Secure Service Provisioning (SSP) framework for IP Multimedia Subsystem (IMS)

نویسنده

  • Muhammad Sher
چکیده

v Abstract With the emergence of mobile multimedia services, such as unified messaging, click to dial, cross network multiparty conferencing and seamless multimedia streaming services, the fixed–mobile convergence and voice–data integration has started, leading to an overall Internet–Telecommunications merger. The IP Multimedia Subsystem (IMS) is considered as the next generation service delivery platform in the converged communication world. It consists of modular design with open interfaces and enables the flexibility for providing multimedia services over IP technology. In parallel this open based emerging technology has security challenges from multiple communication platforms and protocols like IP, Session Initiation Protocol (SIP) and Real-time Transport Protocol (RTP). The objective of Secure Service Provisioning (SSP) Framework is to cram the potential attacks and security threats to IP Multimedia Subsystem (IMS) and to explore security solutions developed by IETF, 3GPP and TISPAN. This research work incorporates these solutions into SSP Framework to secure IMS and next generation Service Delivery Platform (SDP). We define this part as level 1 security protection which includes user and network authentication, authorization to access multimedia services, providing confidentiality and integrity protection etc. against eavesdropping, session hijacking and man-in-the middle attacks etc. In the next step, we have investigated the limitations and improvements to level 1 security and proposed the enhancement and extension as level 2 security by developing Intrusion Detection and Prevention (IDP) system against Denial-of-Service (DoS)/Distributed DoS (DDoS) flooding attacks, misuses and frauds in IMS-based networks. These security threats recently have been identified by 3GPP and TISPAN but no solution is recommended and developed. Therefore our solution may be considered as recommendation in future. Our approach based on developing both stateless and stateful intrusion detection and prevention system. From development point of view, we have divided the work into two modules: the first module is IDP-Core; addressing and mitigating the flooding attacks in IMS core. Its objective is to protect the IMS resources and IMS-core entities from DoS/DDoS flooding attacks. This module based on online stateless detection methodology and activates when CPU processing load of P-CSCF (Proxy-Call State Control Function) reaches or crosses the defined threshold limit. The second module is IDP-AS; addressing and mitigating the misuse attacks facing to IMS Application Servers (AS). Its focus is to secure the ISC interface between IMS Core and Application Servers. This module is based on stateful misuse detection methodology by creating and comparing user state (partner) when he/she is communicating with …

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Security Threats and Solutions for Application Server of IP Multimedia Subsystem (IMS-AS)

In this paper we will explore security threats and attacks possibility and security solution for Application Server of IP Multimedia Subsystem(IMS-AS). The SIP Application Server is an important entity of IP Multimedia Subsystem (IMS) because applications providing value added services are deployed on the Application Server. The SIP Application Server is triggered by Serving Call State Control ...

متن کامل

IP Multimedia Subsystems (IMS)

IP multimedia subsystem (IMS) represents a standardized next-generation reference system to provide an overlay global open service delivery platform (SDP) that enables provisioning of converged multimedia

متن کامل

QoS Framework for SIP Signalling

The Session Initiation Protocol (SIP) is widely accepted as the IETF alternative the ITU-T H.323 teleconferencing protocol to enable call and media session management and control. It is also used in carrier grade environments, such as the IP Multimedia Subsystem (IMS) of the 3rd Generation Partnership Project (3GPP) in emerging Universal Mobile Telecommunications System (UMTS) networks. This pa...

متن کامل

Fuzzy Logic for QoS Control in IMS network

The nature of the services provided by IP Multimedia Subsystem (IMS) networks require a maximum quality, this will appear in service provisioning for differentiate between the added value of IMS and other classical case as well as Internet. Toward, the QoS management mechanisms focus primarily on resource reservation in service provisioning, all this specification are introduced by 3GPP standar...

متن کامل

Design and Implementation of an IP Multimedia Subsystem (IMS) Emulator Using Virtualization Techniques

Multimedia service provisioning in Packet-Switched networks is one of the most active research and standardization efforts nowadays, and constitutes the most likely evolution of current telecommunication networks. In this environment, the 3GPP IP Multimedia Subsystem (IMS) represents the service provisioning platform of choice for SIP-based content delivery in mobile and fixed environments. How...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007