Removing Ambiguities of IP Telephony Traffic Using Protocol Scrubbers

Network intrusion detection systems (NIDSs) face the serious challenge of attacks such as insertion and evasion attacks that are caused by ambiguous network traffic. Such ambiguity comes as a result of the nature of network traffic which includes protocol implementation variations and errors alongsi...

Full description

Bibliographic Details
Main Author: Bazara I. A. Barry
Format: Article
Language:English
Published: International Institute of Informatics and Cybernetics 2012-10-01
Series:Journal of Systemics, Cybernetics and Informatics
Subjects:
Online Access:http://www.iiisci.org/Journal/CV$/sci/pdfs/HZA344BP.pdf
_version_ 1818019376741220352
author Bazara I. A. Barry
author_facet Bazara I. A. Barry
author_sort Bazara I. A. Barry
collection DOAJ
description Network intrusion detection systems (NIDSs) face the serious challenge of attacks such as insertion and evasion attacks that are caused by ambiguous network traffic. Such ambiguity comes as a result of the nature of network traffic which includes protocol implementation variations and errors alongside legitimate network traffic. Moreover, attackers can intentionally introduce further ambiguities in the traffic. Consequently, NIDSs need to be aware of these ambiguities when detection is performed and make sure to differentiate between true attacks and protocol implementation variations or errors; otherwise, detection accuracy can be affected negatively. In this paper we present the design and implementation of tools that are called protocol scrubbers whose main functionality is to remove ambiguities from network traffic before it is presented to the NIDS. The proposed protocol scrubbers are designed for session initiation and data transfer protocols in IP telephony systems. They guarantee that the traffic presented to NIDSs is unambiguous by eliminating ambiguous behaviors of protocols using well-designed protocol state machines, and walking through packet headers of protocols to make sure packets will be interpreted in the desired way by the NIDS. The experimental results shown in this paper demonstrate the good quality and applicability of the introduced scrubbers.
first_indexed 2024-04-14T07:51:27Z
format Article
id doaj.art-0efac662a49a431aa3e8038ec5e9f06d
institution Directory Open Access Journal
issn 1690-4524
language English
last_indexed 2024-04-14T07:51:27Z
publishDate 2012-10-01
publisher International Institute of Informatics and Cybernetics
record_format Article
series Journal of Systemics, Cybernetics and Informatics
spelling doaj.art-0efac662a49a431aa3e8038ec5e9f06d2022-12-22T02:05:10ZengInternational Institute of Informatics and CyberneticsJournal of Systemics, Cybernetics and Informatics1690-45242012-10-011058591Removing Ambiguities of IP Telephony Traffic Using Protocol ScrubbersBazara I. A. Barry0 University of Khartoum Network intrusion detection systems (NIDSs) face the serious challenge of attacks such as insertion and evasion attacks that are caused by ambiguous network traffic. Such ambiguity comes as a result of the nature of network traffic which includes protocol implementation variations and errors alongside legitimate network traffic. Moreover, attackers can intentionally introduce further ambiguities in the traffic. Consequently, NIDSs need to be aware of these ambiguities when detection is performed and make sure to differentiate between true attacks and protocol implementation variations or errors; otherwise, detection accuracy can be affected negatively. In this paper we present the design and implementation of tools that are called protocol scrubbers whose main functionality is to remove ambiguities from network traffic before it is presented to the NIDS. The proposed protocol scrubbers are designed for session initiation and data transfer protocols in IP telephony systems. They guarantee that the traffic presented to NIDSs is unambiguous by eliminating ambiguous behaviors of protocols using well-designed protocol state machines, and walking through packet headers of protocols to make sure packets will be interpreted in the desired way by the NIDS. The experimental results shown in this paper demonstrate the good quality and applicability of the introduced scrubbers.http://www.iiisci.org/Journal/CV$/sci/pdfs/HZA344BP.pdf IP TelephonyProtocol ScrubbersprotocolssecurityIntrusion Detection Systems
spellingShingle Bazara I. A. Barry
Removing Ambiguities of IP Telephony Traffic Using Protocol Scrubbers
Journal of Systemics, Cybernetics and Informatics
IP Telephony
Protocol Scrubbers
protocols
security
Intrusion Detection Systems
title Removing Ambiguities of IP Telephony Traffic Using Protocol Scrubbers
title_full Removing Ambiguities of IP Telephony Traffic Using Protocol Scrubbers
title_fullStr Removing Ambiguities of IP Telephony Traffic Using Protocol Scrubbers
title_full_unstemmed Removing Ambiguities of IP Telephony Traffic Using Protocol Scrubbers
title_short Removing Ambiguities of IP Telephony Traffic Using Protocol Scrubbers
title_sort removing ambiguities of ip telephony traffic using protocol scrubbers
topic IP Telephony
Protocol Scrubbers
protocols
security
Intrusion Detection Systems
url http://www.iiisci.org/Journal/CV$/sci/pdfs/HZA344BP.pdf
work_keys_str_mv AT bazaraiabarry removingambiguitiesofiptelephonytrafficusingprotocolscrubbers