Monitoring SIP Traffic Using Support Vector Machines

作者: Mohamed Nassar , Radu State , Olivier Festor

DOI: 10.1007/978-3-540-87403-4_17

关键词:

摘要: We propose a novel online monitoring approach to distinguish between attacks and normal activity in SIP-based Voice over IP environments. demonstrate the efficiency of even when only limited data sets are used learning phase. The solution builds on set 38 features VoIP flows uses Support Vector Machines for classification. validate our proposal through large offline experiments performed mix real world traces from provider locally generated own testbed. Results show high accuracy detecting SPIT flooding promising performance an deployment measured.

参考文章(23)
Dipak Ghosal, Brennen Reynolds, Secure IP Telephony using Multi-layered Protection. network and distributed system security symposium. ,(2003)
Peng Ning, Sushil Jajodia, Xiaoyang Sean Wang, Intrusion Detection in Distributed Systems: An Abstraction-Based Approach ,(2003)
Christopher Krügel, Thomas Toth, Engin Kirda, Service specific anomaly detection for network intrusion detection acm symposium on applied computing. pp. 201- 208 ,(2002) , 10.1145/508791.508835
Hun Jeong Kang, Zhi-Li Zhang, Supranamaya Ranjan, Antonio Nucci, SIP-based VoIP traffic behavior profiling and its applications Proceedings of the 3rd annual ACM workshop on Mining network data - MineNet '07. pp. 39- 44 ,(2007) , 10.1145/1269880.1269891
Humberto J. Abdelnur, Radu State, Olivier Festor, KiF Proceedings of the 1st international conference on Principles, systems and applications of IP telecommunications - IPTComm '07. pp. 47- 56 ,(2007) , 10.1145/1326304.1326313
Alfonso Valdes, Keith Skinner, Adaptive, Model-Based Monitoring for Cyber Attack Detection recent advances in intrusion detection. pp. 80- 92 ,(2000) , 10.1007/3-540-39945-3_6
Vijay A. Balasubramaniyan, Mustaque Ahamad, Haesun Park, CallRank: Combating SPIT Using Call Duration, Social Networks and Global Reputation conference on email and anti-spam. ,(2007)