A framework for monitoring SIP enterprise networks - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

A framework for monitoring SIP enterprise networks

Résumé

In this paper we aim to enable security within SIP enterprise domains by providing monitoring capabilities at three levels: the network traffic, the server logs and the billing records. We propose an anomaly detection approach based on appropriate feature extraction and one-class Support Vector Machines (SVM). We propose methods for anomaly/attack type classification and attack source identification. Our approach is validated through experiments on a controlled test-bed using a customized normal traffic generation model and synthesized attacks. The results show promising performances in terms of accuracy, efficiency and usability.
Fichier principal
Vignette du fichier
nss10.pdf (1.32 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00519728 , version 1 (21-09-2010)

Identifiants

Citer

Mohamed Nassar, Radu State, Olivier Festor. A framework for monitoring SIP enterprise networks. Fourth international conference on Network and System Security - NSS 2010, Sep 2010, Melbourne, Australia. pp.1--8, ⟨10.1109/NSS.2010.79⟩. ⟨inria-00519728⟩
84 Consultations
416 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More