DocumentCode :
241205
Title :
Security analysis of VoIP architecture for identifying SIP vulnerabilities
Author :
Rehman, Ubaid Ur ; Abbasi, Abdul Ghafoor
Author_Institution :
Sch. of Electr. Eng. & Comput. Sci., Nat. Univ. of Sci. & Technol., Islamabad, Pakistan
fYear :
2014
fDate :
8-9 Dec. 2014
Firstpage :
87
Lastpage :
93
Abstract :
Voice over Internet Protocol (VoIP) is an emerging technology that changes the way of communication services over IP networks. It provides flexible and low cost services to the users, which make it more popular than the existing Public Switch Telephone Network (PSTN). With the popularity of this technology, it became targeted victim of different attacks. In this paper we analyzed VoIP architecture, both theoretically and practically with more emphasizes on security of Session Initiation Protocol (SIP). In order to analyze theoretically, we performed a literature survey related to SIP security and classified it in term of existing SIP attacks and defenses. Our theoretical analysis reveals that most attacks on VoIP architecture were successful due to weaknesses of SIP, especially the authentication mechanism used in the session establishment phase. For practical analysis, we used open source Asterisk and pen-test it in different attacking scenarios using Kali Linux distribution. Our practical analysis studies revealed that open source asterisk server is still vulnerable to several attacks, which includes eavesdropping, intentional interruption, social threats, interception and modification, and unintentional interruption. We also provide a concise mitigating scheme based on Single Sign-On (SSO), which provides an efficient and reliable authentication mechanism for securing SIP.
Keywords :
Internet telephony; telecommunication security; Kali Linux distribution; PSTN; SIP; VoIP; authentication mechanism; public switch telephone network; security analysis; session initiation protocol; voice over Internet protocol; Authentication; Cryptography; Internet; Interrupters; Protocols; Servers; Asterisk; PSTN; RTP; SIP; Security; VoIP;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Emerging Technologies (ICET), 2014 International Conference on
Conference_Location :
Islamabad
Print_ISBN :
978-1-4799-6088-0
Type :
conf
DOI :
10.1109/ICET.2014.7021022
Filename :
7021022
Link To Document :
بازگشت