一种抵抗SIP服务器畸形和泛洪攻击的方法

J. Networks Pub Date : 2015-03-03 DOI:10.4304/jnw.10.2.77-84
Ming-Yang Su, Chen-Han Tsai
{"title":"一种抵抗SIP服务器畸形和泛洪攻击的方法","authors":"Ming-Yang Su, Chen-Han Tsai","doi":"10.4304/jnw.10.2.77-84","DOIUrl":null,"url":null,"abstract":"As a result of its low costs and high degree of integration with other services, Voice over Internet Protocol (VoIP) has become very widely used, while Session Initiation Protocol (SIP) is one of the most important protocols for providing the VoIP service. Since SIP is an open source code with a simple structure and high expansibility, SIP servers are more vulnerable to attack by SIP messages malformed in order to stunt the server, or by a flood of SIP messages causing server congestion or shutdown. The system proposed in this paper therefore has two functions; one is to filter malformed messages that conflict with the SIP protocol, and the other is to determine whether an SIP server is under flooding attack. This study used the Chi- square test, usually applied in statistics, to identify flooding attacks. The proposed system can automatically modify an SIP server's blacklist to deter an attacker's subsequent attempts.","PeriodicalId":14643,"journal":{"name":"J. Networks","volume":"94 1","pages":"77-84"},"PeriodicalIF":0.0000,"publicationDate":"2015-03-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":"{\"title\":\"An Approach to Resisting Malformed and Flooding Attacks on SIP Servers\",\"authors\":\"Ming-Yang Su, Chen-Han Tsai\",\"doi\":\"10.4304/jnw.10.2.77-84\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"As a result of its low costs and high degree of integration with other services, Voice over Internet Protocol (VoIP) has become very widely used, while Session Initiation Protocol (SIP) is one of the most important protocols for providing the VoIP service. Since SIP is an open source code with a simple structure and high expansibility, SIP servers are more vulnerable to attack by SIP messages malformed in order to stunt the server, or by a flood of SIP messages causing server congestion or shutdown. The system proposed in this paper therefore has two functions; one is to filter malformed messages that conflict with the SIP protocol, and the other is to determine whether an SIP server is under flooding attack. This study used the Chi- square test, usually applied in statistics, to identify flooding attacks. The proposed system can automatically modify an SIP server's blacklist to deter an attacker's subsequent attempts.\",\"PeriodicalId\":14643,\"journal\":{\"name\":\"J. Networks\",\"volume\":\"94 1\",\"pages\":\"77-84\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-03-03\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"7\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"J. Networks\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.4304/jnw.10.2.77-84\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"J. Networks","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4304/jnw.10.2.77-84","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

摘要

VoIP (Voice over Internet Protocol)由于其低成本和与其他业务的高度集成而得到了广泛的应用,而SIP (Session Initiation Protocol)是提供VoIP业务的最重要的协议之一。由于SIP是开源代码,结构简单,可扩展性高,因此SIP服务器更容易受到恶意破坏服务器的SIP消息的攻击,或者受到大量SIP消息导致服务器拥塞或关闭的攻击。因此,本文提出的系统具有两个功能;一是过滤与SIP协议冲突的畸形消息,二是判断SIP服务器是否受到泛洪攻击。本研究使用统计学中常用的卡方检验来识别洪水攻击。该系统可以自动修改SIP服务器的黑名单,以阻止攻击者的后续攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
An Approach to Resisting Malformed and Flooding Attacks on SIP Servers
As a result of its low costs and high degree of integration with other services, Voice over Internet Protocol (VoIP) has become very widely used, while Session Initiation Protocol (SIP) is one of the most important protocols for providing the VoIP service. Since SIP is an open source code with a simple structure and high expansibility, SIP servers are more vulnerable to attack by SIP messages malformed in order to stunt the server, or by a flood of SIP messages causing server congestion or shutdown. The system proposed in this paper therefore has two functions; one is to filter malformed messages that conflict with the SIP protocol, and the other is to determine whether an SIP server is under flooding attack. This study used the Chi- square test, usually applied in statistics, to identify flooding attacks. The proposed system can automatically modify an SIP server's blacklist to deter an attacker's subsequent attempts.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Asynchronous Multi-Channel MAC Protocol A Wireless Charging Infrastructure for Future Electrical Vehicular Adhoc Networks Application of Predictive Analytics in Telecommunications Project Management Secondary User Aggressiveness Optimization in Sensing-Transmission Scheduling for Cognitive Radio Networks Enhanced Chunk Regulation Algorithm for Superior QoS in Heterogeneous P2P Video on Demand
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1