Security Analysis of Voice-over-IP Protocols

Security Analysis of Voice-over-IP Protocols
复制标题

IP 语音协议的安全分析

DOI:
--
复制
发表时间:
2007
期刊:
IEEE Computer Security Foundations Symposium
影响因子:
--
通讯作者:
Vitaly Shmatikov
Vitaly Shmatikov
中科院分区:
--
文献类型:
--
作者:
Prateek Gupta;Vitaly Shmatikov

文献摘要

被引文献

相似文献

语音通信作为数据报分组在IP网络上的传输(通常称为IP语音(VoIP)电话)正迅速获得广泛接受。随着私人电话通话在不安全的公共网络上进行,VoIP通信的安全性越来越重要。我们提出了一个结构化的VoIP协议栈,其中包括信令(SIP),会话描述(SDP),密钥建立(SDES,MIKEY和ZRTP)和安全媒体传输(SRTP)协议的安全分析。使用手动和工具支持的形式化分析相结合,我们发现了几个设计缺陷和攻击,其中大部分是由VoIP堆栈不同层的协议相互之间的假设之间的微妙不一致引起的。最严重的攻击是对SDES的重放攻击,它会导致SRTP重复用于媒体加密的密钥流,从而完全破坏传输层安全性。我们还演示了一个中间人攻击ZRTP,它允许攻击者说服通信双方,他们已经失去了他们的共享秘密。如果他们使用没有显示器的VoIP设备,因此无法执行“人工认证”过程,则他们被迫进行不安全的通信,或者根本不进行通信,即,这就变成了拒绝服务攻击。最后,我们表明,在MIKEY中使用的密钥推导过程不能用来证明安全密钥交换的标准加密模型中的派生密钥的安全性。
The transmission of voice communications as datagram packets over IP networks, commonly known as voice-over-IP (VoIP) telephony, is rapidly gaining wide acceptance. With private phone conversations being conducted on insecure public networks, security of VoIP communications is increasingly important. We present a structured security analysis of the VoIP protocol stack, which consists of signaling (SIP), session description (SDP), key establishment (SDES, MIKEY, and ZRTP) and secure media transport (SRTP) protocols. Using a combination of manual and tool-supported formal analysis, we uncover several design flaws and attacks, most of which are caused by subtle inconsistencies between the assumptions that protocols at different layers of the VoIP stack make about each other. The most serious attack is a replay attack on SDES, which causes SRTP to repeat the keystream used for media encryption, thus completely breaking transport-layer security. We also demonstrate a man-in-the-middle attack on ZRTP, which allows the attacker to convince the communicating parties that they have lost their shared secret. If they are using VoIP devices without displays and thus cannot execute the "human authentication" procedure, they are forced to communicate insecurely, or not communicate at all, i.e., this becomes a denial of service attack. Finally, we show that the key derivation process used in MIKEY cannot be used to prove security of the derived key in the standard cryptographic model for secure key exchange.