[VOIPSEC] Actual Attacks

Christopher A. Martin chris at sip1.com
Tue Feb 22 23:23:01 CST 2005


I think that there is a difference on the point of DoS attack. 

SBC's are generally more  robust and designed to withstand attack to a
point...the DoS that is most realistic to an SBC, properly deployed, say in
a carrier network, is not bandwidth related, but rather application related
(bugs or flaws in the application or capacity issues [number of sessions per
second that the SBC or the carriers proxy can withstand]).

With an SBC deployed the endpoint need not be aware of the DoS being
performed against it, at least directly to the endpoints bandwidth...

Another benefit of this is that attackers are not aware of the endpoints
address meaning that the attacker cannot launch any other application or
network related attacks directly against the endpoint...to attempt to
exploit the endpoint, however when the bad guys figure out what they may be
able to perform using VoIP this may not become true unless the vendors
defend against these attacks, much like spam prevention and other similar
technology...

There is no need to advertise the endpoints address just because someone
wants to place a phone call... :)
________________________________

Christopher A. Martin
P.O. Box 1264
Cedar Hill, Texas 75106
 
Domains.SIP1.com
http://domains.sip1.com 
Low cost domain name registration & other Internet services.
 
Sign up for your PayPal merchant account today and start selling your
products on line today!
https://www.paypal.com/us/mrb/pal=Q622ZEE3CUWM8
 

> -----Original Message-----
> From: Voipsec-bounces at voipsa.org [mailto:Voipsec-bounces at voipsa.org] On
> Behalf Of Brian Rosen
> Sent: Tuesday, February 22, 2005 2:06 PM
> To: 'Geoff Devine'; Voipsec at voipsa.org
> Subject: RE: [VOIPSEC] Actual Attacks
> 
> Okay, but what is the difference between a DoS attack on the SBC and a DoS
> attack on the endpoint?  And what makes you think that making the endpoint
> "anonymous", but addressable (albeit indirectly) stops a DoS attack?
> 
> This is a form of security by obscurity, and does not offer any real
> security.  SBCs may have some positive security benefits, but
> anonymization
> of the addresses is not one of them.  In  fact it makes the system more
> brittle by increasing the number of vulnerablilities (you have two chances
> to have a broken implementation instead of one).
> 
> Brian
> 
> > -----Original Message-----
> > From: Voipsec-bounces at voipsa.org [mailto:Voipsec-bounces at voipsa.org] On
> > Behalf Of Geoff Devine
> > Sent: Tuesday, February 22, 2005 11:17 AM
> > To: Voipsec at voipsa.org
> > Subject: RE: [VOIPSEC] Actual Attacks
> >
> > Christopher A. Martin <chris at sip1.com> writes:
> >
> > > - Standard DoS today in terms of flooding cannot be stopped, but it
> > can be
> > > handled in the Internet backbone (which often occurs transparently
> > > so the rest of us don't see it).
> > >
> > > - Also standard precautions, such as deploying SIP aware firewalls or
> > border
> > > controllers which handle the media dynamically prevent a majority of
> > port
> > > scans and other direct attacks which low end devices are typically
> > > susceptible to.
> >
> > A side effect of using session controllers and their brethren in a VoIP
> > architecture is that you make the IP address of the endpoint anonymous.
> > This addresses both privacy concerns and makes DoS attacks against a
> > subscriber endpoint less likely.  Any architecture that permits media
> > streams to flow directly between subscriber endpoints is very vulnerable
> > to DoS attacks on those endpoints.
> >
> > Geoff
> >
> > _______________________________________________
> > Voipsec mailing list
> > Voipsec at voipsa.org
> > http://voipsa.org/mailman/listinfo/voipsec_voipsa.org
> >
> 
> 
> 
> 
> _______________________________________________
> Voipsec mailing list
> Voipsec at voipsa.org
> http://voipsa.org/mailman/listinfo/voipsec_voipsa.org





More information about the Voipsec mailing list