TY - GEN
T1 - A self-learning system for detection of anomalous SIP messages
AU - Rieck, Konrad
AU - Wahl, Stefan
AU - Laskov, Pavel
AU - Domschitz, Peter
AU - Müller, Klaus Robert
PY - 2008
Y1 - 2008
N2 - Current Voice-over-IP infrastructures lack defenses against unexpected network threats, such as zero-day exploits and computer worms. The possibility of such threats originates from the ongoing convergence of telecommunication and IP network infrastructures. As a countermeasure, we propose a self-learning system for detection of unknown and novel attacks in the Session Initiation Protocol (SIP). The system identifies anomalous content by embedding SIP messages to a feature space and determining deviation from a model of normality. The system adapts to network changes by automatically retraining itself while being hardened against targeted manipulations. Experiments conducted with realistic SIP traffic demonstrate the high detection performance of the proposed system at low false-positive rates.
AB - Current Voice-over-IP infrastructures lack defenses against unexpected network threats, such as zero-day exploits and computer worms. The possibility of such threats originates from the ongoing convergence of telecommunication and IP network infrastructures. As a countermeasure, we propose a self-learning system for detection of unknown and novel attacks in the Session Initiation Protocol (SIP). The system identifies anomalous content by embedding SIP messages to a feature space and determining deviation from a model of normality. The system adapts to network changes by automatically retraining itself while being hardened against targeted manipulations. Experiments conducted with realistic SIP traffic demonstrate the high detection performance of the proposed system at low false-positive rates.
UR - http://www.scopus.com/inward/record.url?scp=57349174533&partnerID=8YFLogxK
U2 - 10.1007/978-3-540-89054-6_5
DO - 10.1007/978-3-540-89054-6_5
M3 - Conference contribution
AN - SCOPUS:57349174533
SN - 354089053X
SN - 9783540890539
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 90
EP - 106
BT - Principles, Systems and Applications of IP Telecommunications
PB - Springer Verlag
T2 - 2nd International Conference on Principles, Systems and Applications of IP Telecommunications, IPTComm 2008
Y2 - 1 July 2008 through 2 July 2008
ER -