Formal Methods Demo Session Initiation Protocol (SIP) Vulnerability Testing - PowerPoint PPT Presentation

About This Presentation
Title:

Formal Methods Demo Session Initiation Protocol (SIP) Vulnerability Testing

Description:

Title: VoIP H.323 Author: David Gibson Last modified by: COEMASTER Created Date: 7/10/2002 6:55:35 PM Document presentation format: Letter Paper (8.5x11 in) – PowerPoint PPT presentation

Number of Views:372
Avg rating:3.0/5.0
Slides: 8
Provided by: DavidG384
Category:

less

Transcript and Presenter's Notes

Title: Formal Methods Demo Session Initiation Protocol (SIP) Vulnerability Testing


1
Formal Methods DemoSession Initiation Protocol
(SIP)Vulnerability Testing
2
SIP Network in SDL
3
Call Hijacking Possible Scenario
SIP Proxy Registrar
1006
1
Dial 1006
LAN
3
Dial 1006
1007
1004
2
Re-Registered
Covert Registrar/Proxy Routes the Call
4
Vulnerability to Call Hijacking
Vulnerable - Phone accepts the Registrar without
authentication
Corrected - Phone rejects unauthenticated
Registrar
5
Vulnerable
Cisco IP Phone 7940
REGISTER requests stop
6
Corrected
The SDL Model of the IP Phone authenticates the
proxy
7
Formal Approach in Design and Testing
  • Formal Languages and Methods (SDL, MSC, ASN.1,
    TTCN)
  • every statement is mathematically provable to be
    correct
  • every statement validated by trusted tools
  • standards and spacifications can be validated
    before approval
  • Programming code generated by machine
  • no human intervention
  • no errors, no Trojan horses
  • Trusted tools generate the implementation
  • tools based on formal techniques can be certified
    as trusted
  • implementation of a standard can be certified as
    trusted
  • Tests generated from validated specifications
  • traceability to trusted design requirements and
    specifications
Write a Comment
User Comments (0)
About PowerShow.com