SECURELOGIX CORPORATION — Department of Homeland Security SBIR Phase II: H-SB015.1-003
SECURELOGIX CORPORATION — SBIR Phase II award from Department of Homeland Security.
- Amount
- $697,708
- Agency
- Department of Homeland Security
- Program / Phase
- SBIR · Phase II
- Topic
- H-SB015.1-003
- Solicitation
- HSHQDC-15-R-00017
- NAICS
- —
- Place of performance
- TX
- Period
- 2016-03-15 → 2018-03-14
Description
TDoS is a form of DoS that affects government, enterprise, and small business voice systems. It is the most significant threat to voice systems and by far the most likely form of voice-based DoS. TDoS attackers use SIP, free IP-PBXs, call generators, and spoofed calling numbers to cheaply and anonymously flood their victims with calls. The attackers have the advantage, because attacks are easy to generate, victims often have a small number of critical phones and attendants that are easily overwhelmed, and have little capability to mitigate the attacks. The state of the art in mitigation is largely static black and white lists in PBXs, SBCs, and service provider networks. Plus, by spending just a little more effort, attackers can make their attacks much more complex and difficult to mitigate. Soon the ability to generate very large distributed TDoS attacks will also be possible, increasing the list of potential victims. The proposed project will define a defense and robust prototype for these types of attacks. A robust defense approach consisting of 5 levels of filters, which inspect the calling number, SIP signaling, use network probes for some calls, and using Turing Tests and content analysis for other calls, all configured with flexible policies and business rules, will be defined. A robust prototype implementing the most promising countermeasures will be built upon the commercial PolicyGuru solution. This will provide a foundation for this Phase II effort and rapid transition to a commercial product.