Monitoring SIP traffic using Support Vector Machines - Inria - Institut national de recherche en sciences et technologies du numérique Access content directly
Conference Papers Year : 2008

Monitoring SIP traffic using Support Vector Machines

Abstract

In this paper, we propose a novel online monitoring approach able to distinguish between attacks and normal activity in SIP based Voice over IP environments. We demonstrate the efficiency of the approach even in presence of very limited data sets for the learning phase. The solution builds on the monitoring of a set of 38 features in VoIP flows and on Support Vector Machines for the classification part. We validate our proposal through large offline experiments performed over a mix of real world traces from a large VoIP provider and attacks locally generated on our own testbed. Results show high accuracy to detect SPIT and flooding attacks and promising performance for an online deployment are measured.
Fichier principal
Vignette du fichier
main.pdf (631.74 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

inria-00325290 , version 1 (27-09-2008)

Identifiers

  • HAL Id : inria-00325290 , version 1

Cite

Mohamed Nassar, Radu State, Olivier Festor. Monitoring SIP traffic using Support Vector Machines. 11th International Symposium on Recent advances in intrusion detection - RAID 2008, Sep 2008, Boston, United States. pp.311-330. ⟨inria-00325290⟩
186 View
413 Download

Share

Gmail Facebook X LinkedIn More