A Comprehensive Survey of Voice over IP Security Research

被引:73
作者
Keromytis, Angelos D. [1 ]
机构
[1] Columbia Univ, Dept Comp Sci, Mail Code 0401, New York, NY 10027 USA
基金
美国国家科学基金会;
关键词
VoIP; SIP; security; SESSION INITIATION PROTOCOL; AUTHENTICATION SCHEME; PERFORMANCE ANALYSIS; SPIT MANAGEMENT; SIP; ATTACKS; SPAM; TELEPHONY; INFRASTRUCTURE; CHALLENGES;
D O I
10.1109/SURV.2011.031611.00112
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present a comprehensive survey of Voice over IP security academic research, using a set of 245 publications forming a closed cross-citation set. We classify these papers according to an extended version of the VoIP Security Alliance (VoIPSA) Threat Taxonomy. Our goal is to provide a roadmap for researchers seeking to understand existing capabilities and to identify gaps in addressing the numerous threats and vulnerabilities present in VoIP systems. We discuss the implications of our findings with respect to vulnerabilities reported in a variety of VoIP products. We identify two specific problem areas (denial of service, and service abuse) as requiring significant more attention from the research community. We also find that the overwhelming majority of the surveyed work takes a black box view of VoIP systems that avoids examining their internal structure and implementation. Such an approach may miss the mark in terms of addressing the main sources of vulnerabilities, i.e., implementation bugs and misconfigurations. Finally, we argue for further work on understanding cross-protocol and cross-mechanism vulnerabilities (emergent properties), which are the byproduct of a highly complex system-of-systems and an indication of the issues in future large-scale systems.
引用
收藏
页码:514 / 537
页数:24
相关论文
共 266 条
[1]   Assessing the security of VoIP services [J].
Abdelnur, H. ;
State, R. ;
Chrisment, I. ;
Popi, C. .
2007 10TH IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2009), VOLS 1 AND 2, 2007, :373-+
[2]  
Abdelnur H, 2006, VOIP MASE 06: 1ST IEEE WORKSHOP ON VOIP MANAGEMENT AND SECURITY, P29
[3]   Abusing SIP authentication [J].
Abdelnur, Humberto ;
Avanesov, Tigran ;
Rusinowitch, Michael ;
State, Radu .
FOURTH INTERNATIONAL SYMPOSIUM ON INFORMATION ASSURANCE AND SECURITY, PROCEEDINGS, 2008, :237-242
[4]  
Abdelnur Humberto J, 2007, P 1 INT C PRINC SYST, P47
[5]  
Ackermann R, 2001, INT FED INFO PROC, V64, P53
[6]  
Al-Riyami SS, 2003, LECT NOTES COMPUT SC, V2894, P452
[7]  
[Anonymous], P 4 IFIP IEEE INT C
[8]  
[Anonymous], P IEEE WORKSH INF AS
[9]  
[Anonymous], P 12 IFIP IEEE INT S
[10]  
[Anonymous], P 5 AUSTR INF SEC MA