Shen Zhang, Lu Zhou, Mingli Wu, Zhushou Tang, Na Ruan, Haojin Zhu
{"title":"VoLTE设备sip感知攻击自动检测","authors":"Shen Zhang, Lu Zhou, Mingli Wu, Zhushou Tang, Na Ruan, Haojin Zhu","doi":"10.1109/VTCFall.2016.7880916","DOIUrl":null,"url":null,"abstract":"Abstract-Due to the worldwide deployment of Long Term Evolution (LTE), the fourth-generation (4G) mobile cellular networking technology, Voice over LTE (VoLTE) [2] has been also well developed in past few years. It exploits packet-switched network to provide call services instead of the traditional circuit- switched telephony. Similar to the Voice over IP (VoIP), VoLTE adopts Session Initiation Protocol (SIP) to achieve some control functions. Therefore, it means attack techniques against the SIP will also be effective against VoLTE devices. In this paper, we propose a novel device-side SIP-aware detecting system against two kinds of SIP attacks, SIP message flooding attack and malformed SIP message attack. To detect the message flooding attack, we set threshold for the traffic of SIP message received from VoLTE interface within one minute. And for the malformed message attack, we provide the structure and formalization rules of SIP messages to detect malformed SIP messages by utilizing ontology descriptions. This paper presents the design and implementation of this detecting system. The simulation test shows that this system will improve the security level of VoLTE service in real applications.","PeriodicalId":6484,"journal":{"name":"2016 IEEE 84th Vehicular Technology Conference (VTC-Fall)","volume":"25 1","pages":"1-5"},"PeriodicalIF":0.0000,"publicationDate":"2016-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":"{\"title\":\"Automatic Detection of SIP-Aware Attacks on VoLTE Device\",\"authors\":\"Shen Zhang, Lu Zhou, Mingli Wu, Zhushou Tang, Na Ruan, Haojin Zhu\",\"doi\":\"10.1109/VTCFall.2016.7880916\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Abstract-Due to the worldwide deployment of Long Term Evolution (LTE), the fourth-generation (4G) mobile cellular networking technology, Voice over LTE (VoLTE) [2] has been also well developed in past few years. It exploits packet-switched network to provide call services instead of the traditional circuit- switched telephony. Similar to the Voice over IP (VoIP), VoLTE adopts Session Initiation Protocol (SIP) to achieve some control functions. Therefore, it means attack techniques against the SIP will also be effective against VoLTE devices. In this paper, we propose a novel device-side SIP-aware detecting system against two kinds of SIP attacks, SIP message flooding attack and malformed SIP message attack. To detect the message flooding attack, we set threshold for the traffic of SIP message received from VoLTE interface within one minute. And for the malformed message attack, we provide the structure and formalization rules of SIP messages to detect malformed SIP messages by utilizing ontology descriptions. This paper presents the design and implementation of this detecting system. The simulation test shows that this system will improve the security level of VoLTE service in real applications.\",\"PeriodicalId\":6484,\"journal\":{\"name\":\"2016 IEEE 84th Vehicular Technology Conference (VTC-Fall)\",\"volume\":\"25 1\",\"pages\":\"1-5\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"5\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 IEEE 84th Vehicular Technology Conference (VTC-Fall)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/VTCFall.2016.7880916\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE 84th Vehicular Technology Conference (VTC-Fall)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/VTCFall.2016.7880916","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
摘要
摘要:随着第四代(4G)移动蜂窝网络技术长期演进(LTE)在全球范围内的部署,语音LTE (VoLTE)[2]在过去几年中也得到了很好的发展。它利用分组交换网络代替传统的电路交换电话提供呼叫服务。VoLTE与VoIP (Voice over IP)类似,采用SIP (Session Initiation Protocol)协议来实现部分控制功能。因此,这意味着针对SIP的攻击技术也将对VoLTE设备有效。本文提出了一种针对SIP报文泛洪攻击和SIP报文畸形攻击的设备侧SIP感知检测系统。为了检测报文泛洪攻击,我们设置了一分钟内从VoLTE接口接收SIP报文流量的阈值。针对SIP畸形消息攻击,提出了SIP消息的结构和形式化规则,利用本体描述检测SIP畸形消息。本文介绍了该检测系统的设计与实现。仿真测试表明,该系统在实际应用中提高了VoLTE业务的安全水平。
Automatic Detection of SIP-Aware Attacks on VoLTE Device
Abstract-Due to the worldwide deployment of Long Term Evolution (LTE), the fourth-generation (4G) mobile cellular networking technology, Voice over LTE (VoLTE) [2] has been also well developed in past few years. It exploits packet-switched network to provide call services instead of the traditional circuit- switched telephony. Similar to the Voice over IP (VoIP), VoLTE adopts Session Initiation Protocol (SIP) to achieve some control functions. Therefore, it means attack techniques against the SIP will also be effective against VoLTE devices. In this paper, we propose a novel device-side SIP-aware detecting system against two kinds of SIP attacks, SIP message flooding attack and malformed SIP message attack. To detect the message flooding attack, we set threshold for the traffic of SIP message received from VoLTE interface within one minute. And for the malformed message attack, we provide the structure and formalization rules of SIP messages to detect malformed SIP messages by utilizing ontology descriptions. This paper presents the design and implementation of this detecting system. The simulation test shows that this system will improve the security level of VoLTE service in real applications.