Home > Telecom News > VoIP protocol insecurity
Telecom News:
EMAIL THIS

VoIP protocol insecurity

By Lisa Phifer
02 Feb 2006 | SearchTelecom.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Like many Internet protocols, SIP was designed with simplicity, not security, in mind. And, although H.323 was created to meet broader goals, security issues have plagued it as well. Some vulnerabilities are inherent in the protocols themselves; others have been introduced by the developers who turn these standards into products. The following are some examples:
  • Plaintext SIP messages are trivial to modify or inject, particularly over broadcast media. Although SIP is not encrypted, it can be protected using IPsec, SSL/TLS or S/MIME. However, even then, some header fields like "To" and "Via" must remain visible so SIP requests can be routed correctly. Attackers can thus send spoofed INITIATE requests containing phony IP addresses. Or an attacker who captures SIP setup messages can use spoofed "BYE" requests to disrupt calls in progress.

  • ASN.1 makes H.323 messages slightly harder to fabricate, but not much. To make matters worse, in January 2004, the UK National Infrastructure Security Coordination Center reported a slew of ASN.1 vulnerabilities in many H.323 implementations. According to US CERT VU#749342 (http://www.kb.cert.org/vuls/id/749342), "Sending an exceptional ASN.1 element to a vulnerable telephony component that cannot handle it may cause the application or system behavior to become unpredictable... The impacts associated with these vulnerabilities include denial-of-service and potential execution of arbitrary code." Many of the affected implementations have since been patched, but this illustrates the potential for widespread vulnerabilities in complex new code that is not thoroughly error-tested.

  • Researchers also discovered dozens of denial-of-service (DoS) vulnerabilities in the INVITE message processing of many SIP implementations. According to CERT Advisory CA-2003-06 (http://www.cert.org/advisories/CA-2003-06.html), "Exploitation of these vulnerabilities may result in denial-of-service conditions, service interruptions, and in some cases may allow an attacker to gain unauthorized access to the affected device."

  • Even when a single vendor's implementation is involved, impact may be significant due to the volume of VoIP endpoints. In April 2004, the Microsoft Windows H.323 implementation (http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx) reportedly contained a request-handling buffer overflow condition. This vulnerability can be exploited to run arbitrary code on unpatched Windows 98, ME, NT, 2000, XP and Server 2003 systems, and with early versions of NetMeeting.
These are just a few of the SIP and H.323 Common Vulnerabilities and Exposures (CVEs) found over the past few years. To be fair, many other Internet protocols are vulnerable to spoofing or buffer overflows. But given the high availability associated with the public switched telephone network, companies moving to VoIP may be more sensitive to these threats. Furthermore, as RFC 3261 acknowledges, "SIP is not an easy protocol to secure. Its use of intermediaries, its multi-faceted trust relationships, its expected usage between elements with no trust at all and its user-to-user operation make security far from trivial."

This tip originally appeared as part of SearchSecurity.com's VoIP protocols: A technical guide


ABOUT THE AUTHOR:
Lisa Phifer is vice president of Core Competence Inc., a consulting firm specializing in network security and management technology. Phifer has been involved in the design, implementation, and evaluation of data communications, internetworking, security, and network management products for nearly 20 years. She teaches about wireless LANs and virtual private networking at industry conferences and has written extensively about network infrastructure and security technologies for numerous publications.

Tags: Business and Managed ServicesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Business and Managed Services
Three major issues face telecom on cloud computing services adoption
Telcos can sell Infrastructure as a Service with security, resiliency
To deliver managed telecom service, telcos must consolidate businesses
Is the future of 4G LTE wireless networks in cloud computing?
Carriers poised to offer cloud computing services, but with some risks
Telecom cloud services change hosting business model
Mobile device management has big profit margin for wireless carriers
Network integration outsourcers need network operations know-how
Preparing metro networks for 4G LTE backhaul
Next-gen service convergence hinges on SDP common elements

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
average revenue per user  (SearchTelecom.com)
multichassis multilink PPP  (SearchTelecom.com)
multilink PPP  (SearchTelecom.com)
telecommunications  (SearchTelecom.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Telecom Network Solutions: Telecom Routing, MPLS, Optical Network, VOIP
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts