Skip to main content

2020 | OriginalPaper | Buchkapitel

Development of a Distributed VoIP Honeypot System with Advanced Malicious Traffic Detection

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

The number of active users using Voice over IP (VoIP) services has an increasing tendency. With an expanding number of users, there is also a rapid increase in the number of hackers interested in attacking the VoIP communication system. This paper aims at detecting malicious SIP traffic and also deals with the security of the VoIP architecture issue. It is not a trivial matter to secure the VoIP system because exploiting the vulnerabilities of IP based telecommunication systems have increased. It is crucial to develop a tool that would be able to detect these attacks, analyse collected data, monitor attackers progress and to prepare an effective way of how to defend against VoIP attackers. That was the primary motivation why we have decided to develop our honeypot solution which can detect attacks on VoIP infrastructure, and it is adapted to the new security threats and which is designed according to the needs of the telecommunications market. Our VoIP honeypot is implemented purely in JAVA programming language and is capable of capturing and processing various types of attacks. The whole project is based on a Linux distribution, ready for the easiest deployment because it is prepared as a virtual machine image.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Literatur
2.
Zurück zum Zitat Voznak, M., Kapicak, L., Zdralek, J., Nevlud, P., Plucar, J.: Multimedia services in asterisk based on voiceXML. Int. J. Math. Models Methods Appl. Sci. 5(5), 857–865 (2011) Voznak, M., Kapicak, L., Zdralek, J., Nevlud, P., Plucar, J.: Multimedia services in asterisk based on voiceXML. Int. J. Math. Models Methods Appl. Sci. 5(5), 857–865 (2011)
3.
Zurück zum Zitat Voznak, M., Rezac, F.: Threats to voice over IP communications systems. WSEAS Trans. Comput. 9(11), 1348–1358 (2010) Voznak, M., Rezac, F.: Threats to voice over IP communications systems. WSEAS Trans. Comput. 9(11), 1348–1358 (2010)
4.
Zurück zum Zitat Nevlud, P., Bures, M., Kapicak, L., Zdralek, J.: Anomaly-based network intrusion detection methods. Adv. Electr. Electron. Eng. 11(6), 468–474 (2013) Nevlud, P., Bures, M., Kapicak, L., Zdralek, J.: Anomaly-based network intrusion detection methods. Adv. Electr. Electron. Eng. 11(6), 468–474 (2013)
5.
Zurück zum Zitat Sisalem, D., Floroiu, J., Kuthan, J., Abend, U., Schulzrinne, H.: SIP Security. Wiley Blackwell, Hoboken (2009)CrossRef Sisalem, D., Floroiu, J., Kuthan, J., Abend, U., Schulzrinne, H.: SIP Security. Wiley Blackwell, Hoboken (2009)CrossRef
6.
Zurück zum Zitat Rezac, F., Voznak, M., Tomala, K., Rozhon, J., Vychodil, J.: Security analysis system to detect threats on a SIP VoIP infrasctructure elements. Adv. Electr. Electron. Eng. 9(5), 225–232 (2011) Rezac, F., Voznak, M., Tomala, K., Rozhon, J., Vychodil, J.: Security analysis system to detect threats on a SIP VoIP infrasctructure elements. Adv. Electr. Electron. Eng. 9(5), 225–232 (2011)
7.
Zurück zum Zitat Safarik, J., Partila, P., Rezac, F., Macura, L., Voznak, M.: Automatic classification of attacks on IP telephony. Adv. Electr. Electron. Eng. 11(6), 481–486 (2013) Safarik, J., Partila, P., Rezac, F., Macura, L., Voznak, M.: Automatic classification of attacks on IP telephony. Adv. Electr. Electron. Eng. 11(6), 481–486 (2013)
8.
Zurück zum Zitat Voznak, M., Safarik, J., Rezac, F.: Threat prevention and intrusion detection in VoIP infrastructures. Int. J. Math. Comput. Simul. 7(1), 69–76 (2013) Voznak, M., Safarik, J., Rezac, F.: Threat prevention and intrusion detection in VoIP infrastructures. Int. J. Math. Comput. Simul. 7(1), 69–76 (2013)
9.
Zurück zum Zitat Voznak, M., Rozhon, J.: SIP infrastructure performance testing. In: 9th WSEAS International Conference on Telecommunications and Informatics, TELE-INFO 2010 , pp. 153–158 (2010) Voznak, M., Rozhon, J.: SIP infrastructure performance testing. In: 9th WSEAS International Conference on Telecommunications and Informatics, TELE-INFO 2010 , pp. 153–158 (2010)
10.
Zurück zum Zitat Rozhon, J., Voznak, M.: SIP registration burst load test. In: Communications in Computer and Information Science, vol. 189. CCIS(PART 2), pp. 329–336 (2011) Rozhon, J., Voznak, M.: SIP registration burst load test. In: Communications in Computer and Information Science, vol. 189. CCIS(PART 2), pp. 329–336 (2011)
11.
Zurück zum Zitat Vennila, G., Manikandan, M., Suresh, M.: Detection and prevention of spam over internet telephony in voice over internet protocol networks using Markov chain with incremental SVM. Int. J. Commun. Syst. 30(11) (2017) Vennila, G., Manikandan, M., Suresh, M.: Detection and prevention of spam over internet telephony in voice over internet protocol networks using Markov chain with incremental SVM. Int. J. Commun. Syst. 30(11) (2017)
12.
Zurück zum Zitat Voznak, M., Rezac, F.: The implementation of SPAM over Internet telephony and a defence against this attack. In: TSP 2009: 32nd International Conference on Telecommunications and Signal Processing, pp. 200–203 (2009) Voznak, M., Rezac, F.: The implementation of SPAM over Internet telephony and a defence against this attack. In: TSP 2009: 32nd International Conference on Telecommunications and Signal Processing, pp. 200–203 (2009)
Metadaten
Titel
Development of a Distributed VoIP Honeypot System with Advanced Malicious Traffic Detection
verfasst von
Ladislav Behan
Lukas Sevcik
Miroslav Voznak
Copyright-Jahr
2020
DOI
https://doi.org/10.1007/978-3-030-14907-9_40

Neuer Inhalt