methods; SIP NAT; SIP behavior; SIP data; SIP messages; SIP traces; SIP traffic pattern; SiAnTo; active NAT traversal techniques; anomalies analysis; anonymization module; anonymized SIP traffic; confidentiality issues; e-mail addresses; multimedia communication sessions; network designers; personal information spread; privacy issues; public data-store; registration storm; session initiation protocol; signaling protocol; traffic-session properties; Electronic mail; IP networks; Privacy; Protocols; Registers; Servers; Storms;
Conference_Titel :
Networking Conference, 2014 IFIP
Conference_Location :
Trondheim
DOI :
10.1109/IFIPNetworking.2014.6857106