A SIP DoS Flooding Attack Defense Mechanism based on Priority Class Queue
This paper focuses on the research of defense mechanism of DoS (denial of service) attacks in SIP network. An M/M/1/K queue analysis model based on queue theory is proposed to analyze the SIP DoS attack firstly. Then, a DoS attack defense mechanism is proposed in order to alleviate SIP server’s influence by INVITE flooding attack. In our defense mechanism, the priority queue is introduced in SIP server’s message processing. At last, simulation is taken to analyze the performance of the defense mechanism proposed in this paper. The simulation results proves that SIP DoS flooding attack defense mechanism not only prolongs the serving time of SIP server correctly, but also realizes the aim of differentiating legitimate SIP message from attack flow.
SIP DoS attack Flooding Queuing Model Defense Mechanism
Wan Xiao-Yu Zhang Li Fan Zi-Fu
Next Generation Network Application Technology Institute, Chongqing University of Posts and Telecommunications??Chongqing 400065, China
国际会议
北京
英文
1-4
2010-06-25(万方平台首次上网日期,不代表论文的发表时间)