首页> 外文期刊>Computer networks >A survey on registration hijacking attack consequences and protection for session initiation protocol (SIP)
【24h】

A survey on registration hijacking attack consequences and protection for session initiation protocol (SIP)

机译:会话发起议定书注册劫持攻击后果和保护调查(SIP)

获取原文
获取原文并翻译 | 示例

摘要

Today, many organizations are transforming their traditional telephone services into Voice over Internet Protocol (VoIP) systems. These services are simple to implement, but they are often vulnerable to attacks because they are packet-switched IP networks to support the circuit-switched used for voice communication. SIP is widely used as a signaling protocol to facilitate video and voice communication, as well as for more multimedia applications. However, it is not protected against various types of attacks because of its open nature and lack of a clear line of defense against the growing number of security threats. Among these risks, registration hijacking assaults, known by its harmful effect, attack both the User Agent Server (UAS) and the User Agent Client (UAC). In particular, the REGISTER message is evaluated as one of the main reasons of registration hijacking assaults in SIP. An attacker who deactivates the SIP registration of a valid user and replaces it with the logical address of the hacker. This allows the hacker to block incoming calls as well as redirect, replay or end calls at will. In this survey, we present a complete study of the registration attack against SIP, communicating its different alternatives and analyzing its consequences. We have also categorized current solutions based on the different registration hijacking attack approaches they face, their types, and their targets. In addition, We conduct an in-depth review of the robustness and inefficiency of these solutions, as well as an in-depth analysis of each one's basic assumptions to better understand their limitations. Finally, we recommend protecting the UAC registration method against registration-hijacking by using the Media Access Control (MAC) address to improve the efficiency of the studied solutions.
机译:如今,许多组织正在将传统的电话服务转换为互联网协议(VoIP)系统的语音。这些服务易于实施,但它们往往容易受到攻击,因为它们是分组交换的IP网络,以支持用于语音通信的电路切换。 SIP广泛用作信令协议,以便于视频和语音通信,以及更多多媒体应用。然而,由于其开放性和缺乏针对越来越多的安全威胁,缺乏明确的防守,因此不受各种类型的攻击免受保护。在这些风险中,注册劫持攻击,通过其有害效果所知,攻击用户代理服务器(UAS)和用户代理客户端(UAC)。特别是,寄存器消息被评估为注册在SIP中劫持攻击的主要原因之一。攻击者停用有效用户的SIP注册并用黑客的逻辑地址替换它。这允许黑客阻止来电以及重定向,重放或最终呼叫。在本调查中,我们对SIP的注册攻击进行了完整的研究,传达了其不同的替代方案并分析其后果。我们还根据他们面对的不同注册劫持攻击攻击,他们的类型及其目标分类了当前解决方案。此外,我们对这些解决方案的稳健性和效率低下进行了深入的审查,以及对每个人的基本假设的深入分析,以更好地了解他们的局限性。最后,我们建议使用媒体访问控制(MAC)地址来保护UAC注册方法,以提高研究的解决方案的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号