{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T01:02:36Z","timestamp":1769043756740,"version":"3.49.0"},"reference-count":22,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2022,2,17]],"date-time":"2022-02-17T00:00:00Z","timestamp":1645056000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001871","name":"Funda\u00e7\u00e3o para a Ci\u00eancia e Tecnologia","doi-asserted-by":"publisher","award":["UIDB\/50008\/2020"],"award-info":[{"award-number":["UIDB\/50008\/2020"]}],"id":[{"id":"10.13039\/501100001871","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001871","name":"Funda\u00e7\u00e3o para a Ci\u00eancia e Tecnologia","doi-asserted-by":"publisher","award":["PTDC\/EEI-TEL\/30433\/2017"],"award-info":[{"award-number":["PTDC\/EEI-TEL\/30433\/2017"]}],"id":[{"id":"10.13039\/501100001871","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001871","name":"Funda\u00e7\u00e3o para a Ci\u00eancia e a Tecnologia","doi-asserted-by":"publisher","award":["PRT\/BD\/152200\/2021"],"award-info":[{"award-number":["PRT\/BD\/152200\/2021"]}],"id":[{"id":"10.13039\/501100001871","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>This paper investigates the detection of abnormal sequences of signaling packets purposely generated to perpetuate signaling-based attacks in computer networks. The problem is studied for the Session Initiation Protocol (SIP) using a dataset of signaling packets exchanged by multiple end-users. A sequence of SIP messages never observed before can indicate possible exploitation of a vulnerability and its detection or prediction is of high importance to avoid security attacks due to unknown abnormal SIP dialogs. The paper starts to briefly characterize the adopted dataset and introduces multiple definitions to detail how the deep learning-based approach is adopted to detect possible attacks. The proposed solution is based on a convolutional neural network capable of exploring the definition of an orthogonal space representing the SIP dialogs. The space is then used to train the neural network model to classify the type of SIP dialog according to a sequence of SIP packets prior observed. The classifier of unknown SIP dialogs relies on the statistical properties of the supervised learning of known SIP dialogs. Experimental results are presented to assess the solution in terms of SIP dialogs prediction, unknown SIP dialogs detection, and computational performance, demonstrating the usefulness of the proposed methodology to rapidly detect signaling-based attacks.<\/jats:p>","DOI":"10.3390\/computers11020027","type":"journal-article","created":{"date-parts":[[2022,2,17]],"date-time":"2022-02-17T20:24:26Z","timestamp":1645129466000},"page":"27","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Detection of Abnormal SIP Signaling Patterns: A Deep Learning Comparison"],"prefix":"10.3390","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7555-8194","authenticated-orcid":false,"given":"Diogo","family":"Pereira","sequence":"first","affiliation":[{"name":"Departamento de Engenharia Electrot\u00e9cnica e de Computadores, Faculdade de Ci\u00eancias e Tecnologia, FCT\/UNL, Universidade Nova de Lisboa, 2829-516 Caparica, Portugal"},{"name":"Instituto de Telecomunicacoes, 1049-001 Lisbon, Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9181-8438","authenticated-orcid":false,"given":"Rodolfo","family":"Oliveira","sequence":"additional","affiliation":[{"name":"Departamento de Engenharia Electrot\u00e9cnica e de Computadores, Faculdade de Ci\u00eancias e Tecnologia, FCT\/UNL, Universidade Nova de Lisboa, 2829-516 Caparica, Portugal"},{"name":"Instituto de Telecomunicacoes, 1049-001 Lisbon, Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,2,17]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Rosenberg, J., Schulzrinne, H., Camarillo, G., Johnston, A., Peterson, J., Sparks, R., Handley, M., and Schooler, E. (2002). SIP: Session Initiation Protocol, Available online: https:\/\/www.hjp.at\/doc\/rfc\/rfc3261.html.","DOI":"10.17487\/rfc3261"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Uzelac, A., and Lee, Y. (2011). Voice over IP (VoIP) SIP Peering Use Cases, Available online: https:\/\/www.hjp.at\/doc\/rfc\/rfc6405.html.","DOI":"10.17487\/rfc6405"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1109\/MIC.2008.57","article-title":"IMS Application Servers: Roles, Requirements, and Implementation Technologies","volume":"12","author":"Khlifi","year":"2008","journal-title":"IEEE Internet Comput."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1109\/MCOM.2012.6231286","article-title":"A SIP-SHIM6-based solution providing interdomain service continuity in IMS-based networks","volume":"50","author":"Achour","year":"2012","journal-title":"IEEE Commun. Mag."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/MNET.2006.1705880","article-title":"Denial of service attacks targeting a SIP VoIP infrastructure: Attack scenarios and prevention mechanisms","volume":"20","author":"Sisalem","year":"2006","journal-title":"IEEE Netw."