Your browser does not support JavaScript!

Home    Robust prevention of Dial attacks  

Results - Details

Add to Basket
[Add to Basket]
Identifier 000358770
Title Robust prevention of Dial attacks
Alternative Title Αποδοτική αντιμετώπιση επιθέσεων τύπου Dial
Author Καπραβέλος, Αλέξανδρος
Thesis advisor Μαρκάτος, Ευάγγελος
Abstract The way we communicate nowadays has changed due to the advancement of Voice Over IP (VoIP) technology, which has enabled the interconnection of the Internet and the telephone network as Internet users can call landline or mobile devices through VoIP services. ALthough, this technology has many advantages and has been widely deployed, there are security concerns that yet have to be examined. The focus of this work is to explore the security properties that arise from making accesible telephone devices from the Internet through the use of VoIP. We carry out attacks using Internet services that aim to keep telephone devices busy, hindering legitimate callers drom gaining access. We use the term DIAL (Digitally Initiated Abuse of teLephones), or, in the simple form, Dial attack, to refer to this behavior. We develop a simulation environment for modeling a Dial attack in order to quantify its full potential and measure the effect of attack parameters. Based on the simualtion's results we perform the attack in the real-world. By using a Voice over IP (VoIP) provider as the attack medium, we manage to hold an existing landline device busy for 85% of the attack duration by issuing only 3 calls per second and, thus, render the device unusable. The attack has zero financial cost, requires negligible computational resources and cannot be traced back to tha attacker. Furthermore, the nature of the attack is such that anyone can launch a Dial attack towards any telephone device. Our investigation of existing countermeasures in VoIP providers shows that they follow an all-or-nothing approach, but mist importantly, that their anomaly detection systems react slowly against our attacks, as we managed to issue tens of thousands of calls before getting spotted. To cope with this, we propose a flexible anomaly detection system for VoIP calls, which promotes fairness for callers. With our system in place it is hard for an adversary to keep the device busy for more than 5% of the duration of the attack. We also propose defenses on the client side, implemented as a fully functional call centre with the use of Phone CAPTACHs to defend against DIAL attacks.
Language English
Issue date 2010-07-16
Collection   School/Department--School of Sciences and Engineering--Department of Computer Science--Post-graduate theses
  Type of Work--Post-graduate theses
Views 478

Digital Documents
No preview available

Download document
View document
Views : 2