intrusion response system for sip based applications with engineered feature set

نویسندگان

hassan asgharian

computer engineering, iran university of science and technology, tehran, iran ahmad akbari

computer engineering, iran university of science and technology, tehran, iran bijan raahemi

school of electrical engineering and computer science, university of ottawa, ottawa, canada

چکیده

session initiation protocol (sip) is the main signaling protocol of next generation networks (ngn). sip based applications are usually deployed over the internet, for which their text-based nature and internal stateful operation make them vulnerable to different types of attacks. the real‑time functionality of sip based applications make their related security systems more complex. on the other hand, automatic response to intrusions is one of the most important issues in securing different applications. the current state of intrusion detection systems (ids) is that they often generate too many same or similar alerts for one intrusion which makes the function of response system unreliable. in this paper, we propose a security framework for automatic intrusion response in sip environments. our framework consists of specific firewall, detection engine and response part. the sip firewall works based on uris (universal reference identifier), and filters the incoming packets in the edge of network. input packets are directed to the specification based detection engine which works based on the proposed exactly engineered features. the output of this system and the current state of the sip proxy (e.g. call completion rate, call rejection rate and etc.) are fed to the response system to make a final decision. a prepared test bed is used for analyzing the performance of the proposed response system, measuring its performance using three distinct datasets. the experimental results show the performance of the proposed response system in terms of detection rates.

برای دانلود باید عضویت طلایی داشته باشید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

SIP Intrusion Detection and Response Architecture for Protecting SIP-based Services

After 3GPP had selected SIP as the signaling protocol for IMS, it is expected that SIP plays an important role in IP multimedia services. But, since SIP-based services are offered over the internet, there are security threats inherited from the internet environment. There are also new security threats because new techniques have been introduced to deliver multimedia traffic over the internet. I...

متن کامل

Policies Based Intrusion Response System for DBMS

Intrusion detection systems play an important role in detecting online intrusions and provide necessary alerts. Intrusion detection can also be done for relational databases. Intrusion response system for a relational database is essential to protect it from external and internal attacks. We propose a new intrusion response system for relational databases based on the database response policies...

متن کامل

A Parallel Genetic Algorithm Based Method for Feature Subset Selection in Intrusion Detection Systems

Intrusion detection systems are designed to provide security in computer networks, so that if the attacker crosses other security devices, they can detect and prevent the attack process. One of the most essential challenges in designing these systems is the so called curse of dimensionality. Therefore, in order to obtain satisfactory performance in these systems we have to take advantage of app...

متن کامل

Intrusion Detection using Supervised Learning with Feature Set Reduction

Intrusion detection systems intend to recognize attacks with a low false positive rate and high detection rate. Many feature selection methods introduced to eliminate redundant and irrelevant features, because raw features may abbreviate accuracy or robustness of classification. In this paper we are proposing the information gain technique for the selection of the features. A feature with the h...

متن کامل

A Parallel Genetic Algorithm Based Method for Feature Subset Selection in Intrusion Detection Systems

Intrusion detection systems are designed to provide security in computer networks, so that if the attacker crosses other security devices, they can detect and prevent the attack process. One of the most essential challenges in designing these systems is the so called curse of dimensionality. Therefore, in order to obtain satisfactory performance in these systems we have to take advantage of app...

متن کامل

Feature Selection Approach for Intrusion Detection System

At present, network security needs to be concerned to provide secure information channels due to increase in potential network attacks. Intrusion Detection System (IDS) is a valuable tool for the defense-in-depth of computer networks. However, building an efficient ID faces a number of challenges. One of the important challenges is dealing with data containing a high number of features. Current...

متن کامل

منابع من

با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید


عنوان ژورنال:
journal of advances in computer research

جلد ۷، شماره ۳، صفحات ۳۳-۴۵

میزبانی شده توسط پلتفرم ابری doprax.com

copyright © 2015-2023