[VOIPSEC] Security of SIP over UDP

dirk.pollet at belgacom.be dirk.pollet at belgacom.be
Fri Feb 18 11:09:13 CST 2005


Looking at VoIP services for consumers, we're wondering about the risk
of SIP over UDP.

How easy is the spoofing of SIP messages, and has anyone already
experienced problems such as DOS attacks, call interruptions, call
manipulations, etc. ? Has anyone knowledge of the existence of hacking
tools to send spoofed SIP messages over UDP ?

Secondly, should someone attack a SIP server using spoofed SIP messages
over UDP, we assume that it is very difficult to react / protect against
it. Any ideas/suggestions ?

Are there commercial SIP implementations that accept only SIP over TCP ?
Any known important inconveniences of using only SIP over TCP ?

Regards
Dirk
dirk.pollet at belgacom.be




**** DISCLAIMER ****
http://www.belgacom.be/maildisclaimer


More information about the Voipsec mailing list