论文部分内容阅读
SIP(Session Initiation Protocol,会话初始协议)是常用的支持多媒体会话的信令控制协议。RTP(Real-time Transport Protocol,实时传输协议)是提供语音等实时特性端到端传输的媒体控制协议。随着VoIP技术在通信领域的应用日益广泛,与之相关的安全问题也成为了业界研究的重点。文中介绍了基于SIP的VoIP系统中有关RTP的攻击,通过协议与报文分析,深入分析并实现了窃听攻击与RTP注入攻击,证明了这两种协议存在安全漏洞,最后提出了防范这些攻击的方案,为提高VoIP系统的安全性提供了参考。
SIP (Session Initiation Protocol, Session Initiation Protocol, Session Initiation Protocol) is a commonly used signaling control protocol that supports multimedia sessions. Real-time Transport Protocol (RTP) is a media control protocol that provides end-to-end transmission of real-time features such as voice. With the increasingly wide application of VoIP technology in the field of communications, the related security issues have also become the focus of the industry research. In this paper, we introduce the attacks on RTP in SIP based VoIP system. Through protocol and packet analysis, we deeply analyze and implement eavesdropping attack and RTP injection attack. It proves that these two protocols have security vulnerabilities. Finally, Program, to improve the security of VoIP system provides a reference.