Abusing SIP authentication - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Article Dans Une Revue Journal of Information Assurance and Security Année : 2009

Abusing SIP authentication

Résumé

The recent and massive deployment of Voice over IP infrastructures had raised the importance of the VoIP security and more precisely of the underlying signalisation protocol SIP. In this paper, we will present a new attack against the authentication mechanism of SIP. This attack allows to perform toll fraud and call hijacking. We will detail the formal specification method that allowed to detect this vulnerability, highlight a simple usage case and propose a mitigation technique.
Fichier principal
Vignette du fichier
jias-SIP.pdf (471.06 Ko) Télécharger le fichier
Origine : Accord explicite pour ce dépôt
Loading...

Dates et versions

inria-00405356 , version 1 (20-07-2009)

Identifiants

  • HAL Id : inria-00405356 , version 1

Citer

Humberto Abdelnur, Tigran Avanesov, Michael Rusinowitch, Radu State. Abusing SIP authentication. Journal of Information Assurance and Security, 2009, Special Issue on Access Control and Protcols, 4 (4), pp.311-318. ⟨inria-00405356⟩
193 Consultations
620 Téléchargements

Partager

Gmail Facebook X LinkedIn More