Vulnerabilities of the Real-Time Transport (RTP) Protocol for Voice over IP (VoIP) Traffic
Over the past decade, Voice over IP (VoIP) has revolutionalized the telecommunications industry. VoIP has become more prevalent than ever, and consequently more users have switched to IP-based data networks for their telephone use from the analogue Public Switched Telephone Network (PSTN).One challenge, though, is to secure and protect these VoIP connections. In this paper, we investigate a ...
VulnerabilitiesoftheReal-TimeTransport(RTP)
ProtocolforVoiceoverIP(VoIP)Traf c
MikeAdams
AcmePacketurlington,MA01803
Email:madams@acmepacket.com
MinseokKwon
DepartmentofComputerScienceRochesterInstituteofTechnology
Email:jmk@cs.rit.edu
Abstract—Overthepastdecade,VoiceoverIP(VoIP)hasrevolutionalizedthetelecommunicationsindustry.VoIPhasbe-comemoreprevalentthanever,andconsequentlymoreusershaveswitchedtoIP-baseddatanetworksfortheirtelephoneusefromtheanaloguePublicSwitchedTelephoneNetwork(PSTN).Onechallenge,though,istosecureandprotecttheseVoIPconnections.Inthispaper,weinvestigateanewapproachtodemonstratethevulnerabilityofVoIPconnections.Ourapproachmonitorsreal-timedatastreams(e.g.,RTP),andinsertspacketscontainingfraudulentvoicedataatexpectedtimesestimatedfromthemonitoring.Asfalsepacketsarewell-alignedwithoriginalpackets,wecanmaximizetheeffectsofthetestwhileminimizingthenumberofinsertedpackets.Thisminimalnumberoffalsepacketsalsohelpseschewthedetectioneffortsofdenial-of-servicedefensemechanisms.OurresultsindicatethattheinsertedpacketsatdesiredtimescanindeeddisrupttheoriginalRTPstreamwithoutanynoticeabletraf cincrease.
IndexTerms—VoiceoverIP,RTP,SIP,multimedianetworks,security,vulnerability,experiments
I.INTRODUCTION
Inrecentyears,VoiceoverIP(VoIP)technologieshavemadesigni cantprogressbothinresearchandcommer-cially[1]–[4].VoIPallowsuserstomakephonecallsoverIP-baseddatanetworksinsteadofthePublicSwitchedTele-phoneNetwork(PSTN)throughsuchtechnologiesasSIP[1],RTP[2],andH.323[5].Asthetechnologyadvances,VoIPcanprovideahigherqualityandyetmoreaffordablephoneservicethanPSTN.ThetelecommunicationindustryiswithoutadoubtmovingtowardsusingVoIPastheirmainphoneinfrastructure.
DespitetheadvancesinVoIPtechnologies,avastmajorityoftheVoIPservicesprovidedbytelecommunicationcarriersarenotsecureandvulnerabletoavarietyofmaliciousactivi-ties.Ifanattackersniffsonthenetworkbetweentwoend-usersincommunication,theattackercanseevirtuallyeverypieceofdatasentoverthewire.Theattackercaneveninsertitsownfraudulentpacketsintothewireprohibitingthevictimfromusingnetworkresources(likedenial-of-serviceattacks).
Ourgoalinthispaperistodemonstratethatadenial-of-serviceattackcanbecraftedspeci callytargetingtheVoIPnetwork,yetishardtodetectanddefeat.Whiletheattackcanbeappliedtootherreal-timedatastreams,weonlyfocusontheVoIPuseoftheG.711(U-lawandA-law)codecthatemploystheRTPprotocoltotransmitdigitizedvoicedata[2],[6].Theattackcanalsobeconsideredasthevulnerability
testofRTP.ThemainideaistoinjectfalseRTPpacketsatspeci ctimessothatthereceiveracceptsthesefalseRTPpacketswhiledroppinglegitimateones.Thistypeofattackispossiblebecausewecananticipatetheexactmomentwhenaspeci cRTPpacketisdelivered.Moreover,ISPsdonotusuallyinspectRTPpayloadsduetotheirlimitedresources,andcanseenoclearevidenceofanymaliciousbehaviorinthisattack.WealsoadoptasimilarmethodtotheshrewattackforTCPcongestioncontrol[7]tomakethisattackhardtobedetectedordefeated.Notethatthefocusisondemonstratingthatsuchanattackisfeasible,notonstudyingthereactionofVoIPclientstocallqualityunderattack.
Oursystemcomprisestwosubcomponents:1)apacketcaptureengineand2)apacketinjectionengine.ThepacketcaptureenginemonitorsthenetworkforanyRTPtraf candenablesthepacketinjectionenginewhenaVoIPcallisdetected.ThepacketinjectionenginethensynchronizeswiththeunderlyingRTPstreamandinsertsfraudulentRTPpacketsshortlyaheadofthescheduledarrivaltime.OurresultsshowthattheinsertedpacketsatdesiredtimescanindeeddisrupttheoriginalRTPstreamwithoutanynoticeabletraf cincrease.Theresultsalsoshowthatthistypeofattackcanbedoneinastealthywayandishardtotracebackviatypicaldenial-of-servicepreventionschemes.
Therestofthepaperisorganizedasfollows.InSec-tionII,wediscusstherationaleforourvulnerabilitytest,anddemonstratewhyourschemeisfeasibleinthecontextofVoIP.InSectionIII,wegiveanoverviewofrelatedwork.InSectionIV,wedescribethebasicdesignofourschemeanditsimplementationdetails.InSectionV,wepresentperformanceresultsfromourexperiments.Finally,wesummarizeourconclusionsandfutureworkinSectionVI.
II.MOTIVATION
OurvulnerabilitytestschemedoesnottechnicallydisruptRTPorforgeanyharmfulactivities.Theschemeratherdistortstheperceptionofaudioattheend-userbyaddingbogusduplicateRTPpackets.Howissuchanattackpossible?Theanswersaretwofold:1)itisnotviableforISPstoinspectRTPpayloads,and2)thereisnoclearevidenceofmaliciousbehaviorexcepttheperceptionoftheend-user.
TheISPsdonotinspectRTPpayloads,encryptandauthen-ticatemessages[8],orconductanysortofdeeppacketanalysis


