首页> 外文学位 >Securing public and IP telephone networks.
【24h】

Securing public and IP telephone networks.

机译:保护公共和IP电话网络。

获取原文
获取原文并翻译 | 示例

摘要

The Signaling System 7 (SS7) is the control network used by public telephones all over the world. Having been designed in an era in which few large telephone companies controlled an entire network, SS7 was designed with no security in mind. Due to telecommunications deregulation, liberalization of economies, and the convergence of telephone, IP, and wireless networks, the number of interfaces to SS7 has increased. New players in the market and numerous entry points between SS7 and other networks have brought many vulnerabilities. Today, anyone capable of introducing messages into the SS7 network can bring down telephone services. As a solution, I propose MTPSec, which is a framework that enforces authentication and custom creates secure channels at the message transfer protocol (MTP3) layer. MTP3 is comparable to the IP layer of the OSI model, and hence this proposal could serve as the IPSec of the telecommunications world. It is shown by simulation that employing MTPSec, adds only 360 museconds to an average call's setup time delays for a domestic telephone call in an average-sized country. This delay is tolerable for the additional security service it provides.; At the interface of SS7 and the IP network, the inter-signaling between the IP and SS7 network can be exploited from either side to disrupt the services provided on the other side. I show how this can be done and propose a solution based on access control, signal screening, and detection of anomalous signaling. To be an effective solution, the latter two methods consider syntactic correctness, semantic validity of the signal content, and appropriateness of a particular signal in the context of earlier exchanged messages.; IP telephony (i.e., Voice over Internet Protocol [VoIP]) shares network resources with regular Internet traffic and therefore is susceptible to the existing security holes of the Internet. Moreover, given that voice communication is time sensitive and uses a suite of interacting protocols, VoIP exposes new forms of vulnerabilities to attacks. I propose a VoIP Intrusion Detection System (vIDS) that uses state machines of network protocols and interactions among them for conducting intrusion detection. This approach is particularly suited for protecting VoIP applications that use many protocols. The experimental results demonstrate that on average the online placement of vIDS induces the additional delay of ≃ 100 ms to call setup time. The average increase of CPU overhead induced by vIDS is only 3.6%.; I also propose and implement a VoIP Flood Detection System (vFDS), which is an online, statistical anomaly detection framework that generates alerts based on abnormal variations in a selected hybrid collection of traffic flows. It views collections of related packet streams as evolving probability distributions and measures abnormal variations in their relationships using the Hellinger distance. Experimental results demonstrated that vFDS is fast and accurate in detecting flooding attacks without noticeably increasing call setup times or introducing jitter into voice streams.
机译:信令系统7(SS7)是全世界公用电话使用的控制网络。在一个几乎没有大型电话公司控制整个网络的时代进行设计之后,SS7的设计就没有考虑安全性。由于电信放松管制,经济自由化以及电话,IP和无线网络的融合,SS7的接口数量增加了。市场上的新参与者以及SS7与其他网络之间的众多入口点带来了许多漏洞。今天,任何能够将消息引入SS7网络的人都可以关闭电话服务。作为解决方案,我提出了MTPSec,它是一个在消息传输协议(MTP3)层上执行身份验证和自定义创建安全通道的框架。 MTP3可与OSI模型的IP层相提并论,因此该建议可以用作电信界的IPSec。通过仿真显示,对于中等规模国家/地区的国内电话,采用MTPSec只会使平均呼叫的建立时间延迟增加360毫秒。它提供的附加安全服务可以容忍此延迟。在SS7和IP网络的接口处,可以从任一侧利用IP和SS7网络之间的相互信号来破坏另一侧提供的服务。我展示了如何做到这一点,并提出了一种基于访问控制,信号筛选和异常信号检测的解决方案。作为一种有效的解决方案,后两种方法考虑了语法正确性,信号内容的语义有效性以及在较早交换的消息中特定信号的适当性。 IP电话(即,互联网协议语音[VoIP])与常规的互联网业务共享网络资源,因此容易受到互联网现有安全漏洞的影响。此外,鉴于语音通信对时间敏感并且使用一套交互协议,因此VoIP向攻击暴露了新形式的漏洞。我提出了一种VoIP入侵检测系统(vIDS),该系统使用网络协议的状态机以及它们之间的交互来进行入侵检测。此方法特别适用于保护使用许多协议的VoIP应用程序。实验结果表明,平均而言,vIDS的在线放置会引起≃的额外延迟。 100 ms呼叫建立时间。 vIDS导致的CPU开销平均增加仅为3.6%。我还提出并实现了VoIP洪水检测系统(vFDS),这是一种在线统计异常检测框架,可根据选定的混合流量集合中的异常变化生成警报。它将相关数据包流的集合视为不断演变的概率分布,并使用Hellinger距离测量其关系中的异常变化。实验结果表明,vFDS在检测洪泛攻击方面快速而准确,而不会显着增加呼叫建立时间或在语音流中引入抖动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号