施添登- 以RTP 通信協定實現身份鑑別與不可否認性的方法
[ 摘要 ]
由於網路電話興起,企業與家庭用戶可以透過網際網路完成資訊與語音訊號整合服務,伴隨而來,卻是不可輕忽的網路安全議題,根據美國商業周刊(Business Week)報導,網路電話對於駭客及數位損害敏感性不下於其他任何以網路為基礎的應用程式。
網路電話廣泛利用IETF所制定SIP(Session Initiation Protocol)標準與RTP(Real-time Transport Protocol)來實現通信呼叫與媒體訊息傳遞,其應用以TCP/UDP通信協定為背景,也因此繼承了傳統IP網路可能遭受的威脅,如機密性(confidentiality)與鑑別性(authentication)議題等。企業使用網路電話,促使成為商業溝通管道,如何強化其不可否認性,來實踐商業價值,是網路電話應用另一個議題。RFC3261使SIP通信協定具有機密性與鑑別性安全規範,但要在Internet上提供一個達到end to end安全機制,仍存在許多有待克服與標準化議題。本研究朝向以RTP傳送語音訊息中實作具有Error Correction 機制的資訊隱藏(Information Hiding)技術,透過夾帶數位簽章(DS),來傳遞身分識別機能,實現身份鑑別與不可否認,藉此提供一個可選擇的安全機制。
[ 英文摘要 ]
Since VOIP has become popular for corporations and individuals to exchange information and voice through the internet, the convenience comes along with some security problems. According to Business Week, VOIP may possibly be attacked by hackers as other internet application.
VOIP has realized call signaling and media data delivery with SIP (Session Initiation Protocol) and RTP (Real-time Transport Protocol) which are established by IETF. Since VOIP has the same background (TCP/UDP) as IP network, there might be a threat to confidentiality and authentication as well. It is important to intensify the non-repudiation especially when corporations use VOIP to make business communications. RFC3261 has standardized confidentiality and authentication by SIP; however, we still have some problems to solve in order to offer security from end to end on the internet. Therefore, my research suggests a security system that can implement authentication and non-repudiation on RTP protocol. We will utilize the technology of Error Correction and Information Hiding that can carry identification by voice data.
95級碩士論文-基於P2P SIP環境下之網路語音監聽機制
林慶興 基於P2P SIP環境下之網路語音監聽機制
[ 摘要 ]
隨著網際網路的蓬勃發展,現有的PSTN 電信網路在未來幾年內將會被以IP技術為基礎的網路取而代之。在現有的眾多技術中,又以Session Initial Protocol(SIP)最受到大家的注目,SIP主要是用於建立、修改、終止各種多媒體會議,其簡單、快速等特性也受到了許多通訊工業的重要組織所採用。然而,SIP本身是基於Internet所設計的協定,因此也繼承了Internet本身的弱點。
因此,我們從最近發生在VoIP網路中的攻擊事件中進行分析發現,VoIP網路的安全性並沒有辦法跟建立在PSTN上的電信網路相提並論。本研究預計導入目前IETF草案制定中的P2PSIP為基礎,該草案利用P2P其沒有固定的Server以及快速找尋新Super node 的特性,可大大地減少VoIP 網路被破壞的機率,用以取代傳統的Client-Server架構。
VoIP的監聽在目前是一項具有爭議性議題,如何進行有效管理必須仰賴協定以及制度推行者有共同協商,為此各學者做法皆不盡相同,而P2P SIP是一種新興架構,本研究預計在此一新型態架構下提出監聽辦法,實為一項新挑戰,但考量日後VoIP發展,以及P2P應用服務逐漸廣為接受,本研究的議題想必能被凸顯其貢獻。有鑑於此,本研究預計提出一個基於P2P SIP環境下,能夠允許監聽在P2P架構下,以SIP為通訊初始化協定的VoIP系統。
[ 英文摘要 ]
Recently, according to great progressing of the information technology on Internet, so people can communication with everyone by various technologies. The technologies include e-mail, instant message, VoIP.
Many illegal behaviors are use PSTN to communication with each other. In the future, there will avoid the intercept by use VoIP/instant message to communication with anyone. Therefore, all countries are facing the new challenge – intercept on VoIP.
