首页> 外文OA文献 >A method for forensic artifact collection, analysis and incident response in environments running Session Initiation Protocol (SIP) and Session Description protocol
【2h】

A method for forensic artifact collection, analysis and incident response in environments running Session Initiation Protocol (SIP) and Session Description protocol

机译:一种在运行会话初始协议(SIP)和会话描述协议的环境中进行取证工件收集,分析和事件响应的方法

摘要

In this paper, we perform an analysis of SIP, a popular voice over IP (VoIP) protocol and propose a framework for capturing and analysing volatile VoIP data in order to determine forensic readiness requirements for effectively udidentifying an attacker. The analysis was performed on real attack data and the findings were encouraging. It seems that if appropriate forensic readiness processes and controls are in place, a wealth of evidence can be obtained. The type of the end user equipment of the internal users, the private IP, the software that is used can help build a reliable baseline information database. On the other hand the private IP addresses of the potential attacker even during the presence of NAT services, as well as and the attack tools employed by the malicious parties are logged for further analysis.
机译:在本文中,我们对SIP(一种流行的IP语音(VoIP)协议)进行了分析,并提出了一种捕获和分析易失VoIP数据的框架,以确定法证准备要求,以有效地识别攻击者。对真实的攻击数据进行了分析,结果令人鼓舞。看来,如果适当的取证准备过程和控制措施到位,则可以获得大量证据。内部用户的最终用户设备,专用IP,所使用的软件的类型可以帮助构建可靠的基准信息数据库。另一方面,即使存在NAT服务时,潜在攻击者的私有IP地址以及恶意方使用的攻击工具也会被记录下来,以进行进一步分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号