There are so many different kinds of threats or attacks in VoIP world. Attackers may disrupt media service by flooding traffic, or collect privacy information by intercepting call, or make fraud calls by spoofing identities. Spammers may utilize VoIP networks to deliver spam calls, instant messages, or presence information, which are more effective than email spams because it is very difficult to filter VoIP spam. Anyway, there are many possible ways to categorize these threats. I would use four categories that most VoIP threats are belonging to: The first group is “threats against availability”: It is a group of threats against service availability that is supposed to be running 24 hours, 7 days a week. That is, these threats aim at VoIP service interruption, typically, in the form of Denial of Service (DoS). The typical examples are Call flooding, Malformed messages (protocol fuzzing), call teardown, Call hijacking (registration or media session hijacking), Server impersonating, Quality of Service (QoS) abuse. The second group is “threats against confidentiality”: It does not impact current communications generally, but provide an unauthorized means of capturing media, identities, patterns, and credentials that are used for subsequent unauthorized connections or other deceptive practices. The typical examples are eavesdropping media, call pattern tracking, data mining, and reconstruction. The third group is “threats against integrity”: It is altering messages or media after intercepting them in the middle of the network. That is, an attacker can see the entire signaling and media stream between endpoints as an intermediary. The alteration can consist of deleting, injecting, or replacing certain information in the VoIP message or media. The typical types of threat at high level are message alteration and media alteration. The forth group is “threats against social context” (as known as “social threat”): It is somewhat different from other technical threats against availability, confidentiality, or integrity, in terms of the intention and methodology. It focuses on how to manipulate the social context between communication parties so that an attacker can misrepresent himself as a trusted entity and convey false information to the target user (victim). The typical threats against social context are Misrepresentation of identity, Spam of call (voice), IM, and presence, Phishing. I’m going to pick some of the threats and describe the details at the next session. If anyone wants to know a specific attack, please let me know.
VoIP Threat Taxonomy
Analysis
Feb 6, 20092 mins




