Gestion des risques dans les infrastructures VoIP

Abstract : IP telephony has become a new paradigm that permits to establish and transmit voice communications with IP networks. Its deployment has been accelerated by the standardization of dedicated signaling protocols. However, VoIP services are faced to several security issues which are inherited from the IP layer or specific to the service. A large variety of protection mechanisms are available to deal with them. However, IP telephony is a real-time service which requires high network performance. The application of countermeasures may significantly affect such a critical service. Risk management provides new perspectives for this issue. This thesis deals with the application of risk management in VoIP infrastructures. The first axis consists in the automation of the risk management process in VoIP enterprise network. In this context, we have developed a mathematical model for assessing risk, a set of progressive countermeasures to counter attackers and mitigation algorithms that evaluate the risk level and takes the decision to activate a subset of countermeasures. To improve our strategy, we have coupled it with an anomaly detection system based on SVM and a self-configuration mechanism which provides feedback about countermeasure efficiency. The second axis deals with the extension of our adaptive risk strategy to P2PSIP infrastructures. We have implemented a specific risk model and a dedicated set of countermeasures with respect to its peer-to-peer nature. For that, we have identified attack sources and established different threat scenarios. We have analyzed the RELOAD framework and proposed trust mechanisms to address its residual attacks. Finally, the third axis focuses on VoIP services in the cloud where we have proposed a risk strategy and several strategies to deploy and apply countermeasures
Document type :
Theses
Complete list of metadatas

Cited literature [107 references]  Display  Hide  Download

https://hal.univ-lorraine.fr/tel-01749575
Contributor : Thèses Ul <>
Submitted on : Thursday, March 29, 2018 - 12:20:09 PM
Last modification on : Thursday, May 31, 2018 - 12:30:50 PM
Long-term archiving on : Friday, September 14, 2018 - 8:10:14 AM

File

DDOC_T_2013_0044_DABBEBI.pdf
Files produced by the author(s)

Identifiers

  • HAL Id : tel-01749575, version 1

Citation

Oussema Dabbebi. Gestion des risques dans les infrastructures VoIP. Autre [cs.OH]. Université de Lorraine, 2013. Français. ⟨NNT : 2013LORR0044⟩. ⟨tel-01749575v1⟩

Share

Metrics

Record views

10

Files downloads

7