...
首页> 外文期刊>IEEE Network >Information Leak Vulnerabilities in SIP Implementations
【24h】

Information Leak Vulnerabilities in SIP Implementations

机译:SIP实施中的信息泄漏漏洞

获取原文
获取原文并翻译 | 示例

摘要

The use of VoIP as a cheaper communications alternative is growing at an astronomical rate. However, potential abuse of the technology may hinder its deployment. One key security concern is the exploitation of implementation vulnerabilities in the form of unauthorized access, worms, viruses, ana denial of service attacks, particularly when combined with explicit targeting of implementations that are known to be vulnerable. One way to protect from exploitations of implementation-specific vulnerabilities is "security-by-obscurity" where a SIP device does not reveal its specific software version. For the same reason, the SIP standard does not encourage announcing the software version in SIP messages. In this article we show that even when SIP messages do not explicitly contain software version information, there is sufficient information leak to determine it. To demonstrate this, we introduce techniques to fingerprint SIP devices and develop a fingerprinting tool called SIPProbe that collects fingerprints and identifies SIP implementations. This type of information leak presents a new security concern as it can be used by malicious users as a building block to scan SIP devices and launch attacks.
机译:VoIP作为一种更便宜的通信替代品的使用正以天文数字的速度增长。但是,对该技术的潜在滥用可能会阻碍其部署。一个主要的安全问题是利用未授权访问,蠕虫,病毒,拒绝服务攻击等形式的实施漏洞,尤其是与明确已知的易受攻击的目标结合使用时。防止利用特定于实现的漏洞的一种方法是“逐个安全性”,其中SIP设备不会公开其特定的软件版本。出于相同的原因,SIP标准不鼓励在SIP消息中宣布软件版本。在本文中,我们表明,即使SIP消息未明确包含软件版本信息,也有足够的信息泄漏来确定它。为了证明这一点,我们将技术引入指纹SIP设备并开发了一种称为SIPProbe的指纹工具,该工具可以收集指纹并识别SIP实现。这种类型的信息泄漏带来了新的安全问题,因为恶意用户可以将其用作扫描SIP设备和发起攻击的基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号