標題: Honeypot-based VoIP防禦系統
Honeypot-based VoIP Protection System
作者: 蔡威廷
Tsai, Wei-Ting
關鍵字: VoIP;網路語音;SIP;IDS;FSM;Honeypot;會話啟始協定;入侵偵測系統;有限狀態機;蜜罐
出版社: 資訊科學與工程學系所
隨著網路普及化,電腦設備的低廉,透過網路交談(Voice over Internet Protocol)變成了一種新的通訊趨勢,通訊變得更加便利、快速,也進而降低通訊成本。訊令啟始協定SIP(Session Initiation Protocol)是目前最普遍負責控制VoIP通話建立的訊令控制協定,絕大部分攻擊的目標都是從此下手,又因為SIP是應用層的通訊協定,存在著不少網路協定存在的弱點與威脅,為了維護正常使用者的權益,安全防範的工作就日益重要,目前大部分運用一些現有的方法:HTTP digest、TLS(Transport Layer Security)、secure SIP(SIPS)、IP security(IPsec)及S/MIME(Secure MIME)等方法維護系統的安全性。
除了利用現行的技術之外,入侵偵測系統( Intrusion Detection System, IDS )提供管理者在攻擊展開攻擊之前,偵測出攻擊產生並發出警訊,管理者能夠提早做好防備,然而入侵偵測系統很大的問題是警訊的數量為其龐大,一天內可能已經累積數萬筆,必需要透過篩選或是經由軟體去分析。本文中參考目前常見之VoIP相關的攻擊手法,利用攻擊樹(Attack Tree)的架構做為分類,試著完整的表現出各種針對VoIP的攻擊。此外,我們利用Honeypot的概念,設計出用來收集攻擊者資訊的SIP服務使用者,刻意部署SIP通訊服務,與攻擊者之間進行互動,藉著紀錄攻擊者的行為,以彌補入侵偵測系統在收集資訊上不足的缺點。並且在入侵偵測系統上,分析收集到的攻擊者來源的警訊,藉此提升發現真正攻擊行為的機率,改善入侵偵測系統的效率,以期有效地減少損害的程度。

With the Internet being universal, it becomes a new trend to communicate with others through Voice over Internet Protocol (VoIP). Communication is getting more populous. Session Initiation Protocol (SIP) is in charge of controlling the signaling of communication establishment. Because SIP is a communication protocol of application layer, a lot of weakness and threats are possible. At present, most commonly de facto standardization protocols, such as HTTP digest, Transport Layer Security (TLS), secure SIP (SIPS), IP security (IPsec) and Secure MIME (S/MIME), are employed to meet the system security requirement.
In addition to the proposals of standardization techniques, an IDS can provide system managers an alert message before assailant attacks are taking place. The critical challenge of IDS is the large amount of alert occurrences within a short period of time. In the paper, we will assort the VoIP-related assailments by attack tree, and also forge the communications between users and attackers by using Honeypot to collect the information of the despiteful attackers. The Honeypot-based user agent will not only supplement the deficiency in the information collection by Intrusion Detection Systems, but also increase the probability of capturing real invaders. We expect to effectively protect SIP services from damages caused by malicious attacks.
