Fast Detection of Denial-of-Service Attacks on IP Telephony

Hemant Sengar, Haining Wang, D. Wijesekera, S. Jajodia
{"title":"Fast Detection of Denial-of-Service Attacks on IP Telephony","authors":"Hemant Sengar, Haining Wang, D. Wijesekera, S. Jajodia","doi":"10.1109/IWQOS.2006.250469","DOIUrl":null,"url":null,"abstract":"Recently voice over IP (VoIP) is experiencing a phenomenal growth. Being a real-time service, VoIP is more susceptible to denial-of-service (DoS) attacks than regular Internet services. Moreover, VoIP uses multiple protocols for call control and data delivery, making it vulnerable to various DoS attacks at different protocol layers. An attacker can easily disrupt VoIP services by flooding TCP SYN packets, UDP-based RTP packets, or SIP-based INVITE messages, which pose a critical threat to IP telephony. In this paper, we present an online statistical detection mechanism, called vFDS, to detect DoS attacks in the context of VoIP. The core of vFDS is based on Hellinger distance method, which computes the variability between two probability measures. Using Hellinger distance, we characterize normal protocol behaviors and then detect the traffic anomalies caused by flooding attacks. Our experimental results show that vFDS achieves fast and accurate detection of DoS attacks","PeriodicalId":248938,"journal":{"name":"200614th IEEE International Workshop on Quality of Service","volume":"2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2006-11-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"69","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"200614th IEEE International Workshop on Quality of Service","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IWQOS.2006.250469","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 69

Abstract

Recently voice over IP (VoIP) is experiencing a phenomenal growth. Being a real-time service, VoIP is more susceptible to denial-of-service (DoS) attacks than regular Internet services. Moreover, VoIP uses multiple protocols for call control and data delivery, making it vulnerable to various DoS attacks at different protocol layers. An attacker can easily disrupt VoIP services by flooding TCP SYN packets, UDP-based RTP packets, or SIP-based INVITE messages, which pose a critical threat to IP telephony. In this paper, we present an online statistical detection mechanism, called vFDS, to detect DoS attacks in the context of VoIP. The core of vFDS is based on Hellinger distance method, which computes the variability between two probability measures. Using Hellinger distance, we characterize normal protocol behaviors and then detect the traffic anomalies caused by flooding attacks. Our experimental results show that vFDS achieves fast and accurate detection of DoS attacks
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
IP电话拒绝服务攻击的快速检测
最近,IP语音(VoIP)正经历着惊人的增长。作为一种实时服务,VoIP比普通的互联网服务更容易受到拒绝服务(DoS)攻击。此外,VoIP使用多种协议进行呼叫控制和数据传输,容易受到不同协议层的各种DoS攻击。攻击者可以通过大量的TCP SYN报文、基于udp的RTP报文或基于sip的INVITE消息来破坏VoIP业务,对IP电话构成严重威胁。在本文中,我们提出了一种在线统计检测机制,称为vFDS,用于检测VoIP环境下的DoS攻击。vFDS的核心是基于海灵格距离法,计算两个概率测度之间的可变性。利用海灵格距离对正常协议行为进行表征,进而检测由洪水攻击引起的流量异常。实验结果表明,vFDS能够快速准确地检测出DoS攻击
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A Variation of Route Flap Damping to Improve BGP Routing Convergence Dynamic Resource Reservation in IEEE 802.16 Broadband Wireless Networks On the Performance of Error-resilient End-point-based Multicast Streaming Dynamic Adaptation of Temporal Event Correlation for QoS Management in Distributed Systems Flow-Cookies: Using Bandwidth Amplification to Defend Against DDoS Flooding Attacks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1