Published January 1, 2017 | Version v1
Conference paper Open

Malicious Users Discrimination in Organized Attacks Using Structured Sparsity

  • 1. Bogazici Univ, Elect & Elect Engn, TR-34342 Istanbul, Turkey
  • 2. Bogazici Univ, Dept Comp Engn, TR-34342 Istanbul, Turkey

Description

Communication networks can be the targets of organized and distributed attacks such as flooding-type DDOS attack in which malicious users aim to cripple a network server or a network domain. For the attack to have a major effect on the network, malicious users must act in a coordinated and time correlated manner. For instance, the members of the flooding attack increase their message transmission rates rapidly but also synchronously. Even though detection and prevention of the flooding attacks are well studied at network and transport layers, the emergence and wide deployment of new systems such as VoIP (Voice over IP) have turned flooding attacks at the session layer into a new defense challenge. In this study a structured sparsity based group anomaly detection system is proposed that not only can detect synchronized attacks, but also identify the malicious groups from normal users by jointly estimating their members, structure, starting and end points. Although we mainly focus on security on SIP (Session Initiation Protocol) servers/proxies which are widely used for signaling in VoIP systems, the proposed scheme can be easily adapted for any type of communication network system at any layer.

Files

bib-a2ef2e40-d88d-4afa-a12b-e49836c1c4e7.txt

Files (179 Bytes)

Name Size Download all
md5:8e6f1f05f13b4745f7cc3eb9a0ea4cdd
179 Bytes Preview Download