Beta
33241

Problems of SIP Flooding Attacks Anomaly Detection Algorithms

Article

Last updated: 04 Jan 2025

Subjects

-

Tags

-

Abstract

Abstract:
Session Initiation Protocol (SIP) is vulnerable to a wide variety of Denial of Service
(DoS) attacks, flooding is the most common, effective and the easiest to generate one.
In this paper we present an evaluation study to four well-known anomaly detection
algorithms, namely: Adaptive Threshold, Cumulative sum (CUSUM), Non
Parametric Cumulative Sum (NP-CUSUM), and Hellinger Distance (HD). The
evaluation is assisted using simulated traffic dataset. We show that these algorithms
suffer from two main problems, the first is called attack masking and the second is
adaptation with attack. In the attack masking, attacker sends preamble followed by
the attack. The preamble changes the tuned parameters of the detection algorithm,
these changes mask the attack and keep it undetected. Attacker in the second problem
deviates the detection algorithm parameters gradually, in such a way the attack is
considered as normal traffic. The paper also shows that NP-CUSUM and HD
algorithms, which utilize the protocol behavior to detect intrusion, suffer from third
problem, and they are very simple to con. Attacker simply follows the same protocol
behavior, and its related traffic is considered as normal, and cannot be detected.

DOI

10.21608/iceeng.2010.33241

Keywords

Session initiation protocol, flooding attacks, denial of service, Anomaly detection, Adaptive Threshold, cumulative sum, non parametric cumulative sum, Hellinger distance

Authors

First Name

H.

Last Name

Al-Allouni

MiddleName

-

Affiliation

Syrian Armed Forces.

Email

-

City

-

Orcid

-

First Name

A.

Last Name

Rohiem

MiddleName

-

Affiliation

Egyptian Armed Forces.

Email

-

City

-

Orcid

-

First Name

M.

Last Name

Hashem

MiddleName

-

Affiliation

Ain Shams University, Cairo, Egypt.

Email

-

City

-

Orcid

-

First Name

A.

Last Name

El-moghazy

MiddleName

-

Affiliation

Egyptian Armed Forces.

Email

-

City

-

Orcid

-

Volume

7

Article Issue

7th International Conference on Electrical Engineering ICEENG 2010

Related Issue

5537

Issue Date

2010-05-01

Receive Date

2019-05-26

Publish Date

2010-05-01

Page Start

1

Page End

14

Print ISSN

2636-4433

Online ISSN

2636-4441

Link

https://iceeng.journals.ekb.eg/article_33241.html

Detail API

https://iceeng.journals.ekb.eg/service?article_code=33241

Order

80

Type

Original Article

Type Code

833

Publication Type

Journal

Publication Title

The International Conference on Electrical Engineering

Publication Link

https://iceeng.journals.ekb.eg/

MainTitle

Problems of SIP Flooding Attacks Anomaly Detection Algorithms

Details

Type

Article

Created At

22 Jan 2023