DocumentCode
1856462
Title
VoIP Eavesdropping: A Comprehensive Evaluation of Cryptographic Countermeasures
Author
Pérez-Botero, Diego ; Donoso, Yezid
Author_Institution
Dept. of Syst. & Comput. Eng., Univ. de los Andes, Bogota, Colombia
fYear
2011
fDate
21-24 Sept. 2011
Firstpage
192
Lastpage
196
Abstract
VoIP adoption has gained traction because the service is easy to deploy in various contexts (e.g. business, households, P2P) and represents considerable cost savings in comparison with traditional phone lines. Unfortunately, security measures haven´t kept up with VoIP´s gain in popularity and its users are placing the same amount of trust on the system as they do with landlines. As a result, eavesdropping has become a serious security threat, since network layer and application layer interception attacks are readily available and relatively easy to pull off. This document covers VoIP security schemes with a hands-on approach that encompasses an investigation of current implementations for each protocol, along with performance tests using Quality of Service (QoS) measurements. Our results show that call setup time isn´t largely affected by either signaling protection schemes or key exchange mechanisms, unless TCP is employed as the transport protocol, which is the case with TLS signaling and MIKEY key exchange. Hence, tunneling SIP messages with DTLS and IPSec as well as exchanging keys by using SDES and ZRTP doesn´t hinder the call setup process. Meanwhile, the dearth of support for secure protocols other than TLS, SDES and SRTP in current VoIP clients has rendered S/MIME unviable. The same phenomenon has also led to suboptimal call performance characteristics being inherent to MIKEY and ZRTP key exchange in terms of packet jitter, since their existing implementations have no SIP reinvite support or involve an additional software layer for packet encryption and decryption.
Keywords
Internet telephony; cryptographic protocols; jitter; quality of service; signalling protocols; telecommunication security; transport protocols; DTLS client; IPSec; MIKEY key exchange; QoS measurement; S-MIME; SDES client; SIP reinvite support; SRTP client; TCP; TLS signaling; VoIP eavesdropping; VoIP security scheme; ZRTP key exchange; application layer interception attack; call setup process; comprehensive evaluation; cryptographic countermeasure; key exchange mechanism; packet decryption; packet encryption; packet jitter; phone line; quality of service measurement; signaling protection scheme; software layer; transport protocol; tunneling SIP message; Delay; Encryption; Media; Protocols; Quality of service; Servers; Eavesdropping; Key Exchange Mechanism; Media Encryption; Quality of Service; Secure Signaling; VoIP Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Networking and Distributed Computing (ICNDC), 2011 Second International Conference on
Conference_Location
Beijing
Print_ISBN
978-1-4577-0407-9
Type
conf
DOI
10.1109/ICNDC.2011.46
Filename
6047133
Link To Document