A Review on Detecting an Attackers In VoIP Using Honeypot |
Author(s): |
| Kurhade Supriya B. , JCOE,Kuran; Palwe chaitali B., JCOE,kuran; Pande Priyanka R., JCOE,Kuran |
Keywords: |
| VOIP, Honeypot |
Abstract |
|
The number of users of VoIP services is increasing every year. Basically, VoIP systems are more attractive for attackers. This paper describes the implementation of a low interaction honeypot for monitoring illegal activities in VoIP environments. The honeypot operated during 92 days and collected 3502 events related to the SIP protocol. The analysis of the results allows understanding the modus operandi of the attacks targeted to VoIP infrastructures. These results may be used to improve defence mechanisms like firewalls and intrusion detection systems. SIP is one of the major VoIP protocols and has its architecture composed of four basic elements: user agent, SIP proxy, redirect server and registry server. The user agent (UA) is a logical function that matches the architecture of the client. It is responsible for initiating or replying to SIP transactions and can act as both client (UAC) and as a server (UAS), starting SIP requests and SIP responses accepting, or accepting SIP requests and answering them, respectively. There are few implementations on VoIP security and attacks in real-world VoIP systems. Some of them propose the use of honeypots to catch malicious traffic in a VoIP environment. Honeypots can be defined as a computational resource to be probed, attacked and / or compromised, whose value lies precisely in the unauthorized or illegal use of the resources offered. |
Other Details |
|
Paper ID: IJSRDV3I80394 Published in: Volume : 3, Issue : 8 Publication Date: 01/11/2015 Page(s): 730-735 |
Article Preview |
|
|
|
|
