A Tool for Detecting Theft-of-Service in SIP-based Systems
- 总结
- Lead Inventors: Henning Schulzrinne, Ph.D.Problem or Unmet Need:Session Initiation Protocol (SIP) based Voice-over-IP (VoIP) services are more susceptible to theft of service since calls are established over an IP-based network. Theft of service can happen due to various reasons such as identity assurance, multiple call endpoints, unsolicited intrusion in the VoIP network and of services such as emergency dialing and voicemail access. Many computers may run a soft-phone or a physical phone with Java virtual machine and can be exploited to circumvent security schemes including TLS, S/MIME, or digest authentication mechanisms. Additionally, calls can be routed to unauthorized multiple end-points. Finally, processing spurious SIP requests can lead to compromise of SIP servers. The technology is a software tool that can detect three types of theft of service, i.e., those of identity, multiple call end points, and unsolicited SIP requests. The tool provides a modular web-based interface. It checks if the SIP servers are processing unsolicited messages, whether user is allowed launch simultaneous calls, and the robustness of SIP systems against crafted messages, all in an automated manner.
- 技术优势
- An easy to configure single tool that can be used by the network/security departments of an organization to find vulnerabilities in their VoIP networks An organization interested in purchasing a VoIP system can request potential sellers to verify their security claims against this tool
- 技术应用
- Organizations deployinng VoIP networks Comprehensive tool set for use in QA for telephone service providers Carrier grade VoIP providers
- 详细技术说明
- The technology is a software tool that can detect three types of theft of service, i.e., those of identity, multiple call end points, and unsolicited SIP requests. The tool provides a modular web-based interface. It checks if the SIP servers ar...
- *Abstract
-
None
- *Inquiry
- Calvin Chu Columbia Technology Ventures Tel: (212) 854-8444 Email: TechTransfer@columbia.edu
- *IR
- M07-103
- *Principal Investigation
-
- *Web Links
- USPTO: US 2009/007220-A1
- 国家/地区
- 美国
欲了解更多信息,请点击 这里
