by: versha thakur shravani aishwarya sai kamal. the session initiation protocol (sip) is a simple...
TRANSCRIPT
![Page 1: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/1.jpg)
Ensuring Information Confidentiality and Securing SIP
Messages
By:
Versha Thakur
Shravani Aishwarya
Sai Kamal
PROJECT PRESENTATION ON
![Page 2: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/2.jpg)
INTRODUCTION
The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand.
SIP has four major functions:
a) Locate and end-point,
b) Initiate a signal,
c) Ensure compatibility and start a session,
d) Terminate the session
![Page 3: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/3.jpg)
CONTD…With SIP you have to solve five major problems:
Caller-I.D
Called Party I.D
Media Privacy
Media Authentication
Signaling Confidentiality
![Page 4: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/4.jpg)
SIP SECURITY ISSUES
There is no way of asserting that the calling party is an authenticated user/peer on the network.
To understand the security detail & to suggest a better deployment technique.
![Page 5: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/5.jpg)
TRANSPORT LAYER SECURITY (TLS)
Provides communication security over Internet.
Session key used to encrypt data flowing between parties.
Property : Forward Secrecy
TLS is successor of SSL(Secure Socket Layer).
![Page 6: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/6.jpg)
![Page 7: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/7.jpg)
![Page 8: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/8.jpg)
![Page 9: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/9.jpg)
![Page 10: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/10.jpg)
![Page 11: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/11.jpg)
![Page 12: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/12.jpg)
PROBLEMS FACED Library that asterisk requires to use TLS is not
there.
Old version of open SSL
SIP registers work but secure TLS need to be secure with asterisk
“Polycom” version of TLS could be outdated, compared to astersik- required new phones.
SSL on phone & server are incompatible.
![Page 13: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/13.jpg)
CONCLUSION
Whether or not all methods have been used.
Few VoIP service providers use these techniques.
No permanent reduction of the effects of SIP hacks & security related problems.
SIP can revolutionize the VoIP industry now with the advent of VoLTE.
But only if the security, media privacy and authentication issues are addressed and solved.
![Page 14: By: Versha Thakur Shravani Aishwarya Sai Kamal. The Session Initiation Protocol (SIP) is a simple text-based protocol that is easy to understand](https://reader036.vdocuments.site/reader036/viewer/2022062517/56649f2f5503460f94c49821/html5/thumbnails/14.jpg)
REFERENCES
http://it.med.miami.edu/x904.xml
http://www.tekelec.com/tekelec-blog/index.php/2010/06/sip-and-secure-communication-what-does-it-mean/#.Uo4vin9N-vU