Judging from my recent experience, at least one North American SIP trunk provider has not understood the importance of SIP authentication.
While working on a customer’s VoIP system, I noticed that SIP messages sent from their PBX to their SIP trunk provider were triggering an immediate response, without the usual authentication challenge.
This meant that the trunk was not bothering to authenticate call requests, leaving the system open to a toll fraud and other attacks.
The SIP standard specifies a challenge/response authentication mechanism. A well regulated SIP trunk should implement this.
When a device such as PBX attempts to make a call, the trunk should refuse the initial request and challenge the PBX to re-try with the appropriate authentication credentials. When the requesting device receives this challenge, it uses information stored in its configuration database to respond.
The North American trunk provider (who will remain nameless) had issued authentication credentials for the SIP trunk circuits, and the customer had diligently added this information to the PBX’s configuration database.
Unfortunately, for a reason that still remains unclear, the provider seemed unable to configure their own systems properly, so both registration requests and call requests went completely unchallenged. This problem has two very serious consequences.
Continued on next page Tags: VOIP security
Hot Topics

Office web is the latest addition to Microsoft's Office business suite and is set to be the company's most revolutionary version.

Microsoft's 14th version of its award winning, multi-billion dollar cash cow business suite, is the company's most ambitious to date.

Spotify is certainly one of the most popular online music websites in the world which is a feat for a service that was officially launched only in February 2009
Featured Content
- The New Voice of the CIO. 158 CIOs in midsized businesses across 31 countries reveal their insights and vision for enhancing
competitiveness over the next five years.
Download Document
Customer Case Studies
- How a wine wholesaler improved the flow of information
Download full case study
- The server that made an entire university smarter
Download full case study
Videos
Latest Tweets

Comments