50 likes | 169 Vues
VoIP SEAL 2.0 is an advanced security suite designed for SIP-enabled networks, addressing the evolving threats of (D)DoS attacks, interception, and service abuse. The modular, extensible framework provides holistic detection and prevention against diverse security risks, incorporating real-time traffic monitoring and offline analysis of call data records. It features collaborative scoring and personalized protection lists, ensuring adaptable and efficient security tailored to specific network scenarios. Encryption and authentication are essential but not sufficient; a flexible, multifaceted approach is key to safeguarding VoIP infrastructures.
E N D
Thilo Ewald, Nico d’Heureuse, Saverio Niccolini, Jan Seedorf NEC Europe Ltd., Heidelberg, Germany [ewald, dheureuse, niccolini, seedorf]@nw.neclab.eu VoIP SEAL 2.0Security Suite for SIP enabled networks
VoIP SEAL VoIP SEAL • Vision • Attacks on NGN networks will evolve: (D)DoS, Interception and Modification, Abuse of Service (Fraud), Social attacks (e.g., SPIT) • Security and troubleshooting will be fundamental • Key issues • Encryption and authentication will not be enough • No single method of detection and protection • Flexible detection and protection technology is required • Solution • Holistic security detection and preventionframework for SIP-based infrastructures • (VoIP) SEcure Application Level firewall (SEAL) • Modular, extensible and distributed platform • Multiple different SIP-enabled detection andprotection modules cooperate • Easily adaptable to different network scenarios
Operator Operator Stage 2 Stage 2 CDRs Operator Stage 2 Stage 1 Stage 1 CSCF CSCF VoIP SEAL VoIP SEAL VoIP SEAL VoIP SEAL VoIP SEAL VoIP SEAL User User User Stage 1 CSCF Envisioned Deployment Scenarios • Offline analysis • Analysis of call data records, log files, network traces, … • Manual redirection to Stage-2 test (by operator) • Online monitoring • Real-time traffic monitoring • Automatic redirection to Stage-2 test • Inline protection (SEAL 2.0) • Real-time traffic interception • 5 stage protection system
VoIP SEAL - AS HoneyVoIP SBC SIP infrastructure Internet / outer network (unprotected) Operator / Customer network (VoIP SEAL protected) VoIP SEAL 2.0 What changed since IPTComm 2007? • Distributed deployment • Collaborative scoring • SBC • Application Server • User Equipment • Personalization • Personal Black-/WhiteLists • Personal Stage-2 tests • Multi language • Feedback & Configuration via • Web interface • Minibrowser (COTS SIP phone) • Improvements on algorithms - e.g. DTMF-Tests, Greylisting, HoneyVoIP