Leveraging the SIP Load balancer to detect and mitigate DDos attacks

被引:0
|
作者
Akbar, Abdullah [1 ]
Basha, S. Mahaboob [2 ]
Sattar, Syed Abdul [3 ]
机构
[1] Jawaharlal Nehru Technol Univ, Hyderabad, Telangana, India
[2] Al Habeeb Coll Engn & Technol, Hyderabad, Telangana, India
[3] Royal Inst Technol & Sci, Acad Studies, Hyderabad, Telangana, India
关键词
Overload Control; kamailio; server; Session Initiation Protocol (SIP);
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SIP-based Voice Over IP(VoIP) network is becoming predominant in current and future communications. Distributed Denial of service attacks pose a serious threat to VOIP network security. SIP servers are victims of DDos attacks. The major aim of the DDos attacks is to avoid legitimate users to access resources of SIP servers. Distributed Denial of service attacks target the VOIP network by deploying bots at different locations by injecting malformed packets and even they halt the entire VOIP service causes degradation of QoS(Quality of Service). DDos attacks are easy to launch and quickly drain computational resources of VOIP network and nodes. Detecting DDos attacks is a challenging and extremely difficult due to its varying strategy and scope of attackers. Many DDos detection and prevention schemes are deployed in VOIP networks but they are not complete working in both realtime and offline modes. They are inefficient in detecting dynamic and low-rate DDos attacks and even fail when the attack is launched by simultaneously manipulating multiple SIP attributes. In this paper we propose a novel scheme based on Hellinger distance(HD) to detect low-rate and multi-attribute DDos attacks. Usually DDos detection and mitigations schemes are implemented in SIP proxy. But we leverage the SIP load balancer to fight against DDos by using existing load balancing features. We have implemented the proposed scheme by modifying leading open source kamailio SIP proxy server. We have evaluated our scheme by experimental test setup and found results are outperforming the existing DDos prevention schemes in terms of detection rate, system overhead and false-positive alarms.
引用
收藏
页码:1204 / 1208
页数:5
相关论文
共 50 条
  • [41] Baseline - A passive approach to tolerate and detect DoS/DDoS attacks
    Jin, S
    Liu, FY
    Xu, MW
    [J]. SAM '05: PROCEEDINGS OF THE 2005 INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, 2005, : 104 - 110
  • [42] Detect DDoS flooding attacks in mobile ad hoc networks
    Guo Y.
    Perreau S.
    [J]. International Journal of Security and Networks, 2010, 5 (04) : 259 - 269
  • [43] Leveraging the 5G architecture to mitigate amplification attacks
    Repetto, Matteo
    Carrega, Alessandro
    Lamanna, Guerino
    Yusupov, Jaloliddin
    Toscano, Orazio
    Bruno, Gianmarco
    Nuovo, Michele
    Cappelli, Marco
    [J]. PROCEEDINGS OF THE 2021 IEEE 7TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2021): ACCELERATING NETWORK SOFTWARIZATION IN THE COGNITIVE AGE, 2021, : 443 - 449
  • [44] A Bayesian change point model for detecting SIP-based DDoS attacks
    Kurt, Baris
    Yildiz, Cagatay
    Ceritli, Taha Yusuf
    Sankur, Bulent
    Cemgil, Ali Taylan
    [J]. DIGITAL SIGNAL PROCESSING, 2018, 77 : 48 - 62
  • [45] An Innovative Method to Mitigate DDoS Attacks for Cloud Environment Using Bagging and Stacking
    Kiranmai, B.
    Damodaram, A.
    [J]. PROCEEDINGS OF THE FIRST INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND INFORMATICS, ICCII 2016, 2017, 507 : 289 - 299
  • [46] On the effectiveness of rate-limiting methods to mitigate distributed DoS (DDoS) attacks
    Komatsu, Takanori
    Namatame, Akira
    [J]. IEICE TRANSACTIONS ON COMMUNICATIONS, 2007, E90B (10) : 2665 - 2672
  • [47] FastMove: Fast IP switching Moving Target Defense to mitigate DDOS Attacks
    Bandi, Nahid
    Tajbakhsh, Hesam
    Analoui, Morteza
    [J]. 2021 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2021,
  • [48] A task offloading approach based on risk assessment to mitigate edge DDoS attacks
    Huang, Haiou
    Sun, Bangyi
    Hu, Liang
    [J]. COMPUTERS & SECURITY, 2024, 140
  • [49] ORACLE: An Architecture for Collaboration of Data and Control Planes to Detect DDoS Attacks
    Gomez Macias, Sebastian
    Paschoal Gaspary, Luciano
    Felipe Botero, Juan
    [J]. 2021 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2021), 2021, : 962 - 967
  • [50] Development of Simulator for Intrusion Detection System to Detect and Alarm the DDoS Attacks
    Mishra, Ved Prakash
    Shukla, Balvinder
    [J]. 2017 INTERNATIONAL CONFERENCE ON INFOCOM TECHNOLOGIES AND UNMANNED SYSTEMS (TRENDS AND FUTURE DIRECTIONS) (ICTUS), 2017, : 803 - 806