• Apple
  • Mobiles
  • Mobile Services
  • Iphone
  • VoIP
  • SIP Trunk Authentication, who needs it?


    19 February, 2009, by Peter Cox

    Judging from my recent experience, at least one North American SIP trunk provider has not understood the importance of SIP authentication.

    While working on a customer’s VoIP system, I noticed that SIP messages sent from their PBX to their SIP trunk provider were triggering an immediate response, without the usual authentication challenge.   

    This meant that the trunk was not bothering to authenticate call requests, leaving the system open to a toll fraud and other attacks.

    The SIP standard specifies a challenge/response authentication mechanism.  A well regulated SIP trunk should implement this. 

    When a device such as PBX attempts to make a call, the trunk should refuse the initial request and challenge the PBX to re-try with the appropriate authentication credentials. When the requesting device receives this challenge, it uses information stored in its configuration database to respond.

    The North American trunk provider (who will remain nameless) had issued authentication credentials for the SIP trunk circuits, and the customer had diligently added this information to the PBX’s configuration database. 

    Article continues after advert

    Unfortunately, for a reason that still remains unclear, the provider seemed unable to configure their own systems properly, so both registration requests and call requests went completely unchallenged. This problem has two very serious consequences. 

    Continued on next page Tags: VOIP security
    Peter Cox
    Posted by
    Peter Cox
    on 19 February, 2009

    Peter Cox is the founder and CEO of UM Labs Ltd, a company dedicated to researching VoIP security threats and developing effective controls against those threats. He has over 20 years experience of IP application security and was a co-founder of Firewall and email security specialist Borderware Technologies Inc.
    ITProPortal.com - Sponsored Section

    Featured Content

    1. The New Voice of the CIO. 158 CIOs in midsized businesses across 31 countries reveal their insights and vision for enhancing competitiveness over the next five years.

      Download Document

    Customer Case Studies

    1. How a wine wholesaler improved the flow of information
      Download full case study
    2. The server that made an entire university smarter
      Download full case study

    Videos

    Connecting in a smarter planet:

    Latest Tweets





     





    News Now Logo




    Forgot your password?