计算机应用 ›› 2011, Vol. 31 ›› Issue (10): 2660-2664.DOI: 10.3724/SP.J.1087.2011.02660

• 信息安全 • 上一篇    下一篇

抵御SIP分布式洪泛攻击的入侵防御系统

李鸿彬1,2,林浒1,吕昕1,2,杨雪华3   

  1. 1.中国科学院 沈阳计算技术研究所, 沈阳 110168
    2.中国科学院研究生院,北京 100039
    3.沈阳师范大学 教育技术学院, 沈阳 110034
  • 收稿日期:2011-04-19 修回日期:2011-06-09 发布日期:2011-10-11 出版日期:2011-10-01
  • 通讯作者: 李鸿彬
  • 作者简介:李鸿彬(1973-),男,河北临城人,副研究员,博士研究生,主要研究方向:IP通信、VoIP网络安全;林浒(1955-),男,辽宁沈阳人,研究员,博士生导师,主要研究方向:数控系统、IP通信;吕昕(1987-),男,安徽明光人,硕士研究生,主要研究方向:IP通信、VoIP网络安全;杨雪华(1978-),女,辽宁盖州人,讲师,主要研究方向:多媒体技术、IP通信。
  • 基金资助:

    国家水体污染控制与治理科技重大专项(2009ZX07528-006-05)

Intrusion prevention system against SIP distributed flooding attacks

LI Hong-bin1,2, LIN Hu1, Lü Xin1,2, YANG Xue-hua3   

  1. 1.Shenyang Institute of Computing Technology, Chinese Academy of Sciences, Shenyang Liaoning 110168, China
    2. Graduate University of Chinese Academy of Sciences, Beijing 100039, China
    3.College of Educational Technology, Shenyang Normal University, Shenyang Liaoning 110034, China
  • Received:2011-04-19 Revised:2011-06-09 Online:2011-10-11 Published:2011-10-01

摘要: 针对SIP分布式洪泛攻击检测与防御的研究现状,结合基于IP的分布式洪泛攻击和SIP消息的特点,提出了一种面向SIP分布式洪泛攻击的两级防御分布式拒绝服务(DDoS)攻击体系结构(TDASDFA):一级防御子系统(FDS)和二级防御子系统(SDS)。FDS对SIP的信令流进行粗粒度检测与防御,旨在过滤非VoIP消息和丢弃超出指定速率的IP地址的SIP信令,保证服务的可用性;SDS利用一种基于安全级别设定的攻击减弱方法对SIP信令流进行细粒度检测,并过滤具有明显DoS攻击特征的恶意攻击和低流量攻击。FDS和SDS协同工作来实时检测网络状况,减弱SIP分布式洪泛攻击。实验结果表明,TDASDFA能实时地识别和防御SIP分布式洪泛攻击,并且在异常发生时有效地减弱SIP代理服务器/IMS服务器被攻击的可能性。

关键词: 会话初始协议, 分布式洪泛攻击, 两级防御, 安全级别, 攻击减弱, 协同

Abstract: According to the research of distributed SIP flooding attack detection and defense, in combination with the characteristics of IP-based distributed flood attack and SIP messages, the two-level defense architecture against SIP distributed flooding attacks (TDASDFA) was presented. Two-level defensive components made up TDASDFA logically: the First level Defense Subsystem (FDS) and the Second level Defense Subsystem (SDS). FDS coarse-grained detected and defended SIP signaling stream to filter out non-VoIP messages and discard SIP messages of the IP addresses exceeding the specified rate to ensure service availability| SDS fine-grained detected and defended SIP messages using a mitigation method based on security level to identify the cunning attacks and low-flow attacks with obvious features of malicious DoS attacks. FDS and SDS detected and defended network status in real-time together to weaken SIP distributed flooding attacks. The experimental results show that TDASDFA can detect and defend SIP distributed flooding attacks, and reduces the probability of SIP proxy server or IMS server being attacked when the network is on the abnormity.

Key words: Session Initiation Protocol (SIP), distributed flooding attack, two-level defense, security level, attack mitigation, collaboration

中图分类号: