Skip to Main content Skip to Navigation
Conference papers

Abusing SIP Authentication

Humberto Abdelnur 1 Tigran Avanesov 2 Michaël Rusinowitch 2 Radu State 1 
1 MADYNES - Management of dynamic networks and services
INRIA Lorraine, LORIA - Laboratoire Lorrain de Recherche en Informatique et ses Applications
2 CASSIS - Combination of approaches to the security of infinite states systems
FEMTO-ST - Franche-Comté Électronique Mécanique, Thermique et Optique - Sciences et Technologies (UMR 6174), Inria Nancy - Grand Est, LORIA - FM - Department of Formal Methods
Abstract : The recent and massive deployment of Voice over IP infrastructures had raised the importance of the VoIP security and more precisely of the underlying signalization protocol SIP. In this paper, we will present a new attack against the authentication mechanism of SIP. This attack allows to perform toll fraud and call hijacking. We will detail the formal specification method that allowed to detect this vulnerability, highlight a simple usage case and propose a mitigation technique.
Document type :
Conference papers
Complete list of metadata

Cited literature [11 references]  Display  Hide  Download
Contributor : Humberto Abdelnur Connect in order to contact the contributor
Submitted on : Wednesday, October 1, 2008 - 3:21:51 PM
Last modification on : Friday, January 21, 2022 - 3:08:59 AM
Long-term archiving on: : Thursday, June 3, 2010 - 8:40:28 PM


Files produced by the author(s)



Humberto Abdelnur, Tigran Avanesov, Michaël Rusinowitch, Radu State. Abusing SIP Authentication. Information Assurance and Security ( ISIAS), Sep 2008, Naples, Italy. pp.237-242, ⟨10.1109/IAS.2008.29⟩. ⟨inria-00326077⟩



Record views


Files downloads