Please use this identifier to cite or link to this item: https://repository.cihe.edu.hk/jspui/handle/cihe/1382
DC FieldValueLanguage
dc.contributor.authorChan, Anthony Hing-Hungen_US
dc.contributor.otherBarry, B. I. A.-
dc.date.accessioned2021-08-24T01:26:58Z-
dc.date.available2021-08-24T01:26:58Z-
dc.date.issued2008-
dc.identifier.urihttps://repository.cihe.edu.hk/jspui/handle/cihe/1382-
dc.description.abstractVoice over IP (VoIP) environments pose challenging threats to Intrusion Detection Systems (IDSs). Services over VoIP systems are provided by multiple interacting protocols, each with its own vulnerabilities. This scheme could result in novel and more complex attacks, and requires cross-protocol aware IDSs. Furthermore, VoIP devices may suffer a full or partial service loss if the syntax or semantics of the aforementioned protocols are violated. Usually, a single detection approach is suited to identify a subset of the security violations to which a system is subject in VoIP environments. Therefore, a hybrid approach that combines the strengths and avoids the weaknesses of various approaches is needed. In this paper, we discuss the performance and the detection accuracy of a hybrid, host-based intrusion detection system suitable for VoIP environments. Our system has two combined detection modules, namely, a specification-based and a signature-based module. Both modules use State Machines and State Transition Analysis Techniques to model proper protocols' behaviors and potential attacks. Both modules address the issues related to syntax and semantics anomaly detection for the monitored protocols. In addition, our architecture provides a cross-protocol framework for various protocols to exchange useful detection information in real time. We implement our proposed architecture in a network simulator, alongside implementing a variety of attacks to test the credibility of the design. The implemented IDS shows an excellent detection accuracy, and low runtime impact on the performance of the VoIP system.en_US
dc.language.isoenen_US
dc.publisherAssociation for Computing Machineryen_US
dc.titleOn the performance of a hybrid intrusion detection architecture for voice over IP systemsen_US
dc.typeconference proceedingsen_US
dc.relation.publicationProceedings of the 4th International Conference on Security and Privacy in Communication Networks (SecureComm 2008)en_US
dc.identifier.doi10.1145/1460877.1460902-
dc.contributor.affiliationSchool of Computing and Information Sciencesen_US
dc.relation.isbn9781605582412en_US
dc.cihe.affiliatedNo-
item.openairecristypehttp://purl.org/coar/resource_type/c_5794-
item.cerifentitytypePublications-
item.grantfulltextopen-
item.languageiso639-1en-
item.openairetypeconference proceedings-
item.fulltextWith Fulltext-
crisitem.author.deptSchool of Computing and Information Sciences-
crisitem.author.orcid0000-0001-7479-0787-
Appears in Collections:CIS Publication
Files in This Item:
File Description SizeFormat
View Online126 BHTMLView/Open
SFX Query Show simple item record

Google ScholarTM

Check

Altmetric

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.