...
首页> 外文期刊>Computers & Security >An ontology-based policy for deploying secure SIP-based VoIP services
【24h】

An ontology-based policy for deploying secure SIP-based VoIP services

机译:基于本体的策略,用于部署基于SIP的安全VoIP服务

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Voice services over Internet Protocol (VoIP) are nowadays much promoted by telecommunication and Internet service providers. However, the utilization of open networks, like the Internet, raises several security issues that must be accounted for. On top of that, there are new sophisticated attacks against VoIP infrastructures that capitalize on vulnerabilities of the protocols employed for the establishment of a VoIP session (for example the Session Initiation Protocol - SIP).rnThis paper provides a categorization of potential attacks against VoIP services, followed by specific security recommendations and guidelines for protecting the underlying infrastructure from these attacks and thus ensuring the provision of robust and secure services. In order to utilize (share) the aforementioned security guidelines and recommendations into different domains, it is necessary to have them represented in some formal way. To this end, ontologies have been used for representing the proposed guidelines and recommendations in the form of a unified security policy for VoIP infrastructures. This ontology-based policy has been then transformed to a First Order Logic (FOL) formal representation. The proposed ontology-based security policy can be applied in a real VoIP environment for detecting attacks against an SIP-based service, but it can be also utilized for security testing purposes and vulnerabilities identification.rnThe work presented in this paper has been focused to the SIP protocol. However, generalization to other signaling protocols is possible.
机译:如今,电信和Internet服务提供商大大促进了Internet协议(VoIP)上的语音服务。但是,像Internet这样的开放网络的使用带来了一些必须解决的安全问题。最重要的是,针对VoIP基础结构的新的高级攻击利用了用于建立VoIP会话的协议(例如会话发起协议-SIP)的漏洞。rn本文提供了对VoIP服务的潜在攻击的分类。 ,然后是针对特定基础结构的安全建议和指南,旨在保护基础基础架构免受这些攻击,从而确保提供健壮和安全的服务。为了将上述安全准则和建议(共享)用于不同的领域,有必要以某种正式的方式来代表它们。为此,本体已经以用于VoIP基础设施的统一安全策略的形式来表示所提议的指南和建议。然后,这种基于本体的策略已转换为一阶逻辑(FOL)形式表示。所提出的基于本体的安全策略可以在真实的VoIP环境中应用,以检测针对基于SIP的服务的攻击,但也可以用于安全测试目的和漏洞识别。 SIP协议。然而,可以推广到其他信令协议。

著录项

  • 来源
    《Computers & Security》 |2008年第8期|285-297|共13页
  • 作者单位

    Laboratory of Information and Communication Systems Security, Department of Information and Communication Systems Engineering, University of the Aegean, Karlovassi, GR-83200 Samos, Greece;

    Laboratory of Information and Communication Systems Security, Department of Information and Communication Systems Engineering, University of the Aegean, Karlovassi, GR-83200 Samos, Greece;

    Laboratory of Information and Communication Systems Security, Department of Information and Communication Systems Engineering, University of the Aegean, Karlovassi, GR-83200 Samos, Greece;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    SIP; VoIP; ontology; security policies; attack description; formalization;

    机译:啜;VoIP;本体安全政策;攻击说明;形式化;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号