Abusing SIP authentication - Inria - Institut national de recherche en sciences et technologies du numérique Access content directly
Journal Articles Journal of Information Assurance and Security Year : 2009

Abusing SIP authentication

Abstract

The recent and massive deployment of Voice over IP infrastructures had raised the importance of the VoIP security and more precisely of the underlying signalisation protocol SIP. In this paper, we will present a new attack against the authentication mechanism of SIP. This attack allows to perform toll fraud and call hijacking. We will detail the formal specification method that allowed to detect this vulnerability, highlight a simple usage case and propose a mitigation technique.
Fichier principal
Vignette du fichier
jias-SIP.pdf (471.06 Ko) Télécharger le fichier
Origin : Explicit agreement for this submission
Loading...

Dates and versions

inria-00405356 , version 1 (20-07-2009)

Identifiers

  • HAL Id : inria-00405356 , version 1

Cite

Humberto Abdelnur, Tigran Avanesov, Michael Rusinowitch, Radu State. Abusing SIP authentication. Journal of Information Assurance and Security, 2009, Special Issue on Access Control and Protcols, 4 (4), pp.311-318. ⟨inria-00405356⟩
193 View
617 Download

Share

Gmail Facebook X LinkedIn More