Full Text Available

Note: Clicking the button above will open the full text document at the original institutional repository in a new window.

Privacy in Voice-over-IP mitigating the risks at SIP intermediaries

Dissertation (MSc)--University of Pretoria, 2010.

Saved in:
Bibliographic Details
Other Authors: Olivier, Martin S.
Format: Thesis
Published: University of Pretoria 2013
Subjects:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1867613485385383936
access_status_str Open Access
author2 Olivier, Martin S.
author_browse Olivier, Martin S.
author_facet Olivier, Martin S.
collection Thesis
dc_rights_str_mv © 2009, University of Pretoria. All rights reserved. The copyright in this work vests in the University of Pretoria. No part of this work may be reproduced or transmitted in any form or by any means, without the prior written permission of the University of Pretoria.
description Dissertation (MSc)--University of Pretoria, 2010.
format Thesis
id oai:repository.up.ac.za:2263/27702
institution University of Pretoria (South Africa)
last_indexed 2026-06-10T12:36:53.925Z
license_str Other — see source repository
provenance_str_mv Harvested via OAI-PMH from UPSpace — University of Pretoria Institutional Repository
publishDate 2013
publishDateRange 2013
publishDateSort 2013
publisher University of Pretoria
publisherStr University of Pretoria
record_format dspace
source_str UPSpace — University of Pretoria Institutional Repository
spelling oai:repository.up.ac.za:2263/27702 Privacy in Voice-over-IP mitigating the risks at SIP intermediaries Olivier, Martin S. jozzi@intdev.co.za Neumann, Thorsten Information leaking Privacy Sip protocol Voice-over-ip Telecommunication Next generation networks Trusted intermediaries Zed UCTD Dissertation (MSc)--University of Pretoria, 2010. Telephony plays a fundamental role in our society. It enables remote parties to interact and express themselves over great distances. The telephone as a means of communicating has become part of every day life. Organisations and industry are now looking at Voice over IP (VoIP) technologies. They want to take advantage of new and previously unavailable voice services. Various interested parties are seeking to leverage the emerging VoIP technology for more flexible and efficient communication between staff, clients and partners. <o>VoIP is a recent innovation enabled by Next Generation Network (NGN). It provides and enables means of communication over a digital network, specifically the Internet. VoIP is gaining wide spread adoption and will ultimately replace traditional telephony. The result of this trend is a ubiquitous, global and digital communication infrastructure. VoIP, however, still faces many challenges. It is not yet as reliable and dependable as the current Public Switched Telephone Network (PSTN). The employed communication protocols are immature with many security flaws and weaknesses. Session Initiation Protocol (SIP), a popular VoIP protocol does not sufficiently protect a users privacy. A user’s information is neither encrypted nor secured when calling a remote party. There is a lack of control over the information included in the SIP messages. Our specific concern is that private and sensitive information is exchanged over the public internet. This dissertation concerns itself with the communication path chosen by SIP when establishing a session with a remote party. In SIP, VoIP calls are established over unknown and untrusted intermediaries to reach the desired party. We analyse the SIP headers to determine the information leakage at each chosen intermediary. Our concerns for possible breach of privacy when using SIP were confirmed by the findings. A user’s privacy can be compromised through the extraction of explicit private details reflected in SIP headers. It is further possible to profile the user and determine communication habits from implicit time, location and device information. Our research proposes enhancements to SIP. Each intermediary must digitally sign over the SIP headers ensuring the communication path was not be altered. These signatures are added sequentially creating a chain of certified intermediaries. Our enhancements to SIP do not seek to encrypt the headers, but to use these intermediary signatures to reduce the risk of information leakage. We created a model of our proposed enhancements for attaching signatures at each intermediary. The model also provides a means of identifying unknown or malicious intermediaries prior to establishing a SIP session. Finally, the model was specified in Z notation. The Z specification language was well suited to accurately and precisely represent our model. This formal notation was adopted to specify the types, states and model behaviour. The specification was validated using the Z type-checker ZTC. Copyright Computer Science unrestricted 2013-09-07T12:05:57Z 2010-09-02 2013-09-07T12:05:57Z 2010-04-12 2010-09-02 2010-09-02 Dissertation Neumann, T 2009, Privacy in Voice-over-IP mitigating the risks at SIP intermediaries, MSc dissertation, University of Pretoria, Pretoria, viewed yymmdd < http://hdl.handle.net/2263/27702 > E10/436/gm http://hdl.handle.net/2263/27702 http://upetd.up.ac.za/thesis/available/etd-09022010-191200/ © 2009, University of Pretoria. All rights reserved. The copyright in this work vests in the University of Pretoria. No part of this work may be reproduced or transmitted in any form or by any means, without the prior written permission of the University of Pretoria. application/pdf University of Pretoria
spellingShingle Information leaking
Privacy
Sip protocol
Voice-over-ip
Telecommunication
Next generation networks
Trusted intermediaries
Zed
UCTD
Privacy in Voice-over-IP mitigating the risks at SIP intermediaries
title Privacy in Voice-over-IP mitigating the risks at SIP intermediaries
title_full Privacy in Voice-over-IP mitigating the risks at SIP intermediaries
title_fullStr Privacy in Voice-over-IP mitigating the risks at SIP intermediaries
title_full_unstemmed Privacy in Voice-over-IP mitigating the risks at SIP intermediaries
title_short Privacy in Voice-over-IP mitigating the risks at SIP intermediaries
title_sort privacy in voice over ip mitigating the risks at sip intermediaries
topic Information leaking
Privacy
Sip protocol
Voice-over-ip
Telecommunication
Next generation networks
Trusted intermediaries
Zed
UCTD
url http://hdl.handle.net/2263/27702
http://upetd.up.ac.za/thesis/available/etd-09022010-191200/