Published January 1, 2017
| Version v1
Conference paper
Open
Malicious Users Discrimination in Organized Attacks Using Structured Sparsity
- 1. Bogazici Univ, Elect & Elect Engn, TR-34342 Istanbul, Turkey
- 2. Bogazici Univ, Dept Comp Engn, TR-34342 Istanbul, Turkey
Description
Communication networks can be the targets of organized and distributed attacks such as flooding-type DDOS attack in which malicious users aim to cripple a network server or a network domain. For the attack to have a major effect on the network, malicious users must act in a coordinated and time correlated manner. For instance, the members of the flooding attack increase their message transmission rates rapidly but also synchronously. Even though detection and prevention of the flooding attacks are well studied at network and transport layers, the emergence and wide deployment of new systems such as VoIP (Voice over IP) have turned flooding attacks at the session layer into a new defense challenge. In this study a structured sparsity based group anomaly detection system is proposed that not only can detect synchronized attacks, but also identify the malicious groups from normal users by jointly estimating their members, structure, starting and end points. Although we mainly focus on security on SIP (Session Initiation Protocol) servers/proxies which are widely used for signaling in VoIP systems, the proposed scheme can be easily adapted for any type of communication network system at any layer.
Files
bib-a2ef2e40-d88d-4afa-a12b-e49836c1c4e7.txt
Files
(179 Bytes)
| Name | Size | Download all |
|---|---|---|
|
md5:8e6f1f05f13b4745f7cc3eb9a0ea4cdd
|
179 Bytes | Preview Download |