Reference : Abusing SIP authentication
Scientific journals : Article
Engineering, computing & technology : Computer science
http://hdl.handle.net/10993/3842
Abusing SIP authentication
English
Abdelnur, Humberto J. [INRIA > Lorraine, Loria]
Avanesov, Tigran mailto [INRIA > Lorraine, Loria]
Rusinowitch, Michael [INRIA > Lorraine, Loria]
State, Radu mailto [University of Luxembourg > Faculty of Science, Technology and Communication (FSTC)]
2009
Journal of Information Assurance and Security
Dynamic
4
311–318
Yes (verified by ORBilu)
International
1554-1010
1554-1029
Atlanta
GA
[en] Security threat ; VoIP ; SIP protocol ; authentication ; formal validation ; AVISPA
[en] The recent and massive deployment of Voice over IP infrastructures had raised the importance of the VoIP security and more precisely of the underlying signalisation protocol SIP. In this paper, we will present a new attack against the authentication mechanism of SIP. This attack allows to perform toll fraud and call hijacking. We will detail the formal specification method that allowed to detect this vulnerability, highlight a simple usage case and propose a mitigation technique.
http://hdl.handle.net/10993/3842

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Limited access
jias-SIP.pdfPublisher postprint471.06 kBRequest a copy

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.