inria-00148363, version 2
Assessing the security of VoIP Services
Humberto Abdelnur
1Radu State 1Isabelle Chrisment
1Cristian Popi
1
The Tenth IFIP/IEEE International Symposium on Integrated Network Management - IM 2007 (2007) 373-382
Abstract: VoIP networks are in a major deployment phase and are becoming widely spread out due to their extended functionality and cost efficiency. Meanwhile, as VoIP traffic is transported over the Internet, it is the target of a range of attacks that can jeopardize its proper functionality. In this paper we describe our work in a VoIP specific security assessment framework. Such an assessment is automated with integrated discovery actions, data management and security attacks allowing to perform VoIP specific penetration tests. These tests are important because they permit to search and detect existing vulnerabilities or misconfigured devices and services. Our main contributions consist in an elaborated network information model capable to be used in VoIP assessment, an extensible assessment architecture and its implementation, as well as in a comprehensive framework for defining and composing VoIP specific attacks.
- 1: MADYNES (INRIA Lorraine - LORIA)
- INRIA – CNRS : UMR7503 – Université Henri Poincaré - Nancy I – Université Nancy II – Institut National Polytechnique de Lorraine
- Domain : Computer Science/Networking and Telecommunication
- Keywords : VoIP Assessment – Penetration tests – Attack Tree Modeling – VoIP Network information model
- Comment : ISBN : 1-4244-0799-0/http://www.comsoc.org
- Available versions : v1 (2007-05-22) v2 (2007-06-12)
- inria-00148363, version 2
- http://hal.inria.fr/inria-00148363
- oai:hal.inria.fr:inria-00148363
- From: Humberto Abdelnur
- Submitted on: Tuesday, 12 June 2007 09:41:20
- Updated on: Tuesday, 21 June 2011 13:55:37






Associated documents
Export