Detecting unprotected SIP-based voice over IP traffic

Leonardo Carvajal, Lei Chen, C. Varol, D. Rawat
{"title":"Detecting unprotected SIP-based voice over IP traffic","authors":"Leonardo Carvajal, Lei Chen, C. Varol, D. Rawat","doi":"10.1109/ISDFS.2016.7473515","DOIUrl":null,"url":null,"abstract":"The use of Voice over IP (VoIP) applications has dramatically increased in recent years. Large, medium, and small organizations, as well as individuals, are reducing the cost of their phone calls using their data infrastructure or a broadband Internet service to transmit phone calls over IP networks. Like data networks, VoIP networks are also vulnerable to security threats such as Denial-of-Service (DoS) attacks, interception of private communications, registration hijacking, spam, and message tampering. Security mechanisms, such as encryption and authentication, may be used to reduce the potential impact of some of these security threats. However, in reality, VoIP providers may not supply adequate security, or otherwise they are adopting and implementing these countermeasures at very slow rates without informing users whether their phone calls are protected. Given the fact that the interception of private communications is one of the most commonly seen attacks in VoIP, we present a solution to detect unprotected SIP-based VoIP packets. Upon positive detection, alerts may be sent to users informing them about the unprotected VoIP calls, thus potentially preventing identity theft and improving security awareness. Our testing results show that our solution provides accurate detection with zero false detection rate of unprotected SIP-based VoIP traffic.","PeriodicalId":136977,"journal":{"name":"2016 4th International Symposium on Digital Forensic and Security (ISDFS)","volume":"6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-04-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 4th International Symposium on Digital Forensic and Security (ISDFS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISDFS.2016.7473515","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

The use of Voice over IP (VoIP) applications has dramatically increased in recent years. Large, medium, and small organizations, as well as individuals, are reducing the cost of their phone calls using their data infrastructure or a broadband Internet service to transmit phone calls over IP networks. Like data networks, VoIP networks are also vulnerable to security threats such as Denial-of-Service (DoS) attacks, interception of private communications, registration hijacking, spam, and message tampering. Security mechanisms, such as encryption and authentication, may be used to reduce the potential impact of some of these security threats. However, in reality, VoIP providers may not supply adequate security, or otherwise they are adopting and implementing these countermeasures at very slow rates without informing users whether their phone calls are protected. Given the fact that the interception of private communications is one of the most commonly seen attacks in VoIP, we present a solution to detect unprotected SIP-based VoIP packets. Upon positive detection, alerts may be sent to users informing them about the unprotected VoIP calls, thus potentially preventing identity theft and improving security awareness. Our testing results show that our solution provides accurate detection with zero false detection rate of unprotected SIP-based VoIP traffic.
检测未受保护的基于sip的IP语音流量
近年来,IP语音(VoIP)应用的使用急剧增加。大型、中型和小型组织以及个人都在使用他们的数据基础设施或宽带互联网服务通过IP网络传输电话,从而降低他们的电话费用。与数据网络一样,VoIP网络也容易受到诸如拒绝服务(DoS)攻击、拦截私人通信、注册劫持、垃圾邮件和消息篡改等安全威胁。安全机制(如加密和身份验证)可用于减少其中一些安全威胁的潜在影响。然而,在现实中,VoIP提供商可能无法提供足够的安全性,或者他们正在以非常缓慢的速度采用和实施这些对策,而没有通知用户他们的电话是否受到保护。鉴于拦截私有通信是VoIP中最常见的攻击之一,我们提出了一种检测未受保护的基于sip的VoIP数据包的解决方案。在积极的检测后,可能会向用户发送警报,告知他们未受保护的VoIP呼叫,从而潜在地防止身份盗窃和提高安全意识。测试结果表明,我们的解决方案能够对基于sip的无保护VoIP流量进行准确的检测,且误检率为零。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信