DISI - Via Sommarive , 5 - 38123 POVO , Trento - Italy http : / / disi . unitn . it CLASSIFICATION OF SIP MESSAGES BY A SYNTAX FILTER

نویسندگان

  • Raihana Ferdous
  • Renato Lo Cigno
  • Alessandro Zorat
چکیده

The Session Initiation Protocol (SIP) is at the root of many sessions-based applications such as VoIP and media streaming that are used by a growing number of users and organizations. The increase of the availability and use of such applications calls for careful attention to the possibility of transferring malformed, incorrect, or malicious SIP messages as they can cause problems ranging from relatively innocuous disturbances to full blown attacks and frauds. To this end, SIP messages are analyzed to be classified as “good” or “bad” depending on whether this structure and content are deemed acceptable or not. This paper presents a classifier of SIP messages based on a two stage filter. The first stage uses a straightforward lexical analyzer to detect and remove all messages that are lexically incorrect with reference to the grammar that is defined by the protocol standard. The second stage uses a machine learning approach based on a Support Vector Machine (SVM) to analyze the structure of the remaining syntactically correct messages in order to detect semantic anomalies which are deemed a strong indication of a possibly malicious message. The SVM “learns” the structure of the “good” and “bad” SIP messages through an initial training phase and the SVM thus configured correctly classifies messages produced by a synthetic generator and also “real” SIP messages that have been collected from the communication network at our institution. The preliminary results of such classification look very promising and are presented in the final section of this paper.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

DISI Via Sommarive 14 38123 Povo Trento ( Italy ) http : / / www . disi . unitn . it DISTRIBUTED ENTITY SEARCH

Capturing information about entities of the real world (i.e. locations, people, institutions and others) is a goal that is gaining more attention in today’s web of data. We believe that this capturing would only be possible if users can contribute and interact as they do in the real world. The contribution and interaction of users may take place over a distributed network where they can publish...

متن کامل

Attacker economics for Internet - scale vulnerability risk assessment ( Extended

Luca Allodi DISI University of Trento, Italy http: // disi. unitn. it/

متن کامل

Space-Ruled Ecological Processes: Introduction to the Special Issue on Spatial Ecology

Duccio Rocchini 1,2,3 1 University of Trento, Center Agriculture Food Environment, Via E. Mach 1, 38010 S. Michele all’Adige (TN), Italy; [email protected] 2 University of Trento, Centre for Integrative Biology, Via Sommarive, 14, 38123 Povo (TN), Italy 3 Fondazione Edmund Mach, Department of Biodiversity and Molecular Ecology, Research and Innovation Centre, Via E. Mach 1, 38010 S. Mich...

متن کامل

Method for detection and reconstruction of gravitational wave transients with networks of advanced detectors

S. Klimenko, G. Vedovato, M. Drago, F. Salemi, V. Tiwari, G. A. Prodi, C. Lazzaro, K. Ackley, S. Tiwari, 5 C. F. Da Silva Costa, and G. Mitselmakher University of Florida, P.O.Box 118440, Gainesville, Florida, 32611, USA INFN, Sezione di Padova, via Marzolo 8, 35131 Padova, Italy Max Planck Institut für Gravitationsphysik, Callinstrasse 38, 30167 Hannover, and Leibniz Universität Hannover, Hann...

متن کامل

Dominant Folding Pathways of a Beta-Hairpin

Pietro Faccioli∗,1, 2 Alice Lonardi, 3 and Henri Orland Dipartimento di Fisica, Universitá degli Studi di Trento, Via Sommarive 14, Povo (Trento) Italy, I-38100. I.N.F.N., Gruppo Collegato di Trento, Via Sommarive 14, Povo (Trento) Italy, I-38100. Dipartimento di Scienze e Tecnologie Chimiche, Universitá di Roma Tor Vergata, Via della Ricerca Scientifica I-00133 Rome, Italy Institut de Physique...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012