2013Unpublished venueRequires access

An Analysis of Security Implications in Session Initiation Protocol (SIP)

Akhil Behl, Kanika Behl

Open publisher page 5 citations

Abstract

Voice over IP (VoIP) has become an indispensible part of our life as individuals, organizations, and corporate move from traditional Plain Old Telephony Systems (POTS) to VoIP based systems. This allows the cost to make or receive calls come down drastically while the Total Cost of Ownership (TCO) for managing a PABX also to be reduced. In this research paper, we explore the plausibility of an attacker or hacker exploiting one of the most popular and commonly used VoIP protocol - Session Initiation protocol (SIP). Session Initiation Protocol (SIP) [1] being derived from HTTP has its own share of strengths and weaknesses. While it constitutes the provisioning of critical and business relevant services e.g. IP Telephony, Instant Messaging, Presence, etc., it is vulnerable to well known and not so well known attacks. This research paper identifies and describes security issues significant to SIP protocol that may lead to Denial of Service (DoS) [2], flooding attacks, attacks exploiting vulnerabilities at the application layer and Spam over Internet Telephony (SPIT). In this paper we explore the various security issues pertinent to SIP protocol and diverse ways in which a VoIP system leveraging SIP can be attacked. We also try to explore the most effective methods to thwart or alleviate these attacks.

About this research paper

What this paper is about

Voice over IP (VoIP) has become an indispensible part of our life as individuals, organizations, and corporate move from traditional Plain Old Telephony Systems (POTS) to VoIP based systems. This allows the cost to make or receive calls come down drastically while the Total Cost of Ownership (TCO) for managing a PABX also to be reduced. In this research paper, we explore the plausibility of an attacker or hacker exploiting one of the most popular and commonly used VoIP protocol - Session Initiation protocol (SIP). Session Initiation Protocol (SIP) [1] being derived from HTTP has its own share of strengths and weaknesses. While it constitutes the provisioning of critical and business relevant services e.g. IP Telephony, Instant Messaging, Presence, etc., it is vulnerable to well known and not so well known attacks. This research paper identifies and describes security issues significant to SIP protocol that may lead to Denial of Service (DoS) [2], flooding attacks, attacks exploiting vulnerabilities at the application layer and Spam over Internet Telephony (SPIT). In this paper we explore the various security issues pertinent to SIP protocol and diverse ways in which a VoIP system leveraging SIP can be attacked. We also try to explore the most effective methods to thwart or alleviate these attacks.

Why it matters

OpenAlex reports 5 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Voice over IP (VoIP) has become an indispensible part of our life as individuals, organizations, and corporate move from traditional Plain Old Telephony Systems (POTS) to VoIP based systems. This allows the cost to make or receive calls come down drastically while the Total Cost of Ownership (TCO) for managing a PABX also to be reduced. In this research paper, we explore the plausibility of an attacker or hacker exploiting one of the most popular and commonly used VoIP protocol - Session Initiation protocol (SIP). Session Initiation Protocol (SIP) [1] being derived from HTTP has its own share of strengths and weaknesses. While it constitutes the provisioning of critical and business relevant services e.g. IP Telephony, Instant Messaging, Presence, etc., it is vulnerable to well known and not so well known attacks. This research paper identifies and describes security issues significant to SIP protocol that may lead to Denial of Service (DoS) [2], flooding attacks, attacks exploiting vulnerabilities at the application layer and Spam over Internet Telephony (SPIT). In this paper we explore the various security issues pertinent to SIP protocol and diverse ways in which a VoIP system leveraging SIP can be attacked. We also try to explore the most effective methods to thwart or alleviate these attacks.

Key concepts: Voice over IP, Session Initiation Protocol, SIP trunking, Computer science, Denial-of-service attack, Computer security, Session (web analytics), Computer network

Related papers

Back to paper searchBrowse research topicsOriginal source
An Analysis of Security Implications in Session Initiation Protocol (SIP) — Research Paper | ScholarLens