An ontology-based policy for deploying secure SIP-based VoIP services

被引:13
|
作者
Geneiatakis, Dimitris [1 ]
Lambrinoudakis, Costas [1 ]
Kaymbourakis, Georgios [1 ]
机构
[1] Univ Aegean, Dept Informat & Commun Syst Engn, Lab Informat & Commun Syst Secur, GR-83200 Karlovassi, Samos, Greece
关键词
SIP; VoIp; Ontology; Security policies; Attack description; Formalization;
D O I
10.1016/j.cose.2008.07.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Voice services over Internet Protocol (VoIP) are nowadays much promoted by telecommunication and Internet service providers. However, the utilization of open networks, like the Internet, raises several security issues that must be accounted for. On top of that, there are new sophisticated attacks against VoIP infrastructures that capitalize on vulnerabilities of the protocols employed for the establishment of a VoIP session (for example the Session Initiation Protocol - SIP). This paper provides a categorization of potential attacks against VoIP services, followed by specific security recommendations and guidelines for protecting the underlying infrastructure from these attacks and thus ensuring the provision of robust and secure services. In order to utilize (share) the aforementioned security guidelines and recommendations into different domains, it is necessary to have them represented in some formal way. To this end, ontologies have been used for representing the proposed guidelines and recommendations in the form of a unified security policy for VoIP infrastructures. This ontology-based policy has been then transformed to a First Order Logic (FOL) formal representation. The proposed ontology-based security policy can be applied in a real VoIP environment for detecting attacks against an SIP-based service, but it can be also utilized for security testing purposes and vulnerabilities identification. The work presented in this paper has been focused to the SIP protocol. However, generalization to other signaling protocols is possible. (c) 2008 Elsevier Ltd. All rights reserved.
引用
收藏
页码:285 / 297
页数:13
相关论文
共 50 条
  • [1] Implementing a secure VoIP communication over SIP-based networks
    Wen-Bin Hsieh
    Jenq-Shiou Leu
    [J]. Wireless Networks, 2018, 24 : 2915 - 2926
  • [2] Implementation and Evaluation of SIP-based Secure VoIP Communication System
    Kim, JoongMan
    Yoon, SeokUng
    Jeong, HyunCheol
    Won, YooJae
    [J]. EUC 2008: PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON EMBEDDED AND UBIQUITOUS COMPUTING, VOL 2, WORKSHOPS, 2008, : 356 - 360
  • [3] Implementing a secure VoIP communication over SIP-based networks
    Hsieh, Wen-Bin
    Leu, Jenq-Shiou
    [J]. WIRELESS NETWORKS, 2018, 24 (08) : 2915 - 2926
  • [4] Demonstration of Spam and Security Mechanism in SIP-based VoIP Services
    Choi, Jaesic
    Chae, Kangseok
    Choi, Jaeduck
    Jung, Souhwan
    [J]. 2009 6TH IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, VOLS 1 AND 2, 2009, : 52 - 53
  • [5] The implementation of prepaid services over the SIP-based VoIP network
    Yu, LC
    Chen, TL
    Yang, WZ
    [J]. ITRE 2005: 3rd International Conference on Information Technology: Research and Education, Proceedings, 2005, : 151 - 155
  • [6] Prototyping SIP-based VoIP services in Java']Java.
    Zou, H
    Wang, HM
    Mao, WX
    Wang, B
    Focant, S
    Handekyn, K
    Chantrain, D
    Marly, N
    [J]. 2000 INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY PROCEEDINGS, VOLS. I & II, 2000, : 1395 - 1399
  • [7] Audio CAPTCHA for SIP-Based VoIP
    Soupionis, Yannis
    Tountas, George
    Gritzalis, Dimitris
    [J]. EMERGING CHALLENGES FOR SECURITY, PRIVACY AND TRUST: 24TH IFIP TC 11 INTERNATIONAL INFORMATION SECURITY CONFERENCE, SEC 2009, PROCEEDINGS, 2009, 297 : 25 - 38
  • [8] An efficient scheme for supporting personal mobility in SIP-based VoIP services
    Wang, Tsan-Pin
    Chiu, KauLin
    [J]. IEICE TRANSACTIONS ON COMMUNICATIONS, 2006, E89B (10) : 2706 - 2714
  • [9] User Location Management for Personal Mobility in SIP-based VoIP Services
    Wang, Tsan-Pin
    Lee, Hsin-Yu
    [J]. 2008 THIRD INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA, VOLS 1-3, 2008, : 865 - +
  • [10] An improved Authentication Protocol for SIP-based VoIP
    Naqvi, Husnain
    Chaudhry, Shehzad Ashraf
    Mahmood, Khalid
    [J]. PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON RECENT ADVANCES IN COMPUTER SYSTEMS, 2016, 38 : 7 - 12