Presentation is loading. Please wait.

Presentation is loading. Please wait.

Design and implementation of SIP-aware DDoS attack detection system By: Arif Iqbal.

Similar presentations


Presentation on theme: "Design and implementation of SIP-aware DDoS attack detection system By: Arif Iqbal."— Presentation transcript:

1 Design and implementation of SIP-aware DDoS attack detection system By: Arif Iqbal

2 Distributed Denial of Service

3 Types of DDoS Attacks

4 Why DDoS Attack. Very Easy to Launch. No Special Resources Required. No special Skills are required. Target are open on internet -> TO receive all request.

5 Attack Detection System. SIP application traffic statistics. SIP DDoS attack detection threshold Stored. Applying knowledge base rules to each user agent. Monitoring activities of -> User -> Call -> Server

6 User behavior Analysis. REGISTER Message Transmit Period. Number of INVITE Message. From/ To/ Call-ID Ratio Analysis. Top N traffic User Analysis

7 Call Behavior Analysis. Call-ID/SSRC Ratio Analysis. Req/Res Ratio Analysis. Method per Transmission Rate Analysis. IP/URI Ratio Analysis within REGISTER Message. RTP Seq. No Randomness per SSRC

8 Server/network Status Analysis SIP/RTP Traffic Volume Transition Analysis Status code Ration Analysis per server QoS Change Analysis

9 Test Environment

10 Critique and Criticism

11 . Transport Layer Security -> UDP flood -> TCP state exhaustion attacks -> SYN floods. IP Layer Security -> Spoofed Internet Protocol(IP) packet floods -> ICMP flood attacks.. Data Link Layer Security -> Fragmentation Attack

12 Thanks Any Question


Download ppt "Design and implementation of SIP-aware DDoS attack detection system By: Arif Iqbal."

Similar presentations


Ads by Google