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1109\/COMST.2006.253270","article-title":"Survey of security vulnerabilities in session initiation protocol","volume":"8","author":"Geneiatakis","year":"2006","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Camarinha-Matos, L.M., Ferreira, P., and Brito, G. (2021). Detection of Signaling Vulnerabilities in Session Initiation Protocol, Springer International Publishing. Technological Innovation for Applied AI, Systems.","DOI":"10.1007\/978-3-030-78288-7"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Griffioen, H., Hu, H., and Doerr, C. (2021, January 21\u201324). SIP Bruteforcing in the Wild\u2014An Assessment of Adversaries, Techniques and Tools. Proceedings of the 2021 IFIP Networking Conference (IFIP Networking), Espoo, Finland.","DOI":"10.23919\/IFIPNetworking52078.2021.9472857"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Kanoune, Y., Yahiaoui, C., and Rachedi, A. (2020, January 7\u201311). Toward an Approach for Securing IMS Signaling and Media Planes. Proceedings of the GLOBECOM 2020\u20142020 IEEE Global Communications Conference, Taipei, Taiwan.","DOI":"10.1109\/GLOBECOM42002.2020.9322191"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Gupta, M.K., Kumar, R., and Kumari, S. (2020, January 4\u20135). Flaws and Amendment in an ECC-based Authentication Scheme for SIP. Proceedings of the 2020 9th International Conference System Modeling and Advancement in Research Trends (SMART), Moradabad, India.","DOI":"10.1109\/SMART50582.2020.9336790"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Abubakar, M., Jaroucheh, Z., Al Dubai, A., and Buchanan, B. (2021, January 12\u201314). Blockchain-Based Authentication and Registration Mechanism for SIP-Based VoIP Systems. Proceedings of the 2021 5th Cyber Security in Networking Conference (CSNet), Abu Dhabi, United Arab Emirates.","DOI":"10.1109\/CSNet52717.2021.9614646"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"112574","DOI":"10.1109\/ACCESS.2020.3001688","article-title":"A Novel SIP Based Distributed Reflection Denial-of-Service Attack and an Effective Defense Mechanism","volume":"8","author":"Tas","year":"2020","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"137","DOI":"10.1016\/j.comnet.2018.02.025","article-title":"An intelligent cyber security system against DDoS attacks in SIP networks","volume":"136","author":"Semerci","year":"2018","journal-title":"Comput. Netw."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Nazih, W., Hifny, Y., Elkilani, W.S., Dhahri, H., and Abdelkader, T. (2020). Countering DDoS Attacks in SIP Based VoIP Networks Using Recurrent Neural Networks. Sensors, 20.","DOI":"10.3390\/s20205875"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1016\/j.dsp.2017.10.009","article-title":"A Bayesian change point model for detecting SIP-based DDoS attacks","volume":"77","author":"Kurt","year":"2018","journal-title":"Digit. Signal Process."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"44094","DOI":"10.1109\/ACCESS.2021.3065660","article-title":"A Machine Learning Approach for Prediction of Signaling SIP Dialogs","volume":"9","author":"Pereira","year":"2021","journal-title":"IEEE Access"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Hentehzadeh, N., Mehta, A., Gurbani, V.K., Gupta, L., Ho, T.K., and Wilathgamuwa, G. (2011, January 7\u201310). Statistical Analysis of Self-Similar Session Initiation Protocol (SIP) Messages for Anomaly Detection. Proceedings of the 2011 4th IFIP International Conference on New Technologies, Mobility and Security, Paris, France.","DOI":"10.1109\/NTMS.2011.5720662"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"2401","DOI":"10.1109\/ACCESS.2018.2886356","article-title":"The Devil is in the Detail: SDP-Driven Malformed Message Attacks and Mitigation in SIP Ecosystems","volume":"7","author":"Tsiatsikas","year":"2019","journal-title":"IEEE Acces"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/TNSM.2012.011812.110125","article-title":"A Framework for Automated Exploit Prevention from Known Vulnerabilities in Voice over IP Services","volume":"9","author":"Lahmadi","year":"2012","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"730","DOI":"10.1109\/TIFS.2016.2632071","article-title":"Detecting Anomalous Behavior in VoIP Systems: A Discrete Event System Modeling","volume":"12","author":"Golait","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_21","unstructured":"Harris, D., and Harris, S. (2012). Digital Design and Computer Architecture, Morgan Kaufmann Publishers Inc.. [2nd ed.]."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Nassar, M., and Festor, O. (2010). Labeled voip data-set for intrusion detection evaluation. Meeting of the European Network of Universities and Companies in Information and Communication Engineering, Springer.","DOI":"10.1007\/978-3-642-13971-0_10"}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/11\/2\/27\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:21:31Z","timestamp":1760134891000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/11\/2\/27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,17]]},"references-count":22,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2022,2]]}},"alternative-id":["computers11020027"],"URL":"https:\/\/doi.org\/10.3390\/computers11020027","relation":{},"ISSN":["2073-431X"],"issn-type":[{"value":"2073-431X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,2,17]]}}}