Download presentation
Presentation is loading. Please wait.
Published byChrystal Jenkins Modified over 9 years ago
1
Design and implementation of SIP-aware DDoS attack detection system By: Arif Iqbal
2
Distributed Denial of Service
3
Types of DDoS Attacks
4
Why DDoS Attack. Very Easy to Launch. No Special Resources Required. No special Skills are required. Target are open on internet -> TO receive all request.
5
Attack Detection System. SIP application traffic statistics. SIP DDoS attack detection threshold Stored. Applying knowledge base rules to each user agent. Monitoring activities of -> User -> Call -> Server
6
User behavior Analysis. REGISTER Message Transmit Period. Number of INVITE Message. From/ To/ Call-ID Ratio Analysis. Top N traffic User Analysis
7
Call Behavior Analysis. Call-ID/SSRC Ratio Analysis. Req/Res Ratio Analysis. Method per Transmission Rate Analysis. IP/URI Ratio Analysis within REGISTER Message. RTP Seq. No Randomness per SSRC
8
Server/network Status Analysis SIP/RTP Traffic Volume Transition Analysis Status code Ration Analysis per server QoS Change Analysis
9
Test Environment
10
Critique and Criticism
11
. Transport Layer Security -> UDP flood -> TCP state exhaustion attacks -> SYN floods. IP Layer Security -> Spoofed Internet Protocol(IP) packet floods -> ICMP flood attacks.. Data Link Layer Security -> Fragmentation Attack
12
Thanks Any Question
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.