Using Application-Aware Flow Monitoring for SIP Fraud Detection

被引:3
|
作者
Cejka, Tomas [1 ]
Bartos, Vaclav [2 ]
Truxa, Lukas [1 ]
Kubatova, Hana [3 ]
机构
[1] CESNET Ale, Prague 16000 6, Czech Republic
[2] Brno Univ Technol, Fac Informat Technol, CS-61090 Brno, Czech Republic
[3] Czech Tech Univ, FIT, Prague 16000 6, Czech Republic
关键词
D O I
10.1007/978-3-319-20034-7_10
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Flow monitoring helps to discover many network security threats targeted to various applications or network protocols. In this paper, we show usage of the flow data for analysis of a Voice over IP (VoIP) traffic and a threat detection. A traditionally used flow record is insufficient for this purpose and therefore it was extended by application-layer information. In particular, we focus on the Session Initiation Protocol (SIP) and the type of a toll-fraud in which an attacker tries to exploit poor configuration of a private branch exchange (PBX). The attacker's motivation is to make unauthorized calls to PSTN numbers that are usually charged at high rates and owned by the attacker. As a result, a successful attack can cause a significant financial loss to the owner of PBX. We propose a method for stream-wise and near real-time analysis of the SIP traffic and detection of the described threat. The method was implemented as a module of the Nemea system and deployed on a backbone network. It was evaluated using simulated as well as real attacks.
引用
收藏
页码:87 / 99
页数:13
相关论文
共 50 条
  • [1] Application-Aware Flow Monitoring
    Velan, Petr
    Celeda, Pavel
    [J]. 2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 701 - 706
  • [2] Next Generation Application-Aware Flow Monitoring
    Velan, Petr
    Celeda, Pavel
    [J]. MONITORING AND SECURING VIRTUALIZED NETWORKS AND SERVICES, 2014, 8508 : 173 - 178
  • [3] EffiEye: Application-aware Large Flow Detection in Data Center
    Wang, Binfeng
    Su, Jinshu
    Chen, Lin
    Deng, Jinsheng
    Zheng, Long
    [J]. 2017 17TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING (CCGRID), 2017, : 794 - 796
  • [4] Application Performance Optimization Using Application-Aware Networking
    Zhao, Shuai
    Medhi, Deep
    [J]. NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,
  • [5] Dynamic Flow Aggregation in SDNs for Application-aware Routing
    Tsai, Tsung-Hsien
    Wang, Kuochen
    Chao, Tzu-Yu
    [J]. 2016 10TH INTERNATIONAL SYMPOSIUM ON COMMUNICATION SYSTEMS, NETWORKS AND DIGITAL SIGNAL PROCESSING (CSNDSP), 2016,
  • [6] Application-aware multicast
    de Amorim, MD
    Duarte, OCMB
    Pujolle, G
    [J]. GLOBECOM '01: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6, 2001, : 2506 - 2510
  • [7] Application-Aware Latency Monitoring for Cloud Tenants via CloudWatch
    Liu, Dapeng
    Pei, Dan
    Zhao, Youjian
    [J]. 2014 10TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2014, : 73 - 81
  • [8] Detecting Compromised VM via Application-aware Anomaly Detection
    Luo, Kai
    Tu, Shouzhong
    Xia, Chunhe
    Zhou, Dan
    [J]. 2014 TENTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS), 2014, : 392 - 396
  • [9] SIP-enabled Optical Burst Switching architectures and protocols for application-aware optical networks
    Zervas, Georgios
    Qin, Yixuan
    Nejabati, Reza
    Simeonidou, Dimitra
    Callegati, Franco
    Campi, Aldo
    Cerroni, Walter
    [J]. COMPUTER NETWORKS, 2008, 52 (10) : 2065 - 2076
  • [10] Application-aware routing protocol
    Veeraraghavan, M
    Pancha, P
    Eng, KY
    [J]. SECOND IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, PROCEEDINGS, 1997, : 442 - 448