TY - GEN
T1 - Exploiting SIP for botnet communication
AU - Berger, Andreas
AU - Hefeeda, Mohamed
PY - 2009/10/13
Y1 - 2009/10/13
N2 - The Session Initiation Protocol (SIP) implements methods for generic service discovery and versatile messaging. It is, therefore, expected to be a key component in many telecommunication and Internet services. For example, the 3GPP IP Multimedia Subsystem relies heavily on SIP. Given its critical role, ensuring the security of SIP is clearly a crucial task. In this paper, we analyze the SIP protocol and show that it can easily be exploited to mount effective and large-scale botnets. We do this by scrutinizing the details of the SIP protocol and show how it offers a variety of ways to conceal botnet traffic within legitimate-looking SIP traffic. Using our analysis, we implement a SIP bot and present experimental results from a real testbed network. In addition, we employ traffic statistics collected from a large telecommunication provider and discuss the implications for both botnet design and detection. Finally, we present a software tool (called autosip) to generate synthetic traffic that resembles actual SIP traffic with different controllable characteristics. The proposed tool is quite useful for researchers working in the area who may not have access to traffic dumps from actual telecommunication providers.
AB - The Session Initiation Protocol (SIP) implements methods for generic service discovery and versatile messaging. It is, therefore, expected to be a key component in many telecommunication and Internet services. For example, the 3GPP IP Multimedia Subsystem relies heavily on SIP. Given its critical role, ensuring the security of SIP is clearly a crucial task. In this paper, we analyze the SIP protocol and show that it can easily be exploited to mount effective and large-scale botnets. We do this by scrutinizing the details of the SIP protocol and show how it offers a variety of ways to conceal botnet traffic within legitimate-looking SIP traffic. Using our analysis, we implement a SIP bot and present experimental results from a real testbed network. In addition, we employ traffic statistics collected from a large telecommunication provider and discuss the implications for both botnet design and detection. Finally, we present a software tool (called autosip) to generate synthetic traffic that resembles actual SIP traffic with different controllable characteristics. The proposed tool is quite useful for researchers working in the area who may not have access to traffic dumps from actual telecommunication providers.
UR - https://www.scopus.com/pages/publications/74549211386
U2 - 10.1109/NPSEC.2009.5342244
DO - 10.1109/NPSEC.2009.5342244
M3 - Conference contribution
AN - SCOPUS:74549211386
SN - 9781424448654
T3 - 5th IEEE Workshop on Secure Network Protocols, NPSEC'09
SP - 31
EP - 36
BT - 5th IEEE Workshop on Secure Network Protocols, NPSEC'09
T2 - 5th IEEE Workshop on Secure Network Protocols, NPSEC'09
Y2 - 13 October 2009 through 13 October 2009
ER -