SIP Malformed Message detection

Detection and prevention of SIP malformed messages has become an important indicator of high availability VoIP systems. This paper describes possible SIP malformed messages attacks and builds a malformed message detection system. It focuses on achieving high detecting accuracy and at the same time low processing overhead. SIP LEX, lexical analyzer for SIP messages, is implemented for parsing incoming SIP messages in the system to identify the malformed messages. Experiments over synthetic traces demonstrate the efficiency of SIP LEX in SIP malformed messages detection. cap. 1 · Introduction