Fast Detection of Distributed Denial of Service Attacks in VoIP Networks Using Convolutional Neural Networks

Waleed Nazih, Yasser Hifny, Wail S. Elkilani, T. Mostafa
{"title":"Fast Detection of Distributed Denial of Service Attacks in VoIP Networks Using Convolutional Neural Networks","authors":"Waleed Nazih, Yasser Hifny, Wail S. Elkilani, T. Mostafa","doi":"10.21608/IJICIS.2021.51555.1046","DOIUrl":null,"url":null,"abstract":"Voice over Internet Protocol (VoIP) is a recent technology used to transfer media and voice over Internet Protocol (IP). Many organizations moved to VoIP services instead of the traditional telephone systems because of its low cost and variety of introduced services. The Session Initiation Protocol (SIP) is the most used protocol for signaling functions in VoIP networks. It has simple implantation but suffers from less protection against attacks. The Distributed Denial of Service (DDoS) attack is a dangerous attack that preventing legitimate users from using VoIP services and draining their resources. In this paper, we proposed an approach that utilizes deep learning to detect DDoS attacks. The proposed approach uses token embedding to improve the extracted features of SIP messages. Then, Convolutional Neural Network (CNN) was used to detect DDoS attacks with different intensities. Furthermore, a real VoIP dataset that contains different scenarios of attacks was used to evaluate the proposed approach. Our experiments find that the CNN model achieved a high F1 score (99-100%) as another deep learning approach that utilizes Recurrent Neural Network (RNN) but with less detection time. Also, it outperforms another system that depends on classical machine learning in case of low-rate DDoS attacks. https://ijicis.journals.ekb.eg/","PeriodicalId":244591,"journal":{"name":"International Journal of Intelligent Computing and Information Sciences","volume":"61 5 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Intelligent Computing and Information Sciences","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.21608/IJICIS.2021.51555.1046","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Voice over Internet Protocol (VoIP) is a recent technology used to transfer media and voice over Internet Protocol (IP). Many organizations moved to VoIP services instead of the traditional telephone systems because of its low cost and variety of introduced services. The Session Initiation Protocol (SIP) is the most used protocol for signaling functions in VoIP networks. It has simple implantation but suffers from less protection against attacks. The Distributed Denial of Service (DDoS) attack is a dangerous attack that preventing legitimate users from using VoIP services and draining their resources. In this paper, we proposed an approach that utilizes deep learning to detect DDoS attacks. The proposed approach uses token embedding to improve the extracted features of SIP messages. Then, Convolutional Neural Network (CNN) was used to detect DDoS attacks with different intensities. Furthermore, a real VoIP dataset that contains different scenarios of attacks was used to evaluate the proposed approach. Our experiments find that the CNN model achieved a high F1 score (99-100%) as another deep learning approach that utilizes Recurrent Neural Network (RNN) but with less detection time. Also, it outperforms another system that depends on classical machine learning in case of low-rate DDoS attacks. https://ijicis.journals.ekb.eg/
基于卷积神经网络的VoIP网络分布式拒绝服务攻击快速检测
VoIP (Voice over Internet Protocol)是一种最新的通过互联网协议(IP)传输媒体和语音的技术。由于VoIP的低成本和引入的服务种类繁多,许多组织转向VoIP服务而不是传统的电话系统。SIP (Session Initiation Protocol)是VoIP网络中最常用的信令协议。它的植入很简单,但对攻击的保护较少。分布式拒绝服务(DDoS)攻击是一种危险的攻击,它可以阻止合法用户使用VoIP服务并耗尽他们的资源。在本文中,我们提出了一种利用深度学习来检测DDoS攻击的方法。该方法利用令牌嵌入改进了SIP消息提取的特征。然后,利用卷积神经网络(CNN)检测不同强度的DDoS攻击。此外,使用包含不同攻击场景的真实VoIP数据集来评估所提出的方法。我们的实验发现,CNN模型作为另一种利用递归神经网络(RNN)但检测时间更短的深度学习方法,获得了很高的F1分数(99-100%)。此外,在低速率DDoS攻击的情况下,它的性能优于另一个依赖于传统机器学习的系统。https://ijicis.journals.ekb.eg/
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信