It’s important and impatient to develop the interception system on VoIP. For this reason, this research, based on P2PSIP framework, proposes a VoIP Monitoring System, which intercepts both real-time vocal between the communicating parties.. Therefore, the implemented prototype is consisted of VoIP Interception Module. VoIP Interception Module applies MITM in intercepting the vocal.
[ 摘要 ]
隨著網際網路的蓬勃發展,現有的PSTN 電信網路在未來幾年內將會被以IP技術為基礎的網路取而代之。在現有的眾多技術中,又以Session Initial Protocol(SIP)最受到大家的注目,SIP主要是用於建立、修改、終止各種多媒體會議,其簡單、快速等特性也受到了許多通訊工業的重要組織所採用。然而,SIP本身是基於Internet所設計的協定,因此也繼承了Internet本身的弱點。
因此,我們從最近發生在VoIP網路中的攻擊事件中進行分析發現,VoIP網路的安全性並沒有辦法跟建立在PSTN上的電信網路相提並論。本研究預計導入目前IETF草案制定中的P2PSIP為基礎,該草案利用P2P其沒有固定的Server以及快速找尋新Super node 的特性,可大大地減少VoIP 網路被破壞的機率,用以取代傳統的Client-Server架構。
VoIP的監聽在目前是一項具有爭議性議題,如何進行有效管理必須仰賴協定以及制度推行者有共同協商,為此各學者做法皆不盡相同,而P2P SIP是一種新興架構,本研究預計在此一新型態架構下提出監聽辦法,實為一項新挑戰,但考量日後VoIP發展,以及P2P應用服務逐漸廣為接受,本研究的議題想必能被凸顯其貢獻。有鑑於此,本研究預計提出一個基於P2P SIP環境下,能夠允許監聽在P2P架構下,以SIP為通訊初始化協定的VoIP系統。
[ 英文摘要 ]
Recently, according to great progressing of the information technology on Internet, so people can communication with everyone by various technologies. The technologies include e-mail, instant message, VoIP.
Many illegal behaviors are use PSTN to communication with each other. In the future, there will avoid the intercept by use VoIP/instant message to communication with anyone. Therefore, all countries are facing the new challenge – intercept on VoIP.
It’s important and impatient to develop the interception system on VoIP. For this reason, this research, based on P2PSIP framework, proposes a VoIP Monitoring System, which intercepts both real-time vocal between the communicating parties.. Therefore, the implemented prototype is consisted of VoIP Interception Module. VoIP Interception Module applies MITM in intercepting the vocal.
95級碩士論文-基於SIP協定實現網路電話系統安全檢測機制
劉作仁 基於SIP協定實現網路電話系統安全檢測機制
[ 摘要 ]
近年來隨著資訊科技的進步,現代人生活中使用資訊科技的比例也日益增加,再加上資訊科技所帶來的便利性,其相關產品及服務逐漸成為現代人生活中不可或缺的一部份。同時,由於網際網路的蓬勃發展,除了原有電話、手機、傳真…等通訊方式之外,其他基於網際網路所開發的通訊工具,如:電子郵件、即時訊息(Instant Message)以及網路電話(Voice over IP, VoIP)…等,也讓現代人在挑選通訊媒介時有了更多的選擇性。
許多新興的資訊科技猶如雙面刃,在給社會大眾往往只看到這些資訊科技所帶來便利之處,殊不知背後卻隱藏了許多不為人知的危機。舉例來說,目前使用於網路電話的SIP協定便是基於網際網路所設計的,因此也繼承了目前在網際網路上現有的攻擊。為了解決資訊安全的問題,許多弱點掃描的軟體也因應而生,而弱點掃描軟體所提供的結果報告對於缺乏經驗的系統管理者而言,這份報告只能提供目前系統有哪些弱點存在,並沒有辦法找出這些弱點之間的相關性。
因此,本研究利用滲透測試進行網路電話系統安全性檢測機制,搭配使用攻擊樹模擬駭客攻擊之手法以及不同的測試個案對網路電話系統進行檢測。以期能夠幫助缺乏經驗的使用者,找出網路電話系統中所存在的漏洞,並提供該漏洞的解決方法。
[ 英文摘要 ]
In recent years, with advances in IT, modern people living in the use of IT in increasing the proportion, together with the information technology brought about by the convenience, its products and services related to modern life has gradually become an integral part of the life. At the same time, due to the vigorous development of the Internet, in addition to the phone, cellular phone, fax and other means of communication, the other communication tools which developed on the Internet, such as: e-mail, instant messaging and VoIP (Voice over IP, VoIP) and so on, also bring modern people more options to choosing communication medium.
