CSE545 - Advanced Network Security - Professor McDaniel Page
VoIP Security*
Professor Patrick McDaniel CSE545 - Advanced Network Security Spring 2011
1
*Thanks to Prof. Angelos Keromytis for materials for these lecture slides.
VoIP Security* Professor Patrick McDaniel CSE545 - Advanced Network - - PowerPoint PPT Presentation
VoIP Security* Professor Patrick McDaniel CSE545 - Advanced Network Security Spring 2011 *Thanks to Prof. Angelos Keromytis for materials for these lecture slides. CSE545 - Advanced Network Security - Professor McDaniel Page 1 Example of
CSE545 - Advanced Network Security - Professor McDaniel Page
1
*Thanks to Prof. Angelos Keromytis for materials for these lecture slides.
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
http://www.theregister.co.uk/2006/06/08/voip_fraudsters_nabbed/ http://www.theregister.co.uk/2009/02/11/fugitive_voip_hacker_arrested/
hacking scheme involving the resale of Internet telephone service.” “In all, more than 15 Internet phone companies, including the one in Newark, were left having to pay as much as $300,000 each in connection fees for routing the phone traffic to other carriers without receiving any revenue for the calls, prosecutors said.”
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 3
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
4
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
5
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
management
components
mapping, proxying, billing, access control, device configuration/management, customer support, QoS
(typically RTP), QoS, content security signaling
6
AIM ...
(not format) used to process media-specific data
a standard for describing media session parameters
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
7
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
8
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
9
*not shown
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
10
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
11
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
12
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 13
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
14
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 15
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 16
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 17
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 18
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
19
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
20
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
21
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
22
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 23
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
6
Interruption of services
5
Physical access
4
Service abuse
3
Denial of Service
2
Eavesdropping, interception, modification
ID misrepresentation SPIT/SPAM
1
Social threats
VoIPSA Threat Taxonomy
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 25
VoMIT
software
updateability
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
26
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 27
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
28
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 29
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
30
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
31
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
32
(Attacker on hold) Attacker OK ACK Media (RTP) INVITE Attacker 407 Authentication needed ACK 407 Authentication needed ACK INVITE Attacker (auth) INVITE +1900PREMIUM (auth) INVITE +1900PREMIUM Media (RTP) (reverse rewrite, relay authentication request) (call setup) (rewrite INVITE from Alice) (rewrite INVITE from Alice) PSTN call SIP proxy/PSTN bridge Domain D1 Alice@D1 INVITE Alice@D1 +1900PREMIUM
Systems and Internet Infrastructure Security Laboratory (SIIS) Page 33
2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
34