摘要
针对会话初始协议(session initial protocol,SIP)简单、开放、易扩展的特点,对RFC3261中提出的几种安全机制进行了深入分析,指出了SIP网络面临的一些典型攻击和安全威胁。鉴于目前SIP网络面临的安全风险,对端到端和逐段转接的保护机制分别进行研究,探讨了HTTP认证、S/MIME、IPSec、TLS和SIPSURI等安全策略,并详细阐述了在SIP网络中实现这些安全服务所采用的各种安全框架模型。
Aimed at the characteristics of the simple and open and extensible SIP, after analyzing several security mechanisms suggested in RCF3261, some typical attacks and security threat confronted with SIP network are analyzed. In view of the security risk now SIP network faced with, the author made a comprehensive research on end-to-end and hop-by-hop protection mechanism, as well as HTTP authentication, S/SMIME, IPSec, TLS, SIPS URI, and so on. In addition, the framework of various kinds of security models to offer these security services in the network of SIP is exolained in detail.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第18期4347-4350,4353,共5页
Computer Engineering and Design
基金
国家863高技术研究发展计划基金项目(2005AA132015)。
关键词
会话初始协议
安全威胁
安全机制
认证
加密
SIP
security threat
security mechanism
authentication
encryption