Abusing SIP authentication

Humberto Abdelnur 1, * Tigran Avanesov 2, * Michael Rusinowitch 2, * Radu State 1, 3, *
* Corresponding author
1 MADYNES - Management of dynamic networks and services
INRIA Lorraine, LORIA - Laboratoire Lorrain de Recherche en Informatique et ses Applications
2 CASSIS - Combination of approaches to the security of infinite states systems
FEMTO-ST - Franche-Comté Électronique Mécanique, Thermique et Optique - Sciences et Technologies (UMR 6174), INRIA Lorraine, LORIA - Laboratoire Lorrain de Recherche en Informatique et ses Applications
Abstract : The recent and massive deployment of Voice over IP infrastructures had raised the importance of the VoIP security and more precisely of the underlying signalisation protocol SIP. In this paper, we will present a new attack against the authentication mechanism of SIP. This attack allows to perform toll fraud and call hijacking. We will detail the formal specification method that allowed to detect this vulnerability, highlight a simple usage case and propose a mitigation technique.
Complete list of metadatas

Cited literature [9 references]  Display  Hide  Download

https://hal.inria.fr/inria-00405356
Contributor : Tigran Avanesov <>
Submitted on : Monday, July 20, 2009 - 12:42:27 PM
Last modification on : Friday, July 6, 2018 - 3:06:09 PM
Long-term archiving on : Tuesday, June 15, 2010 - 8:33:23 PM

File

jias-SIP.pdf
Explicit agreement for this submission

Identifiers

  • HAL Id : inria-00405356, version 1

Citation

Humberto Abdelnur, Tigran Avanesov, Michael Rusinowitch, Radu State. Abusing SIP authentication. Journal of Information Assurance and Security, Dynamic Publishers Inc., USA, 2009, Special Issue on Access Control and Protcols, 4 (4), pp.311-318. ⟨inria-00405356⟩

Share

Metrics

Record views

400

Files downloads

413