Detection of SIP Scans and Bruteforce Attacks
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F63839172%3A_____%2F17%3A10132921" target="_blank" >RIV/63839172:_____/17:10132921 - isvavai.cz</a>
Result on the web
—
DOI - Digital Object Identifier
—
Alternative languages
Result language
angličtina
Original language name
Detection of SIP Scans and Bruteforce Attacks
Original language description
Extended flow records with application layer (L7) information allow for detection of various types of malicious traffic. Voice over IP (VoIP) is an example of technology that works on L7 and many attacks against it cannot be reliably detected using just basic flow information. Session Initiation Protocol (SIP), which is commonly used for VoIP signalling, is a frequent target of many types of attacks. This paper proposes and evaluates a novel algorithm for near real time detection of username scanning and password guessing attacks on SIP servers. The detection is based on analysis of L7 extended flow records.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
<a href="/en/project/LM2015042" target="_blank" >LM2015042: E-infrastructure CESNET</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2017
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of the 5th Prague Embedded Systems Workshop
ISBN
978-80-01-06178-7
ISSN
—
e-ISSN
neuvedeno
Number of pages
3
Pages from-to
—
Publisher name
ČVUT v Praze, FIT, Katedra číslicového návrhu
Place of publication
Praha, Česká republika
Event location
Roztoky u Prahy, Česká republika
Event date
Jun 29, 2017
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—