SIP security

Business SIP Provider
Provider Plan Details Monthly Rate *
Nextiva SIP Trunking PBX SIP Trunking
  • Compatible with nearly all PBX systems
  • US-based support
  • No contracts at all
$14.95
Details
Vocalocity Unlimited Extension
  • Unlimited calling and long distance
  • Company Call Record, Voicemail to email transcription
  • No contracts, not setup or installation fees
$24.99
Details
RingCentral SIP RingCentral Office
  • Unlimited calling and faxing
  • No Commitment, No Setup Fees, No Installation
$19.99
Details
8x8 8x8 IP Trunking
  • No contract required.
  • Unlimited Calls (9 free countries)
  • Save 50% or more
$29.99
Details
Jive Communications Smart PBX
  • Unlimited Use of All Features
  • Free Long-Distance
  • No Contracts or Hidden Fees
$21.95
Details
Improcom VoIP Unlimited Business SIP Solution
  • Best overall quality & service
  • Unlimited calling in/out
  • Month to month agreement
$24.95
Details
SIP security is a vast and somewhat challenging field.

  • Authentication: Can users steal other users identity?
  • Integrity: Is the SIP message received the same as the one sent?
  • Confidentiality: Is someone else listening on your SIP call setup?
  • Privacy
  • Non-repudiation: Making sure we can trace callers

In addition, the RTP media stream, the actual conversation audio, may need to be confidential.

Client security

  • Replay

Server security

  • Denial of service attacks

IETF RFCs

  • RFC 3329 Security Mechanism Agreement for the Session Initiation Protocol (SIP)
  • RFC Draft SIP digest authentication relay attack

Books


Additional Reading

Multimedia services using SIP face a range of challenges including traversing Firewalls which were never designed to be VoIP aware, exposing a publicly accessible address for a client which invited hacking and so on. Some of the basic issues surrounding SIP and security are examined in a White Paper from Newport Networks: SIP, Security and Session Controllers


Tools

http://www.dumaisnet.ca/index.php?p=asteriskapp#astban This is a simple tool that allows to ban hosts (using iptables) if they send too much SIP traffic which could possibly indicate a brute force attack.

See also




Created by: oej, Last modification: Wed 16 of Mar, 2011 (23:00 UTC) by rwolpov


Please update this page with new information, just login and click on the "Edit" or "Discussion" tab. Get a free login here: Register Thanks! - support@voip-info.org

Page Changes | Comments

 

Featured -

Search: