1 of 57

Preventing Exploitation of Your �VoIP Network

Rohit Dhamankar, Manager of Digital Vaccine�David Endler, Director of Security Research

TippingPoint, a division of 3Com

2 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Service Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

3 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

4 of 57

Introduction - VoIP Security is Holistic

  • VoIP security is built �upon the many�layers of traditional �data security:

5 of 57

Introduction - VoIP Threat Scenarios

  • History has shown that most advances and trends in information technology (e.g. TCP/IP, Wireless 802.11, Web Services, etc.) typically outpace the corresponding realistic security requirements.
  • VoIP is no different, there are a variety of application-level exposures that have yet to be thoroughly documented or identified by vendors and consumers, and attackers for that matter.
  • As VoIP infrastructure becomes more accessible to the common script kiddie, so will the occurrence of attacks.

6 of 57

Introduction – VoIP Introduces New Risks

  • VoIP Networks: Increased Exposure
    • Now prone to many of the same cyber threats of traditional data networks (denial of service, tcp man-in-the-middle, etc.)
    • Some application attacks much easier to perform (toll fraud, eavesdropping, call hijacking, phishing, etc.)
    • VoIP protocols and products have not yet undergone rigorous levels of security scrutiny and testing by the industry
    • As VoIP subscribership increases, so does the number of potential attackers

7 of 57

Introduction – Obligatory VoIP Adoption Slide

8 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

9 of 57

Enterprise VoIP Building Blocks

  • VoIP Telephone: The VoIP phone used by an end-user to make a telephone call. The phone is capable of converting voice into media data packets. The phone may also have advanced features like Web browsing, instant messaging and multi-media conferencing.
  • Call Management Server: Software that runs on a dedicated server platform and offers the functionality of call control and call signaling. This is essentially porting the conventional functions of Private Branch Exchange (PBX) to a dedicated server.
  • Gateway: The network device that connects the IP network and the carrier network such as ISDN or PSTN.
  • Support Services and Infrastructure: MultiPoint Control Units for conferencing, backend services for data tracking of call endpoints, authentication servers etc.

10 of 57

Enterprise VoIP Building Blocks

  • Typical Enterprise VoIP deployments

11 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

12 of 57

VoIP Attacks - VoIP Security is Holistic

  • VoIP security is built �upon the many�layers of traditional �data security:

13 of 57

VoIP Attacks - Slice of VoIP Security Threats

Network Security (IP, UDP , TCP, etc)

Physical Security

Policies and Procedures

OS Security

Supporting Service Security

(web server, database, DHCP)

VoIP Protocol and �Application Security

Weak Voicemail Passwords

Abuse of Long Distance Privileges

Total Call Server Compromise,

Reboot, Denial of Service

Syn Flood, ICMP unreachable, �trivial flooding attacks, DDoS, etc.

SQL Injection, �DHCP resource exhaustion

Buffer Overflows, Worms, Denial of

Service (Crash), Weak Configuration

Toll Fraud, SPIT, Phishing

Malformed Messages (fuzzing)�INVITE/BYECANCEL Floods

CALL Hijacking

Call Eavesdropping�Call Modificaiton

14 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

15 of 57

Vulnerabilities in VoIP Components

SIP Proxy

RedHat Linux

H.323 Gatekeeper

IOS

Softswitch

CallManager

Windows 2000

IIS, MS-SQL,

Apache Tomcat

H.323

HTTP

Skinny

MGCP

Q.931/IP

SIP

RTP

RTCP

Media Server

MCS

Windows 2000

IIS

MS-SQL

Border Router

IOS

Internet

16 of 57

Vulnerabilities in VoIP Components

  • VoIP devices inherit the same vulnerabilities of the operating system or firmware they run on top of (e.g. Cisco Call Manager is typically installed on Windows 2000 and the Avaya Call Manager on Linux.)
  • No matter how secure an actual VoIP application or deployment happens to be, this becomes moot if the underlying operating system is compromised.
  • Many VoIP devices also run Web servers for remote management purposes, which may be vulnerable to attacks ranging from information disclosure to buffer overflows.

17 of 57

Vulnerabilities in VoIP Components - Examples

  • Any denial of service vulnerability in an underlying Cisco IOS running on a Gateway device could potentially be exploited to disrupt the VoIP network.
  • Pingtel Expressa’s VoIP phone has a web interface. Older versions can be exploited to crash the phone by sending an overly long GET request.
  • Some versions of Cisco Call Manager run on Windows and are also vulnerable to the same Windows buffer overflows that have emerged over the last few years (LSASS, Messenger, ASN.1, etc.).

18 of 57

Vulnerabilities in VoIP Components

19 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

20 of 57

Support Services and Infrastructure Dependencies

  • DHCP
  • TFTP
  • DNS
  • HTTP
  • HTTPS
  • Kerberos
  • Syslog
  • LDAP
  • COPS
  • RADIUS

  • SOAP
  • SSH
  • SNMP
  • AAA
  • PAM
  • NTP
  • FTP
  • SFTP
  • Telnet

21 of 57

VoIP Support Services

  • Many of the VoIP devices in their default configuration may have a variety of exposed TCP and UDP ports.
  • If any of the open services are not configured with a password or a weak password, an attacker can get full access.
  • This is a known vulnerability against the Cisco SIP-based phones’ telnet service.

22 of 57

VoIP Component Configuration Weaknesses

  • The SNMP services offered by the devices may be vulnerable to reconnaissance attacks or buffer overflows. In recent security testing, valuable information was gathered from an Avaya IP phone by using SNMP queries with the “public” community name.
  • DHCP Server(s) can be overwhelmed by an attacker

23 of 57

Protection Strategies

  • Apply vendor supplied patches in a timely manner
  • Deploy VoIP aware firewalls
  • Deploy VoIP Intrusion Prevention Solutions
    • Protects when the vendor doesn’t have a patch
    • Buys time to apply patches enterprise wide
  • Restrict logical network access to critical servers and VoIP call processors
  • Change default password on the firmware
  • Perform vendor installation security checklist (if it exists)

24 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

25 of 57

Network Infrastructure Attacks

  • The quality of service of VoIP services directly depends on the availability and security of the network infrastructure they rely upon.
  • SYN floods or other traffic surge attacks that exhaust network resources (e.g. bandwidth, router connection table, etc.) could severely impact all VoIP communications.
  • 2004 CSI/FBI report: "In a shift from previous years, the most expensive computer crime over the past year was due to denial of service.“
  • Worms and viruses can cripple network availability by spewing and scanning

26 of 57

Network Infrastructure Attack Examples

  • ICMP Unreachable: Since SIP can be UDP based, sending a spoofed ICMP “port unreachable” message to the calling party could result in a DoS.
  • Message Integrity and Privacy: The attacker may be able to conduct a man-in-the-middle attack and alter the original communication between two parties.
  • TFTP diversion: Many VoIP devices are configured to periodically download a configuration file from a server through TFTP or other mechanisms. An attacker could potentially divert or spoof this connection and trick the device into downloading a malicious configuration file instead.

27 of 57

Protection Strategies

  • VLAN and logically segment voice and data traffic

28 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

29 of 57

VoIP Protocol Implementation Attacks

  • Functional protocol testing (also called “fuzzing”) is a popular way of finding bugs and vulnerabilities.
  • Fuzzing involves creating different types of packets for a protocol which contain data that pushes the protocol's specifications to the point of breaking them.
  • These packets are sent to an application, operating system, or hardware device capable of processing that protocol, and the results are then monitored for any abnormal behavior (crash, resource consumption, etc.).

30 of 57

VoIP Protocol Implementation Attacks

  • Fuzzing has already led to a wide variety of Denial of Service and Buffer Overflow vulnerability discoveries in vendor implementations of VoIP products that use H.323 and SIP.
  • PROTOS group from the University of Oulu in Finland responsible for high exposure vulnerability disclosures in HTTP, LDAP, SNMP, WAP, and VoIP.
  • http://www.ee.oulu.fi/research/ouspg/protos/index.html

31 of 57

SIP / SDP Message Format

INVITE sip:6713@192.168.26.180:6060;user=phone SIP/2.0

Via: SIP/2.0/UDP 192.168.22.36:6060

From: UserAgent<sip:6710@192.168.22.36:6060;user=phone>

To: 6713<sip:6713@192.168.26.180:6060;user=phone>

Call-ID: 96561418925909@192.168.22.36

Cseq: 1 INVITE

Subject: VovidaINVITE

Contact: <sip:6710@192.168.22.36:6060;user=phone>

Content-Type: application/sdp

Content-Length: 168

v=0

o=- 238540244 238540244 IN IP4 192.168.22.36

s=VOVIDA Session

c=IN IP4 192.168.22.36

t=3174844751 0

m=audio 23456 RTP/AVP 0

a=rtpmap:0 PCMU/8000

a=ptime:20

SDP

Payload

32 of 57

Example Fuzzed Packet

INVITE sip:6713@192.168.26.180:6060;user=phone SIP/2.0

Via: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa

aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa

aaaaaaaaaaaaa…

From: UserAgent<sip:6710@192.168.22.36:6060;user=phone>

To: 6713<sip:6713@192.168.26.180:6060;user=phone>

Call-ID: 96561418925909@192.168.22.36

Cseq: 1 INVITE

Subject: VovidaINVITE

Contact: <sip:6710@192.168.22.36:6060;user=phone>

Content-Type: application/sdp

Content-Length: 168

v=0

o=- 238540244 238540244 IN IP4 192.168.22.36

s=VOVIDA Session

c=IN IP4 192.168.22.36

t=3174844751 0

m=audio 23456 RTP/AVP 0

a=rtpmap:0 PCMU/8000

a=ptime:20

SDP

Payload

33 of 57

Summary of High-Value Target Protocols

  • Intelligent Endpoint Signaling
    • SIP/CMSS
    • H.225/H.245/RAS
  • Master-Slave Endpoint Signaling
    • MGCP/TGCP/NCS
    • Megaco/H.248
    • SKINNY/SCCP
    • Q.931+

  • SS7 Signaling Backhaul
    • SIGTRAN
    • ISTP
    • SS7/RUDP
  • Accounting/Billing
    • RADIUS
    • COPS
  • Media Transfer
    • RTP
    • RTCP

Fuzzing VoIP protocol implementations is only at the tip of the iceberg:

34 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

35 of 57

VoIP Applications Attacks

  • Call Hijacking
  • BYE/CANCEL Denial of Service

36 of 57

Normal Registration

Location Server

Registrar

2. “To contact sip:derek@tpti.com

Use sip:derek@11.5.6.7 for 60 minutes”

derek’s

Phone

1. REGISTER sip:derek@tpti.com

Contact <sip:derek@11.5.6.7>

Expires: 3600

3. 200 OK

37 of 57

Threat Scenario – Registration Hijacking

Location Server

Registrar

2. “To contact sip:derek@tpti.com

Use sip:derek@11.5.6.7 for 60 minutes”

derek’s

Phone

1. REGISTER sip:derek@tpti.com

Contact <sip:derek@11.5.6.7>

Expires: 3600

3. 200 OK

4. “To contact sip:derek@tpti.com

Use sip:mugatu@11.5.6.8 for 30 minutes”

3. REGISTER sip:derek@tpti.com

Contact < mugatu@11.5.6.8 >

Expires: 1800

38 of 57

Threat Scenario – BYE/CANCEL Denial of Service

7. 200 OK

6. INVITE derek@11.5.6.7

8. RTP Coversation

9. SIP BYE derek@11.5.6.7

7. SIP CANCEL derek@11.5.6.7

39 of 57

Authentication Protection Features

  • End to Middle Authentication Background
    • Endpoint Authentication challenge of SIP based networks.

40 of 57

Autentication Protection Features Con’t

41 of 57

Threat Scenario – Killer SIP Messages

Proxy Server (redirect mode)

Location Server

Malformed SIP

Malformed SIP

Malformed SIP

42 of 57

Threat Scenario – RFC Conformance

  • Malformed SIP Messages –INVITE, ACK, BYE, REGISTER, REFER, INFO, CANCEL – known vulnerabilities

INVITE sip:6713@192.168.26.180:6060;user=phone SIP/2.0

Via: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa

aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa

aaaaaaaaaaaaa…

From: UserAgent<sip:6710@192.168.22.36:6060;user=phone>

To: 6713<sip:6713@192.168.26.180:6060;user=phone>

Call-ID: 96561418925909@192.168.22.36

Cseq: 1 INVITE

Subject: VovidaINVITE

Contact: <sip:6710@192.1%s%s%s68.22.36:6060;user=phone>

Content-Type: application/sdp

Content-Length: 168

v=0

o=- 238540244 238540244 IN IP4 192.168.22.36

s=VOVIDA Session

c=IN IP4 192.168.22.36

t=3174844751 0

m=audio 23456 RTP/AVP 0

a=rtpmap:0 PCMU/8000

a=ptime:20

43 of 57

Protection Strategy

  • Enforece SIP RFC conformance (plus extensions)

Proxy Server (redirect mode)

Location Server

Malformed SIP

Malformed SIP

Malformed SIP

44 of 57

Threat Scenario – INVITE/REGISTER/etc Flood

1. INVITE derek@tpti

(spoofed source IP)

2. 302 Moved Temporarily� derek@11.5.6.7

Proxy Server (redirect mode)

Location Server

4: “Where is derek@tpti”

5: “Use derek@11.5.6.7”

Send 10000 INVITES/sec

45 of 57

Threat Scenario – Quality of Service Abuse

46 of 57

Protection Measures

  • Deploy Application Layer Gateway, parse signaling traffic and proxy RTP data.
  • Enforce quality and service and firewall port dynamic assignments across multiple users.
  • Manage NAT/PAT SIP traversal and RTP proxying through existing or new technology
  • Encrypt voice traffic traversing public networks
    • Some components are PacketCable-qualified, implying IPSec supports
    • Enable SIP-TLS and SRTP

47 of 57

Protection Measures

  • Provide physical isolation of network segments using VLANs, VPNS, ARP inspection and port security should be implemented
  • Secure network administration and management through authentication and access control, as well as encryption

48 of 57

Other VoIP Application Attacks

  • Toll Fraud: An attacker can impersonate a valid user/IP phone and use the VoIP network for making free long distance calls.
  • Identity Spoofing: An attacker could forge his Caller-ID credentials to appear to be someone else.
  • Eavesdropping: An attacker with local access to the VoIP LAN may sniff the network traffic and decipher the voice conversations. A tool named VOMIT (voice over misconfigured internet telephones) can be downloaded to easily perform this attack.
  • SPIT: SPAM over IP Telephony
  • PHISHING/CALL-BACK Schemes

49 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

50 of 57

Industry Needs

  • A Central repository to answer fundamental practical questions about VoIP security issues.�
  • Multi-industry group driving security requirements and best practices among vendors and providers.�
  • Free testing methodologies and checklists and tools to help secure infrastructure.�
  • Description and Explanation of current VoIP Security Threats.

51 of 57

Enter VOIPSA

  • The VOICE over IP SECURITY ALLIANCE�
  • VOIPSA's mission is to promote the current state of VoIP security research, VoIP security education and awareness, and free VoIP testing methodologies and tools. �
  • An expansive group of vendors, VoIP providers, and researchers have joined together to participate in these goals. �
  • Great cross membership from standards bodies and other industry groups such as IETF, SIPFORUM, ATIS, etc.

52 of 57

VOIPSA

  • Some Current Members include:

  • Testing Tool Vendors
    • Agilent
    • Codenomicon
    • Spirent Communications

  • Consultants
    • Accenture
    • PriceWaterhouseCoopers
    • Miercom

  • Security Vendors/Providers
    • Borderware
    • Enterasys Networks
    • Foundstone
    • ICSA Labs
    • InfraVAST
    • Insightix
    • Internet Security Systems
    • nCircle
    • Qualys
    • Sonicwall
    • Sourcefire
    • Symantec
    • Tenable Network Security
    • The SANS Institute
    • TippingPoint
    • VeriSign
  • VoIP Providers
    • AT&T
    • Bell Canada
    • Cable and Wireless
    • Charter
    • Cox Communications
    • Level3
    • MCI
    • Qwest
    • SBC
    • Sprint
    • Telcordia
    • Time Warner
    • Verizon Communications

  • VoIP Vendors
    • 3Com
    • Alcatel
    • Alltel
    • Avaya
    • Acme Packet
    • Arbor Networks
    • Enterasys Networks
    • Extreme Networks�Juniper
    • Mitel
    • NetCentrex
    • Nortel
    • Samsung Telecommunications America
    • SecureLogix
    • Siemens
    • Uniden

53 of 57

VOIPSA

  • First two VOIPSA projects launched March 29th 2005:

  • Threat Taxonomy�Definition of a glossary of terms and a taxonomy to organize and describe types of security threats for use by projects within VOIPSA and communications with the press, industry and public.

  • Security Requirements �Development of user profiles and security requirements to guide projects within VOIPSA, such as best practices and testing, and communications with the press, industry and public.

54 of 57

VOIPSA – Participate!

www.voipsa.org

55 of 57

Agenda

  • Introduction to VoIP Security
  • Enterprise VoIP Building Blocks
  • VoIP Attacks (and Protections)
    • Vulnerabilities in VoIP Components (OS, firmware, etc.)
    • Supporting VoIP Services Attacks
    • Network Infrastructure Attacks
    • VoIP Protocol Implementation attacks
    • VoIP Application attacks
  • VOIPSA
  • Conclusion

56 of 57

Conclusion

  • Because VoIP technology is still at the early stage of adoption, attacks against deployments have been largely unheard of or undetected.
  • There are an abundance of vulnerabilities yet to be discovered in the implementations of VoIP protocols through similar protocol fuzzing techniques employed by the PROTOS group.
  • We can expect to see more VoIP application-level attacks occur as attackers become savvier to the technology and gain easier access to test the VoIP infrastructure as it becomes more prevalent across residential areas

57 of 57

Questions?

Thank you very much!

Questions?

rohitd@tippingpoint.com

dendler@tippingpoint.com