• DocumentCode
    778273
  • Title

    Information leak vulnerabilities in SIP implementations

  • Author

    Yan, Hong ; Zhang, Hui ; Sripanidkulchai, Kunwadee ; Shae, Zon-Yin ; Saha, D.

  • Author_Institution
    Carnegie Mellon Univ., Pittsburgh, PA
  • Volume
    20
  • Issue
    5
  • fYear
    2006
  • Firstpage
    6
  • Lastpage
    13
  • Abstract
    The use of VoIP as a cheaper communications alternative is growing at an astronomical rate. However, potential abuse of the technology may hinder its deployment. One key security concern is the exploitation of implementation vulnerabilities in the form of unauthorized access, worms, viruses, and denial of service attacks, particularly when combined with explicit targeting of implementations that are known to be vulnerable. One way to protect from exploitations of implementation-specific vulnerabilities is "security-by-obscurity" where a SIP device does not reveal its specific software version. For the same reason, the SIP standard does not encourage announcing the software version in SIP messages. In this article we show that even when SIP messages do not explicitly contain software version information, there is sufficient information leak to determine it. To demonstrate this, we introduce techniques to fingerprint SIP devices and develop a fingerprinting tool called SIPProbe that collects fingerprints and identifies SIP implementations. This type of information leak presents a new security concern as it can be used by malicious users as a building block to scan SIP devices and launch attacks
  • Keywords
    Internet telephony; signalling protocols; telecommunication security; SIP; SIPProbe; VoIP; denial of service attacks; fingerprinting tool; information leak vulnerabilities; security-by-obscurity; software version information; unauthorized access; viruses; worms; Application software; Computer crime; Computer viruses; Fingerprint recognition; Information security; Network servers; Protection; Protocols; Space technology; Telephony;
  • fLanguage
    English
  • Journal_Title
    Network, IEEE
  • Publisher
    ieee
  • ISSN
    0890-8044
  • Type

    jour

  • DOI
    10.1109/MNET.2006.1705877
  • Filename
    1705877