Many of the emerging information technology like a double-sided blade, in the community only see that these are often only brought about by information technology facilities of the Department, hardly realize that they hide behind a lot of unknown crisis. For instance, SIP, the most use of the VoIP, is a protocol that designed based on the Internet; it inherited the current available on the Internet vulnerability. In order to solve the information security issue, the more and more vulnerability scanner to be born. The report produced by vulnerability scanner for lack of experience of system managers can only inform the current system has vulnerabilities which might be used, and no way to find the correlation between each vulnerabilities.
Therefore, this study uses penetration test and attack tree designing a mechanism to inspect VoIP system security. Managers who are lack of experience forward to helping the system administrator to find out within the organization by the operation of the VoIP system in the existence of leaks, and provide the solution to the leaks.
[ 摘要 ]
近年來隨著資訊科技的進步,現代人生活中使用資訊科技的比例也日益增加,再加上資訊科技所帶來的便利性,其相關產品及服務逐漸成為現代人生活中不可或缺的一部份。同時,由於網際網路的蓬勃發展,除了原有電話、手機、傳真…等通訊方式之外,其他基於網際網路所開發的通訊工具,如:電子郵件、即時訊息(Instant Message)以及網路電話(Voice over IP, VoIP)…等,也讓現代人在挑選通訊媒介時有了更多的選擇性。
許多新興的資訊科技猶如雙面刃,在給社會大眾往往只看到這些資訊科技所帶來便利之處,殊不知背後卻隱藏了許多不為人知的危機。舉例來說,目前使用於網路電話的SIP協定便是基於網際網路所設計的,因此也繼承了目前在網際網路上現有的攻擊。為了解決資訊安全的問題,許多弱點掃描的軟體也因應而生,而弱點掃描軟體所提供的結果報告對於缺乏經驗的系統管理者而言,這份報告只能提供目前系統有哪些弱點存在,並沒有辦法找出這些弱點之間的相關性。
因此,本研究利用滲透測試進行網路電話系統安全性檢測機制,搭配使用攻擊樹模擬駭客攻擊之手法以及不同的測試個案對網路電話系統進行檢測。以期能夠幫助缺乏經驗的使用者,找出網路電話系統中所存在的漏洞,並提供該漏洞的解決方法。
[ 英文摘要 ]
In recent years, with advances in IT, modern people living in the use of IT in increasing the proportion, together with the information technology brought about by the convenience, its products and services related to modern life has gradually become an integral part of the life. At the same time, due to the vigorous development of the Internet, in addition to the phone, cellular phone, fax and other means of communication, the other communication tools which developed on the Internet, such as: e-mail, instant messaging and VoIP (Voice over IP, VoIP) and so on, also bring modern people more options to choosing communication medium.
Many of the emerging information technology like a double-sided blade, in the community only see that these are often only brought about by information technology facilities of the Department, hardly realize that they hide behind a lot of unknown crisis. For instance, SIP, the most use of the VoIP, is a protocol that designed based on the Internet; it inherited the current available on the Internet vulnerability. In order to solve the information security issue, the more and more vulnerability scanner to be born. The report produced by vulnerability scanner for lack of experience of system managers can only inform the current system has vulnerabilities which might be used, and no way to find the correlation between each vulnerabilities.
Therefore, this study uses penetration test and attack tree designing a mechanism to inspect VoIP system security. Managers who are lack of experience forward to helping the system administrator to find out within the organization by the operation of the VoIP system in the existence of leaks, and provide the solution to the leaks.
訂閱:
文章 (Atom)
RSS Feed
Twitter