how to identify a "malicious ServiceChange"?

"Perz, Gernot" <[email protected]>
Newsgroups gmane.ietf.megaco
Message-ID <5B32D34C21BAB14AAE47FF638BF82F0002FF9710@nets13ga.ww300.siemens.net>
Hello, 

I've recently discusssed the following problem:

In a softswitch environment where an MGC is controlling a big trunking
Gateway, a single ServiceChange looking harmless as the following:

!/1 [192.168.5.210]:2944  T=14905015 
    { C=- { SC=ROOT 
              { SV { MT=Restart , 
                     RE="901 Cold Boot" ,
                     20080503T09011001
                   }
               }
           }
    }

could have disastrous effects if it is sent by the GW (or an attacker
simulating the GW) maliciously. The MGC would assume that all the trunks
went down and have/had to be re-established. As a result of this
Servicechange a lot of Controller-side objects would be logically
released by the MGC, resulting in loss of calls, enforced recoveries on
the MG, etc.

The discussion arose out of the assumption of a misbehaving MG sending
this ServiceChange in a loop (f. I. due to SW problem), but we ended at
the conclusion that even the very first "malicious ServiceChange" could
be "deadly".

Question:
=========

Is there some recommended strategy to detect this sort of "malicious
ServiceChange" on the MGC, like some plausibility check against "normal
MEGACO communication traffic" of the same GW?

F. I., usually one wouldn't assume that this ServiceChange would
plausibly occur mixed into fast sequences of NOTIFYs and transaction
replies from the GW. You would rather expect to observe some
communication problems to the GW before this sort of ServiceChange
occurs.

With kind regards and thanks in advance!

Gernot Perz
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.