DocumentCode :
2842886
Title :
A broad-spectrum strategy for runtime risk management in VoIP enterprise architectures
Author :
Dabbebi, O. ; Badonnel, R. ; Festor, O.
Author_Institution :
INRIA Nancy Grand Est, LORIA - Nancy University, Campus Scientifique - BP 239, Technopôle de Nancy Brabois, 54506 Vandoeuvre-lès-Nancy, France
fYear :
2011
fDate :
23-27 May 2011
Firstpage :
478
Lastpage :
484
Abstract :
Telephony over IP (ToIP) has known a large scale deployment and is supported by the standardization of dedicated signalling protocols. This service is less confined than traditional telephony and is exposed to multiple security attacks. In the meantime, protection mechanisms may seriously impact on its performance. Risk management provides new opportunities for dynamically controlling the service exposure while maintaining low security costs. We propose in this paper a broad-spectrum strategy for runtime risk management in VoIP networks and services. We first analyse and model VoIP attacks based on their observability properties. We then generalize a runtime risk model capable of automatically assessing and treating risks based on dynamic safeguards. In particular, we quantify the potentiality of VoIP attacks and the induced risks with respect to their observability. We evaluate the benefits as well as the limits of our solution through an implementation prototype and an extensive set of simulations.
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Integrated Network Management (IM), 2011 IFIP/IEEE International Symposium on
Conference_Location :
Dublin
Print_ISBN :
978-1-4244-9219-0
Electronic_ISBN :
978-1-4244-9220-6
Type :
conf
DOI :
10.1109/INM.2011.5990549
Filename :
5990549
Link To Document :
بازگشت