作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2013, Vol. 39 ›› Issue (2): 119-124. doi: 10.3969/j.issn.1000-3428.2013.02.024

• 安全技术 • 上一篇    下一篇

一种高效抵御SIP洪泛攻击的防御模型

李鸿彬 1,2,林 浒 1,吕 昕 1,2,杨雪华 3   

  1. (1. 中国科学院沈阳计算技术研究所,沈阳 110168;2. 中国科学院研究生院,北京 100039; 3. 沈阳师范大学教育技术学院,沈阳 110034)
  • 收稿日期:2012-01-16 修回日期:2012-01-16 出版日期:2013-02-15 发布日期:2013-02-13
  • 作者简介:李鸿彬(1973-),男,副研究员、博士研究生,主研方向:VoIP网络安全,IP通信技术;林 浒,研究员、博士生导师;吕 昕,硕士研究生;杨雪华,讲师
  • 基金资助:
    国家水体污染控制与治理科技重大专项基金资助项目(2009ZX07528-006-05)

An Efficient Prevention Model Against SIP Flooding Attack

LI Hong-bin 1,2, LIN Hu 1, LV Xin 1,2, YANG Xue-hua 3   

  1. (1. Shenyang Institute of Computing Technology, Chinese Academy of Sciences, Shenyang 110168, China; 2. Graduate University of Chinese Academy of Sciences, Beijing 100039, China; 3. College of Educational Technology, Shenyang Normal University, Shenyang 110034, China)
  • Received:2012-01-16 Revised:2012-01-16 Online:2013-02-15 Published:2013-02-13

摘要: 根据会话初始协议(SIP)拒绝服务攻击的原理和方式,将阈值动态调整和实时动态防御相结合,提出一种抵御SIP洪泛攻击的防御模型,利用卡方流量判定模型与累计和统计模型动态调整阈值,并检测SIP洪泛攻击,通过IP防御模型动态抵御基于IP的SIP洪泛攻击。实验结果表明,该模型可以实时、高效地检测SIP洪泛攻击,在异常发生时有效防止SIP/ IMS服务器被攻击。

关键词: 会话初始协议, 拒绝服务攻击, 洪泛攻击, 卡方流量, 累计和, IP防御模型

Abstract: By analyzing the principle, mode, characteristics of Denial of Service(DoS) attack aiming at Session Initiation Protocol(SIP) and flooding attack faced by SIP network, this paper proposes a prevention model combining a dynamic threshold adjustment with real-time dynamic prevention for SIP flooding attack. It can dynamically adjust the threshold and detect SIP flooding attack through chi-square traffic judging mode and cumulative statistics mode, and can dynamically prevent IP-based SIP flooding attacks with IP defense model. Experimental result shows that the model can effectively detect and prevent the SIP flooding attack, and reduce the probability of SIP/IMS server being attacked when SIP network is on the abnormity.

Key words: Session Initiation Protocol(SIP), Denial of Service(DoS) attack, flooding attack, chi-square traffic, cumulative sum, IP defense model

中图分类号: