DocumentCode :
2283953
Title :
CPU-based DoS attacks against SIP servers
Author :
Luo, Ming ; Peng, Tao ; Leckie, Christopher
Author_Institution :
Dept. of Comput. Sci. & Software Eng., Univ. of Melbourne, Melbourne, VIC
fYear :
2008
fDate :
7-11 April 2008
Firstpage :
41
Lastpage :
48
Abstract :
A key component of VoIP networks is the SIP signaling infrastructure. The reliance of public SIP servers on the Internet has opened up this critical infrastructure to a range of attacks. In particular, Denial of Service (DoS) attacks pose a serious security threat to the quality, reliability and availability of VoIP operations. In this paper, we investigate the impact of DoS attacks on SIP infrastructure, using a popular open source SIP server as a test bed. We have identified four attack scenarios that can exploit vulnerabilities in existing SIP authentication protocols, and we demonstrate the practical impact of these attacks on the target server. In response to these vulnerabilities, we have proposed several countermeasures to defend against each attack scenario. Our experimental results show that the current SIP implementation is highly vulnerable to DoS attacks and countermeasures are needed to make these servers more resilient. More importantly, we prove that authentication alone is no defence against DoS attacks in this context, and can actually increase the vulnerability of target servers instead of solving the problem of DoS attacks.
Keywords :
Internet telephony; network servers; signalling protocols; telecommunication network reliability; CPU-based DoS attacks; SIP authentication protocols; SIP servers; SIP signaling infrastructure; VoIP networks; denial of service attacks; reliability; session initialization protocol; target server vulnerability; Authentication; Availability; Computer crime; Computer science; Internet telephony; Network servers; Protocols; Security; Software engineering; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium, 2008. NOMS 2008. IEEE
Conference_Location :
Salvador, Bahia
ISSN :
1542-1201
Print_ISBN :
978-1-4244-2065-0
Electronic_ISBN :
1542-1201
Type :
conf
DOI :
10.1109/NOMS.2008.4575115
Filename :
4575115
Link To Document :
بازگشت