首页> 外文会议>Availability, Reliability and Security, 2009. ARES '09 >Revealing the Calling History of SIP VoIP Systems by Timing Attacks
【24h】

Revealing the Calling History of SIP VoIP Systems by Timing Attacks

机译:通过定时攻击揭示SIP VoIP系统的呼叫历史

获取原文

摘要

Many emergent security threats which did not exist in the traditional telephony network are introduced in SIP VoIP services. To provide high-level security assurance to SIP VoIP services, an inter-domain authentication mechanism is defined in RFC 4474. However, this mechanism introduces another vulnerability: a timing attack which can be used for effectively revealing the calling history of a group of VoIP users. The idea here is to exploit the certificate cache mechanisms supported by SIP VoIP infrastructures, in which the certificate from a caller's domain will be cached by the callee's proxy to accelerate subsequent requests. Therefore, SIP processing time varies depending whether the two domains had been into contact beforehand or not. The attacker can thus profile the calling history of a SIP domain by sending probing requests and observing the time required for processing. The result of our experiments demonstrates that this attack can be easily launched. We also discuss countermeasures to prevent such attacks.
机译:SIP VoIP服务中引入了许多传统电话网络中不存在的紧急安全威胁。为了向SIP VoIP服务提供高级安全保证,在RFC 4474中定义了一种域间身份验证机制。但是,该机制引入了另一个漏洞:定时攻击,可用于有效地揭示一组VoIP的呼叫历史记录。用户。这里的想法是利用SIP VoIP基础结构支持的证书缓存机制,其中来自呼叫者域的证书将由被呼叫者的代理缓存,以加速后续请求。因此,SIP处理时间根据两个域是否已经预先联系而有所不同。因此,攻击者可以通过发送探测请求并观察处理所需的时间来分析SIP域的呼叫历史。我们的实验结果表明,这种攻击很容易发动。我们还讨论了防止此类攻击的对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号