Analyzing Anomalies in Anonymized SIP Traffic

被引:0
|
作者
Stanek, Jan [1 ]
Kencl, Lukas [1 ]
Kuthan, Jiri [2 ]
机构
[1] Czech Tech Univ, Prague 16627 6, Czech Republic
[2] Tekelec, D-13507 Berlin, Germany
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Session Initiation Protocol (SIP) is a signaling protocol widely used nowadays for controlling multimedia communication sessions. Thus, understanding and troubleshooting SIP behavior is of utmost importance to network designers and operators. However, SIP traffic traces are hard to come by due to privacy and confidentiality issues. SIP contains a lot of personal information spread within the various SIP messages - IP addresses, names, usernames and domains, e-mail addresses etc. The known IP-address anonymization methods are thus insufficient. We present SiAnTo, an extended anonymization technique that substitutes session-participant information with matching, but nondescript, labels. This allows for SIP traces to be publicly shared, while keeping interesting traffic-session properties intact. We further demonstrate its usefulness by studying the problem of SIP NAT traversal as recorded in the anonymized traces. We analyze properties of the so-called "registration storm" incident and measure the influence of the active NAT traversal techniques on SIP traffic pattern, both only possible thanks to the preservation of session relationships inside the anonymized traces. As further benefit to the research community, we set up a public data-store with both the anonymization module and the anonymized traces available and invite other parties to share further SIP data using these open tools.
引用
收藏
页数:9
相关论文
共 50 条
  • [41] Modeling of SIP Retransmission Traffic Under Lossy Network Conditions
    Yavas, Demir Y.
    Hokelek, Ibrahim
    Gunsel, Bilge
    2017 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING (BLACKSEACOM), 2017, : 132 - 136
  • [42] Analyzing freeway traffic under congestion: Traffic dynamics approach
    Nam, DH
    Drew, DR
    JOURNAL OF TRANSPORTATION ENGINEERING-ASCE, 1998, 124 (03): : 208 - 212
  • [43] Analyzing Spatiotemporal Anomalies through Interactive Visualization
    Zhang, Tao
    Liao, Qi
    Shi, Lei
    Dong, Weishan
    INFORMATICS-BASEL, 2014, 1 (01): : 100 - 125
  • [44] Analyzing business process anomalies using autoencoders
    Timo Nolle
    Stefan Luettgen
    Alexander Seeliger
    Max Mühlhäuser
    Machine Learning, 2018, 107 : 1875 - 1893
  • [45] Traffic aggregation based SIP over MPLS network architecture
    Rong, B
    Lebeau, J
    Bennani, M
    Kadoch, M
    Elhakeem, AK
    19TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 1, PROCEEDINGS: AINA 2005, 2005, : 827 - 832
  • [46] Model with Threshold Control for Analyzing a Server with an SIP Protocol in the Overload Mode
    Gaidamaka, Yu. V.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2013, 47 (04) : 211 - 218
  • [47] Modeling SIP Normal Traffic to Detect and Prevent SIP-VoIP Flooding Attacks Using Fuzzy Logic
    Hosseinpour, Mahsa
    Moghaddam, Mohammad Hossein Yaghmaee
    Seno, Seyed Amin Hosseini
    Roshkhari, Hossein Khosravi
    2016 6TH INTERNATIONAL CONFERENCE ON COMPUTER AND KNOWLEDGE ENGINEERING (ICCKE), 2016, : 274 - 279
  • [48] Sampling Method In Traffic Logs Analyzing
    Zhang, Hu
    Liu, Jun
    Zhou, Wenli
    Zhang, Shou
    2016 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT HUMAN-MACHINE SYSTEMS AND CYBERNETICS (IHMSC), VOL. 1, 2016, : 554 - 558
  • [49] Analyzing commercial through-traffic
    Joubert, Johan W.
    SEVENTH INTERNATIONAL CONFERENCE ON CITY LOGISTICS, 2012, 39 : 184 - 194
  • [50] Analyzing Risky Behavior in Traffic Accidents
    Chaudhari, Mayank
    Sarkar, Santonu
    Sharma, Divyasheel
    2020 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2020, : 464 - 471