SLIDE 1
The DoS Problem
- Attacker sends SIP
INVITE or RTSP SETUP to server
- IP for RTP is target
– Source IP in RTSP – SDP in SIP
- Server sends media to
target
Server Client/ Attacker Target
INVITE/SETUP With IP of target
RTP Flood
ICE and RTP DoS draft-rosenberg-mmusic-rtp-denialofservice - - PowerPoint PPT Presentation
ICE and RTP DoS draft-rosenberg-mmusic-rtp-denialofservice draft-rosenberg-sipping-ice Jonathan Rosenberg dynamicsoft The DoS Problem Attacker sends SIP Server INVITE or RTSP RTP SETUP to server Flood INVITE/SETUP IP for RTP is
INVITE/SETUP With IP of target
RTP Flood
– Before sending RTP, check that someone is actually listening at the target address – Requires a request/response mechanism to the RTP ports – Mechanism must not be amenable to attacks itself – That’s ICE!
– Local interfaces – UNSAF protocols – VPNs
– Connectivity test uses peer-to-peer STUN