Secure SIP protects VoIP traffic

Opinion
May 1, 20061 min

* Security mechanism helps fill hole in Session Initiation Protocol

Secure SIP protects VoIP traffic

By Michael Ward

Session Initiation Protocol has become the call control protocol of choice for VoIP networks because of its open and extensible nature. However, the integrity of call signaling between sites is of utmost importance, and SIP is vulnerable to attackers when left unprotected.

Secure SIP is a security mechanism defined by SIP RFC 3261 for sending SIP messages over a Transport Layer Security-encrypted channel. Originally used for securing HTTP sessions, TLS can be repurposed to protect SIP session communications from eavesdropping or tampering. By deploying SIP-based devices that support Secure SIP, network administrators benefit from these increased levels of security for their VoIP networks.

Thwarting threats

Companies are concerned about malicious parties eavesdropping on SIP signaling information, performing man-in-the-middle attacks that disrupt service or gaining unauthorized access to VoIP networks.

RFC 3261 defines mechanisms for providing increased security for a SIP session.

To read more, please click here.

Ward is director of product line management at Trinity Convergence. He can be reached at mward@trinityconvergence.com.