• DocumentCode
    1856462
  • Title

    VoIP Eavesdropping: A Comprehensive Evaluation of Cryptographic Countermeasures

  • Author

    Pérez-Botero, Diego ; Donoso, Yezid

  • Author_Institution
    Dept. of Syst. & Comput. Eng., Univ. de los Andes, Bogota, Colombia
  • fYear
    2011
  • fDate
    21-24 Sept. 2011
  • Firstpage
    192
  • Lastpage
    196
  • Abstract
    VoIP adoption has gained traction because the service is easy to deploy in various contexts (e.g. business, households, P2P) and represents considerable cost savings in comparison with traditional phone lines. Unfortunately, security measures haven´t kept up with VoIP´s gain in popularity and its users are placing the same amount of trust on the system as they do with landlines. As a result, eavesdropping has become a serious security threat, since network layer and application layer interception attacks are readily available and relatively easy to pull off. This document covers VoIP security schemes with a hands-on approach that encompasses an investigation of current implementations for each protocol, along with performance tests using Quality of Service (QoS) measurements. Our results show that call setup time isn´t largely affected by either signaling protection schemes or key exchange mechanisms, unless TCP is employed as the transport protocol, which is the case with TLS signaling and MIKEY key exchange. Hence, tunneling SIP messages with DTLS and IPSec as well as exchanging keys by using SDES and ZRTP doesn´t hinder the call setup process. Meanwhile, the dearth of support for secure protocols other than TLS, SDES and SRTP in current VoIP clients has rendered S/MIME unviable. The same phenomenon has also led to suboptimal call performance characteristics being inherent to MIKEY and ZRTP key exchange in terms of packet jitter, since their existing implementations have no SIP reinvite support or involve an additional software layer for packet encryption and decryption.
  • Keywords
    Internet telephony; cryptographic protocols; jitter; quality of service; signalling protocols; telecommunication security; transport protocols; DTLS client; IPSec; MIKEY key exchange; QoS measurement; S-MIME; SDES client; SIP reinvite support; SRTP client; TCP; TLS signaling; VoIP eavesdropping; VoIP security scheme; ZRTP key exchange; application layer interception attack; call setup process; comprehensive evaluation; cryptographic countermeasure; key exchange mechanism; packet decryption; packet encryption; packet jitter; phone line; quality of service measurement; signaling protection scheme; software layer; transport protocol; tunneling SIP message; Delay; Encryption; Media; Protocols; Quality of service; Servers; Eavesdropping; Key Exchange Mechanism; Media Encryption; Quality of Service; Secure Signaling; VoIP Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networking and Distributed Computing (ICNDC), 2011 Second International Conference on
  • Conference_Location
    Beijing
  • Print_ISBN
    978-1-4577-0407-9
  • Type

    conf

  • DOI
    10.1109/ICNDC.2011.46
  • Filename
    6047133