DocumentCode :
2614178
Title :
Statistical Analysis of Self-Similar Session Initiation Protocol (SIP) Messages for Anomaly Detection
Author :
Hentehzadeh, N. ; Mehta, Anil ; Gurbani, Vijay K. ; Gupta, Lalit ; Ho, Tin Kam ; Wilathgamuwa, Gayan
fYear :
2011
fDate :
7-10 Feb. 2011
Firstpage :
1
Lastpage :
5
Abstract :
The Session Initiation Protocol (SIP) is an important multimedia session establishment protocol used on the Internet. Due to the nature and deployment realities of the protocol (ASCII message representation, widespread usage over UDP, limited use of encryption), it becomes relatively easy to attack the protocol at the message level to launch denial of service attacks. To mitigate this, self- learning systems have been proposed to detect anomalous SIP messages and filter them. However, previous works use datasets with large differences between the normal and anomalous message. This gives high performance for existing classification systems, including those based on Euclidean distances. We present our analysis on a new dataset that has minimal difference between normal and anomalous messages. Our findings indicate that existing classification schemes behave unsatisfactorily on our dataset. We demonstrate why this is the case by statistical analysis of our dataset, and furthermore, present feature reduction techniques to enhance the classification performance of existing classification schemes on our dataset.
Keywords :
Internet; cryptographic protocols; message authentication; multimedia communication; pattern classification; signalling protocols; statistical analysis; Euclidean distance; Internet; anomalous message; anomaly detection; classification system; encryption; feature reduction technique; multimedia session establishment protocol; self learning system; session initiation protocol; statistical analysis; Computer crime; Euclidean distance; Feature extraction; Grammar; Internet; Protocols; Transforms;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
New Technologies, Mobility and Security (NTMS), 2011 4th IFIP International Conference on
Conference_Location :
Paris
ISSN :
2157-4952
Print_ISBN :
978-1-4244-8705-9
Electronic_ISBN :
2157-4952
Type :
conf
DOI :
10.1109/NTMS.2011.5720662
Filename :
5720662
Link To Document :
بازگشت