Method and device for detecting incomplete session attack
A complete and session establishment technology, applied in the field of communication, can solve the problem of incomplete session attack protection, firewall devices unable to effectively detect SIP-based incomplete session attacks, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0044] This embodiment is aimed at registered users, and the processing flow of a method for detecting a SIP-based incomplete session attack provided by this embodiment is as follows: figure 1 As shown, the following processing steps are included:
[0045] Step 11, set the detection cycle of incomplete session attack, obtain the number of initial session requests and the received The number of responses that successfully established the session.
[0046] SIP-based incomplete session attacks have relatively small attack traffic, and each independent session cannot be successfully established; the status and resources of the communication peer device of the session will remain until the session ends due to timeout, cancellation or rejection, etc. , the status and resources of the communication peer device of the session can only be released, and the resource consumption time is relatively long.
[0047] In the embodiment of the present invention, firstly, a detection period of a...
Embodiment 2
[0083] Because in the case that the user is not registered, it is impossible to refer to the "source IP + source port" method to identify the request initiated by a single user (it can be initiated actively or requested, and will not be described in detail below), nor can it be based on the user's request. The IMS service subscription data identifies the user. According to the above analysis, only on the SIP access server, such as PCSCF (Proxy Call Server Control Function, proxy session control function), the SIP registration request in a specific user access network segment can be counted.
[0084] Set an incomplete session attack detection period, and perform statistics on the following two values for a specific user access network segment:
[0085] session_setup_initial_request[n]: the number of session initial requests actively initiated by a specific user access network segment in the nth detection cycle;
[0086] session_setup_final_response[n]: The number of response...
Embodiment 3
[0091] The processing flow of the method for detecting the SIP-based incomplete session attack proposed by this embodiment is as follows: figure 2 As shown, the following processing steps are included:
[0092] Step 21, counting the total number of sessions initiated by registered users in the "session establishment state".
[0093] Perform dynamic statistics on each session initiated by a registered user (it can be initiated actively or requested to be initiated, and will not be described in detail below), and the status of each session is determined. According to the predetermined statistical period, the total number of sessions in the "session establishment state" is counted regularly.
[0094] The session in the above session establishment state includes: the session that has been initiated by the user, has not been successfully established, and has not exited due to timeout, cancellation, rejection, etc.;
[0095] Step 22, judging whether the total number of sessions i...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 