DocumentCode
2583895
Title
An overview of some techniques to exploit VoIP over WLAN
Author
Me, Gianluigi ; Verdone, Damiano
Author_Institution
Tor Vergata Rome Univ.
fYear
2006
fDate
29-31 Aug. 2006
Firstpage
67
Lastpage
67
Abstract
Voice over IP (VoIP) is one of the most emerging technologies, with a very relevant market penetration trend. This technology represents a cost advantage for the business and private networks with greater flexibility, if no new related vulnerabilities are introduced. The problems of security of the VoIP are mainly related to the weaknesses of the combination of the SIP and RTP protocols. In the VoWiFi case, these weaknesses are enhanced by the intrinsic vulnerabilities of the first generation wireless networks (802.11b), or by a bad administration of wireless security systems. After building a VoIP network over Wi-Fi without enforcing security measures for the authentication and the privacy of the data, we show in this paper several typologies of attack: eavesdropping and sniffing of the VoIP calls, man in the middle, denial of service, call interruption and build false calls. All these threats can represent part of a check list for a plug-and-play penetration test schedule, whenever a company deploys a VoIP network infrastructure based on some untested VoIP softphone and wireless LAN (as an internal hotspot)
Keywords
Internet; message authentication; protocols; radiotelephony; telecommunication security; wireless LAN; 802.11b; RTP protocols; SIP protocols; VoIP softphone; VoWiFi systems; WLAN; Wi-Fi systems; authentication; build false calls; call interruption; denial of service; eavesdropping; first generation wireless networks; man in the middle; plug-and-play penetration test schedule; session initiation protocol; sniffing; voice over IP; wireless LAN; wireless local area networks; wireless security systems; Authentication; Communication system security; Computer crime; Costs; Data privacy; Data security; Internet telephony; Protocols; Wireless LAN; Wireless networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Digital Telecommunications, , 2006. ICDT '06. International Conference on
Conference_Location
Cote d´Azur
Print_ISBN
0-7695-2650-0
Type
conf
DOI
10.1109/ICDT.2006.17
Filename
1698514
Link To Document