DocumentCode
2845501
Title
On the inefficacy of Euclidean classifiers for detecting self-similar Session Initiation Protocol (SIP) messages
Author
Mehta, Anil ; Hantehzadeh, Neda ; Gurbani, Vijay K. ; Ho, Tin Kam ; Koshiko, Jun ; Viswanathan, Ramanarayanan
Author_Institution
Southern Illinois Univ., Carbondale, IL, USA
fYear
2011
fDate
23-27 May 2011
Firstpage
329
Lastpage
336
Abstract
The Session Initiation Protocol (SIP) is an important multimedia session establishment protocol used on the Internet. Due to the nature and deployment realities of the protocol (ASCII message representation, most deployments over UDP, limited use of message encryption), it becomes relatively easy to attack the protocol at the message level. To mitigate this, self-learning systems have been proposed to counteract new threats. However the efficacy of existing machine learning algorithms must be studied on varied data sets before they can be successfully used. Existing literature indicates that Euclidean distance based classifiers work well to detect anomalous messages. Our work suggests that such classifiers do not produce adequate results for well-crafted malicious messages that differ very slightly from normal messages. To demonstrate this, we gather SIP traffic and minimally perturb it using 13 generic transforms to create malicious SIP messages. We use the Levenshtein distance, L, as a measure of similarity between normal and malicious SIP messages. We subject our dataset - consisting of malicious and normal SIP messages - to Euclidean distance-based classifiers as well as four standard classifiers. Our results show vast differences for Euclidean distance-based classifiers on our dataset than reported in current literature. We further see that the standard classifiers are better able to classify an anomalous message when L is small.
Keywords
Internet; learning (artificial intelligence); signalling protocols; telecommunication traffic; ASCII message representation; Euclidean classifiers; Internet; Levenshtein distance; SIP messages; UDP; anomalous message detection; machine learning algorithms; message encryption; multimedia session establishment protocol; self-learning systems; self-similar session initiation protocol; Fires; Grammar; IP networks; Image edge detection; Internet; Routing protocols;
fLanguage
English
Publisher
ieee
Conference_Titel
Integrated Network Management (IM), 2011 IFIP/IEEE International Symposium on
Conference_Location
Dublin
Print_ISBN
978-1-4244-9219-0
Electronic_ISBN
978-1-4244-9220-6
Type
conf
DOI
10.1109/INM.2011.5990708
Filename
5990708
Link To Document