Exposing Resource Consumption Attacks in Internet Multimedia Services
Attackers always find ways to elude the employed security
mechanisms of a system, no matter how strong they are.
Nevertheless, audit trails - which as a rule of thumb are kept
by any service provider - store all the events pertaining to the
service of interest. Therefore, audit trail data can be a valuable
ally when it comes to the certification of the security level of
a given service. This stands especially true for critical real-
time services such as multimedia ones, which nowadays are on
the rise. This work proposes a practical, simple to implement
yet powerful solution based on the Hellinger Distance metric
for conducting audit trail analysis destined to expose security
incidents. Our solution relies on a set of different features
existing in the app layer protocol for session handling in order
to classify the analyzed traffic as intrusive or not. Taking the
well-known Session Initiation Protocol (SIP) as an example,
we thoroughly evaluate the effectiveness of the proposed
detection scheme in terms of accuracy under various realistic
scenarios. The outcomes reveal competitive detection rates in
terms of false positives and negatives and can be used as a
reference for future works in the field
TSIATSIKAS Zisis;
KAMBOURAKIS Georgios;
GENEIATAKIS Dimitrios;
2016-01-12
IEEE
JRC92363
http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=7300637,
https://publications.jrc.ec.europa.eu/repository/handle/JRC92363,
Additional supporting files
| File name | Description | File type | |