Title :
A Comprehensive Survey of Voice over IP Security Research
Author :
Keromytis, Angelos D.
Author_Institution :
Dept. of Comput. Sci., Columbia Univ. in the City of New York, New York, NY, USA
Abstract :
We present a comprehensive survey of Voice over IP security academic research, using a set of 245 publications forming a closed cross-citation set. We classify these papers according to an extended version of the VoIP Security Alliance (VoIPSA) Threat Taxonomy. Our goal is to provide a roadmap for researchers seeking to understand existing capabilities and to identify gaps in addressing the numerous threats and vulnerabilities present in VoIP systems. We discuss the implications of our findings with respect to vulnerabilities reported in a variety of VoIP products. We identify two specific problem areas (denial of service, and service abuse) as requiring significant more attention from the research community. We also find that the overwhelming majority of the surveyed work takes a black box view of VoIP systems that avoids examining their internal structure and implementation. Such an approach may miss the mark in terms of addressing the main sources of vulnerabilities, i.e., implementation bugs and misconfigurations. Finally, we argue for further work on understanding cross-protocol and cross-mechanism vulnerabilities (emergent properties), which are the byproduct of a highly complex system-of-systems and an indication of the issues in future large-scale systems.
Keywords :
Internet telephony; telecommunication security; VoIP Security Alliance; VoIP products; VoIP systems; VoIPSA Threat Taxonomy; cross-mechanism vulnerabilities; cross-protocol; large-scale systems; system-of-systems; voice over IP security academic research; voice over IP security research; Authentication; Internet telephony; Media; Protocols; Servers; Taxonomy; SIP; VoIP; security;
Journal_Title :
Communications Surveys & Tutorials, IEEE
DOI :
10.1109/SURV.2011.031611.00112