Conference

Authors: Tsiatsikas Z., Geneiatakis D., Kambourakis G., Keromytis A.
Title: Privacy-Preserving Entropy-Driven Framework for Tracing DoS Attacks in VoIP
Conference: The 8th International Conference on Availability, Reliability and Security (ARES)
Editors:
Ed: No
Eds: No
Pages: 224-229
To appear: No
Month: September
Year: 2013
Place: Regensburg, Germany
Pubisher: IEEE Press
Link: http://ieeexplore.ieee.org/xpl/login.jsp?tp=&arnumber=6657244&url=http%3A%2F%2Fieeexplore.ieee.org%2Fxpls%2Fabs_all.jsp%3Farnumber%3D6657244
File name: entropy.pdf##^^&&449261028.pdf
Abstract: Network audit trails, especially those composed of application layer data, can be a valuable source of information regarding the investigation of attack incidents. Nevertheless, the analysis of log files of large volume is usually both complex (slow) and privacy-neglecting. Especially, when it comes to VoIP, the literature on how audit trails can be exploited to identify attacks remains scarce. This paper provides an entropy-driven, privacy-preserving, and practical framework for detecting resource consumption attacks in VoIP ecosystems. We extensively evaluate our framework under various attack scenarios involving single and multiple assailants. The results obtained show that the proposed scheme is capable of identifying malicious traffic with a false positive alarm rate up to 3.5%.