DocumentCode :
2519494
Title :
Detecting Anomaly Traffic using Flow Data in the real VoIP network
Author :
Son, Hyeongu ; Lee, Youngseok
Author_Institution :
Dept. of Comput. Eng., Chungnam Nat. Univ., Daejeon, South Korea
fYear :
2010
fDate :
19-23 July 2010
Firstpage :
253
Lastpage :
256
Abstract :
As wireless LANs as well as the high-speed broadband Internet service are widely deployed, the VoIP service has become popular. Generally, a lot of commercial VoIP services use SIP and RTP for signaling and voice transport protocols. Most commercial VoIP service providers employ only simple security functions such as basic authentication without packet encryption because of fast implementation and deployment. Therefore, the VoIP service is highly vulnerable to several threats and attacks, because secure protocols for carrying VoIP packets are not fully utilized. For instance, unencrypted SIP packets including authentication messages could be easily forged to be exploited for generating anomaly traffic by malicious users. In this paper, we propose a flow-based VoIP anomaly traffic detection method that could find three representative VoIP anomaly attacks of SIP CANCEL, BYE DoS and RTP flooding that could be easily exploited in the real VoIP network. Our scheme uses the IETF IPFIX standard for monitoring VoIP calls in flow units. From the experiments with the commercial SIP phones in the real VoIP network, we show that SIP CANCEL, BYE DoS and RTP flooding attacks are easily generated and that they could be detected effectively by our proposed method.
Keywords :
Internet telephony; cryptographic protocols; signalling protocols; telecommunication security; telecommunication traffic; transport protocols; wireless LAN; BYE DoS; IETF IPFIX standard; RTP flooding; SIP CANCEL; VoIP network; anomaly traffic detection; message authentication; packet encryption; voice transport protocols; wireless LAN; Authentication; IEEE 802.11 Standards; Monitoring; Protocols; Wireless LAN; Wireless communication; IPFIX; SIP; VoIP; anomaly flow;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Applications and the Internet (SAINT), 2010 10th IEEE/IPSJ International Symposium on
Conference_Location :
Seoul
Print_ISBN :
978-1-4244-7526-1
Electronic_ISBN :
978-0-7695-4107-5
Type :
conf
DOI :
10.1109/SAINT.2010.108
Filename :
5598131
Link To Document :
بازگشت