DocumentCode :
3437296
Title :
A SIP DoS flooding attack defense mechanism based on priority class queue
Author :
Xiao-Yu Wan ; Li, Zhang ; Zi-Fu Fan
Author_Institution :
Next Generation Network Applic. Technol. Inst., Chongqing Univ. of Posts & Telecommun., Chongqing, China
fYear :
2010
fDate :
25-27 June 2010
Firstpage :
428
Lastpage :
431
Abstract :
This paper focuses on the research of defense mechanism of DoS (denial of service) attacks in SIP network. An M/M/1/K queue analysis model based on queue theory is proposed to analyze the SIP DoS attack firstly. Then, a DoS attack defense mechanism is proposed in order to alleviate SIP server´s influence by INVITE flooding attack. In our defense mechanism, the priority queue is introduced in SIP server´s message processing. At last, simulation is taken to analyze the performance of the defense mechanism proposed in this paper. The simulation results proves that SIP DoS flooding attack defense mechanism not only prolongs the serving time of SIP server correctly, but also realizes the aim of differentiating legitimate SIP message from attack flow.
Keywords :
Analytical models; Computer crime; Delay; Exponential distribution; Floods; IP networks; Network servers; Performance analysis; Protocols; Queueing analysis; Defense Mechanism; DoS attack; Flooding; Queuing Model; SIP;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Wireless Communications, Networking and Information Security (WCNIS), 2010 IEEE International Conference on
Conference_Location :
Beijing, China
Print_ISBN :
978-1-4244-5850-9
Type :
conf
DOI :
10.1109/WCINS.2010.5541813
Filename :
5541813
Link To Document :
بازگشت