Search:
     
3CX Phone System for Windows Download the Free Edition

SIP security

SIP security is a vast and somewhat challenging field.

  • Authentication: Can users steal other users identity?
  • Integrity: Is the SIP message received the same as the one sent?
  • Confidentiality: Is someone else listening on your SIP call setup?
  • Privacy
  • Non-repudiation: Making sure we can trace callers

In addition, the RTP media stream, the actual conversation audio, may need to be confidential.

Client security

  • Replay

Server security

  • Denial of service attacks

IETF RFCs

  • RFC 3329 Security Mechanism Agreement for the Session Initiation Protocol (SIP)
  • RFC Draft SIP digest authentication relay attack

Books


Additional Reading

Multimedia services using SIP face a range of challenges including traversing Firewalls which were never designed to be VoIP aware, exposing a publicly accessible address for a client which invited hacking and so on. Some of the basic issues surrounding SIP and security are examined in a White Paper from Newport Networks: SIP, Security and Session Controllers


Tools

http://www.dumaisnet.ca/index.php?p=asteriskapp#astban This is a simple tool that allows to ban hosts (using iptables) if they send too much SIP traffic which could possibly indicate a brute force attack.

See also




Created by: oej,Last modification on Wed 16 of Mar, 2011 [23:00 UTC] by rwolpov


Please update this page with new information, just login and click on the "Edit" or "Discussion" tab. Get a free login here: Register Thanks! - support@voip-info.org

Page Changes | Comments

 





Search: