Home / Computer Science / Securing the calea architecture against denial of service attacks

Securing the calea architecture against denial of service attacks

 

Table Of Contents


<p> </p><p><br>&nbsp;Page</p><p>ABSTRACT 3</p><p>ACKNOWLEDGEMENT 5</p><p>PERMISSION SHEET 6</p><p>APPROVAL SHEET 7</p><p>DECLARATION 8</p><p>LIST OF TABLES 9</p><p>LIST OF FIGURES 10</p><p>LIST OF ABBREVIATIONS/NOTATION/GLOSSARY OF TERMS 11</p><p><b>Chapter</b></p><p><b>1 INTRODUCTION- – – – – – – – – – – – – – – .12</b></p><p><b>2 LITRITURE REVIEW- – – – – – – – – – – – – – – 15</b></p><p>2.1 Call Data Channel(CDC) Resource Exhaustion- – – – – – – – – – 15</p><p>2.1.1 ISDN Feature Keys- – – – – – – – – – – – ..17</p><p>2.1.2 SMS Messaging – – – – – – – – – – – – – – 17</p><p>2.1.3 VoIP Signaling- – – – – – – – – – – – – – .18</p><p>2.1.4 IP Flow- – – – – – – – – – – – – – .19</p><p>2.2 Inbound Attacks- – – – – – – – – – – – – – .19</p><p>2.3 Injecting Uncertainty into Packet Traces- – – – – – – – – – – 19</p><p>2.3.1 Confusion- – – – – – – – – – – – – – – 19</p><p>2.3.2 Subject-Oriented cdma2000 Timestamps – – – – – – – – – – 20</p><p>2.3.3 Loss of cdam2000 Direction Information – – – – – – – – – – 20</p><p>2.4 In-band Signaling within Service Provider- – – – – – – – – – 20</p><p>2.5 Alternatives Methods to Secure the CALEA Architecture – – – – – – – 20</p><p>2.5.1 Passive Provisioning with DOW [method 1]- – – – – – – – – 21</p><p>2.5.2 CALEA Architecture with middleware Message Queue [method 2]- – – – – – 23</p><p>2.6 Chosen Solution: Split Huge File to Minimize Risk- – – – – – – – 24</p><p>2.7 Reasons for Chosen Solution over the Other Two Methods Designs- – – – – – 24</p><p><b>3 DESIGN- – – – – – – – – – – – – – – – 27</b></p><p><b>4 IMPLEMENTATION- – – – – – – – – – – – – – – .30</b></p><p>4.1 AF Simulator Setup- – – – – – – – – – – – – .31</p><p>4.2 DF Simulator Setup- – – – – – – – – – – – – .31</p><p>4.3 CF Simulator Setup- – – – – – – – – – – – – .32</p><p><b>5 TESTING AND ANALYSIS- – – – – – – – – – – – – – 34</b></p><p><b>6 CONCLUSION- – – – – – – – – – – – – – – – .41</b></p><p>Reference – – – – – – – – – – – – – – – – .42</p><p>Appendix A- – – – – – – – – – – – – – – – – 43</p><p>Appendix B – – – – – – – – – – – – – – – – – .48</p><p>Appendix C- – – – – – – – – – – – – – – – – 49</p> <br><p></p>

Project Abstract

Law Enforcement Agencies (LEA) around the world utilizes eavesdropping systems that are based on

the Communications Assistance for Law Enforcement Act (CALEA) architecture, which provides a

platform for transmitting and collecting these data for further analysis. Recent security analysis however

has revealed that CALEA is susceptible to Denial-of-Service (DoS) attacks, which could potentially

compromise the ability of the system to transmit, analyse and utilize the captured data in real time. The

primary reason for this is the limited transfer rate allocated for sending data obtained via eavesdropping.

The bandwidth can be easily overwhelmed by dummy messages if the transmission link is hijacked,

resulting in subsequent loss of real data being transmitted. This would be analogous to the SYN flood

attack observed in web servers.

