inria-00148363, version 2
Assessing the security of VoIP Services
Humberto Abdelnur
1Radu State 1Isabelle Chrisment
1Cristian Popi
1
The Tenth IFIP/IEEE International Symposium on Integrated Network Management - IM 2007 (2007) 373-382
Résumé : VoIP networks are in a major deployment phase and are becoming widely spread out due to their extended functionality and cost efficiency. Meanwhile, as VoIP traffic is transported over the Internet, it is the target of a range of attacks that can jeopardize its proper functionality. In this paper we describe our work in a VoIP specific security assessment framework. Such an assessment is automated with integrated discovery actions, data management and security attacks allowing to perform VoIP specific penetration tests. These tests are important because they permit to search and detect existing vulnerabilities or misconfigured devices and services. Our main contributions consist in an elaborated network information model capable to be used in VoIP assessment, an extensible assessment architecture and its implementation, as well as in a comprehensive framework for defining and composing VoIP specific attacks.
- 1 : MADYNES (INRIA Lorraine - LORIA)
- INRIA – CNRS : UMR7503 – Université Henri Poincaré - Nancy I – Université Nancy II – Institut National Polytechnique de Lorraine (INPL)
- Domaine : Informatique/Réseaux et télécommunications
- Mots-clés : VoIP Assessment – Penetration tests – Attack Tree Modeling – VoIP Network information model
- Commentaire : ISBN : 1-4244-0799-0/http://www.comsoc.org
- Versions disponibles : v1 (22-05-2007) v2 (12-06-2007)
- inria-00148363, version 2
- http://hal.inria.fr/inria-00148363
- oai:hal.inria.fr:inria-00148363
- Contributeur : Humberto Abdelnur
- Soumis le : Mardi 12 Juin 2007, 09:41:20
- Dernière modification le : Mardi 21 Juin 2011, 13:55:37






Documents associés
Exporter