This project proposes a solution to this issue, which involves splitting the original data to be transmitted

into smaller chunks prior to transmission. The motivation is to decrease the probability of packets

containing real data being lost when the bandwidth usage increases when a DOS attack is attempted.

Subsequently larger amount of real data arrives intact at the receiving end, which can then be gainfully

utilized. The process of distinguishing the fake from real messages could be achieved through some

appropriate pattern recognition and classification software, which however would be beyond the scope

of this project. The key activities in this project involve the design, implementation and test of the

performance aspects of the proposed solution to the DOS attack problem.

A brief overview of the CALEA architecture is provided, along with the various key modules that

comprise it. The current solution is proposed after an analysis of various alternatives. The primary

research methodology in this project concerns the design of the experimental tests for the proposed

solution, its implementation, execution, data gathering and subsequent analysis. The trial runs are

repeated for both wireless medium and wired medium in order to compare results. A limited transfer rate

link is used to simulate an overwhelmed link and the FTP protocol is used for the file transfer process. A

performance analysis is shown to indicate the amount of real data that would have been lost without the

use of the solution. A discussion about the strength and weakness of the solution is also provided, along

with avenues for future work.


Project Overview

Blazingprojects Mobile App

📚 Over 50,000 Project Materials
📱 100% Offline: No internet needed
📝 Over 98 Departments
🔍 Software coding and Machine construction
🎓 Postgraduate/Undergraduate Research works
📥 Instant Whatsapp/Email Delivery

Blazingprojects App

Related Research

Computer Science. 2 min read

Predicting Disease Outbreaks Using Machine Learning and Data Analysis...

The project topic, "Predicting Disease Outbreaks Using Machine Learning and Data Analysis," focuses on utilizing advanced computational techniques to ...

BP
Blazingprojects
Read more →
Computer Science. 3 min read

Implementation of a Real-Time Facial Recognition System using Deep Learning Techniqu...

The project on "Implementation of a Real-Time Facial Recognition System using Deep Learning Techniques" aims to develop a sophisticated system that ca...

BP
Blazingprojects
Read more →
Computer Science. 3 min read

Applying Machine Learning for Network Intrusion Detection...

The project topic "Applying Machine Learning for Network Intrusion Detection" focuses on utilizing machine learning algorithms to enhance the detectio...

BP
Blazingprojects
Read more →
Computer Science. 3 min read

Analyzing and Improving Machine Learning Model Performance Using Explainable AI Tech...

The project topic "Analyzing and Improving Machine Learning Model Performance Using Explainable AI Techniques" focuses on enhancing the effectiveness ...

BP
Blazingprojects
Read more →
Computer Science. 2 min read

Applying Machine Learning Algorithms for Predicting Stock Market Trends...

The project topic "Applying Machine Learning Algorithms for Predicting Stock Market Trends" revolves around the application of cutting-edge machine le...

BP
Blazingprojects
Read more →
Computer Science. 4 min read

Application of Machine Learning for Predictive Maintenance in Industrial IoT Systems...

The project topic, "Application of Machine Learning for Predictive Maintenance in Industrial IoT Systems," focuses on the integration of machine learn...

BP
Blazingprojects
Read more →
Computer Science. 2 min read

Anomaly Detection in Internet of Things (IoT) Networks using Machine Learning Algori...

Anomaly detection in Internet of Things (IoT) networks using machine learning algorithms is a critical research area that aims to enhance the security and effic...

BP
Blazingprojects
Read more →
Computer Science. 4 min read

Anomaly Detection in Network Traffic Using Machine Learning Algorithms...

Anomaly detection in network traffic using machine learning algorithms is a crucial aspect of cybersecurity that aims to identify unusual patterns or behaviors ...

BP
Blazingprojects
Read more →
Computer Science. 3 min read

Predictive maintenance using machine learning algorithms...

Predictive maintenance is a proactive maintenance strategy that aims to predict equipment failures before they occur, thereby reducing downtime and maintenance ...

BP
Blazingprojects
Read more →
WhatsApp Click here to chat with us