Efficiency of social connection-based routing in P2P VoIP networks

METHODOLOGY:

           The Fundamentals of Voice over internet protocol there are some elements. They are Router devices, devices, Virtual Private Networks (VPN’s), Switch devices, Load balancing devices, Firewall ,Call Server, Gateway, MCU, Ethernet Switch, Routers etc

TYPES OF VOIP: This peer to peer (p2p) communication tool is for the designing purpose. It checks the p2p VoIP communication. There are three types VOIP

 Computer to Computer In this type VOIP have reasonable price and numerous free software. By using this type we can eliminate a long distance charges. We need software to make a call for a computer to computer i.e. speakers, sound card, microphone, internet connection. The person must have the software on other system and that should be compatible.

IP Phones IP phone having same features like a standard phone. In IP phones there are handset, buttons, and a cradle. The main difference is instead of using RJ-11 phone connector it uses RJ-45 Ethernet connector. The IP phone is connected to the router. For a wireless connection, we can use a Wi-Fi version and it can allow to make calls from a wireless “hot spot.”

ATA – Analog Telephone Adaptor is also call as ATA. To make a call the ATA is connected to a phone. The analog signal converted into a digital signal by the ATA and then transmitted.

VOIP SECURITY FRAMEWORK:

VOIP telephony is the transportation of the voice traffic of the Internet protocol (IP).The IP uses the interconnection between networks. From the past years the internet is the basic for applications and services. It has been grown in a market with the high potentials especially for services i.e. IP telephony. There are three reasons they are, more and more people know the Internet and use it in their daily life, telephony is a business with high revenues and a lot of customers, the Internet with its flexibility, fast development and openness will generate many new services.

Voice over internet protocol in india

Voice over internet protocol have an approach to increase in an international level marketing in india.VOIP have three different ways to use they are IP telephone VOIP,ATA VOIP,PC to PC call. For developing a world VOIP is one of the competitors and it is earning a good popularity. VOIP services made the communication very easy in India. By making a good communication in India this technology is getting reliable, stronger and cheaper. By many consequences the VOIP has been raised since many years.

In India there is no connections and competitive rates and in India. By this Voice over internet protocol services has been increased. Now VOIP is focused internationally. SIP (Session internet protocol) is the international VoIP services standard in India. SIP is the processing a signal and it is used for terminating and transmitting the communication. Voice based communication is one the alternative communication in VoIP. India is also the one the largest marketing country. It is used to develop the videos, movies, and 3G mobile services.

security issues in voip ppt

Security Issues in voice over internet protocol (voip):

VOIP being at a beginning stage, security issues appear to be build in response to its growth. As per the information based on an interview of Frost and Sullivan by analyst Jon Arnold, Denial of service attacks against VoIP in reality is possible. To rectify the threat with Denial of Service, analyst Jon Arnold suggests that a system requires a terminal adaptor node. SPAM affects the SIP code, meaning it makes the language vulnerable to remote coding execution (Jeffrey Albers, Bradley Hahn, Shawn McGann, Rundond Zhu, Seungwoo Park, 2004).

Two primary methods of mitigating attacks that are used by network operators are destination based BGP black hole routing and access control lists (Borderware, 2006). When media pressure security threats are avoided only 1.5% of the organizations trust in the reporting procedures of violation to law enforcement. To allow carriers to detect and mitigate attacks companies come up with relevant packages like Peak flow SP, anti-DDoS software suites etc. (Borderware, 2006).

Interconnections between nodes are supported by an SS7 architecture that boosts the network security. This is the signal controlling system used in the United States and a few other countries in the world (Martinez). As it was mentioned earlier in the report VeriSign is the SS7 (Signaling system 7) authority for Skype. The SS7 architecture consists of something called as the packet switch network; this is a high speed network. This network is connected by 3 types of signaling links which are:

  • Service switching points
  • Signal Transfer Points (STP)
  • Service Control Points (SCP)

There has been a growth in demand for SS7 systems due to the use of data networks to transfer real time voice calls. The best part of the standard SS7 architecture is the free VoIP to VoIP calls (Werbach, K).  Hence SS7 architecture is a mandatory module to be included for signally protection.

First goal to be considered is the high quality calls expected by users in case of wireless security and a voice over wireless LAN deployment (Jacobs, 2006). The two most important functions of relevant VoWLAN security mechanisms are the radio frequency management and load balancing. Aruba networks specialize in these solutions and have a full range over this domain. In the wireless industry, Spectral link, Quote, Chart, Avaya, voice-badge maker Vocera and software designer TeleSym are few big partners to Aruba. Objective of providing security to the VoWLAN lies in the correct MAC addresses authentication and WEP analysis. Due to the codecs and the compression schemes used by Aruba’s partners, Aruba 5000 switch is capable of handling 5000 calls simultaneously. The problems with VoWLAN exist in its basic functionality. VoWLAN needs are much more complex when compared to the data over wireless networks. Providing an interoperability testing for the new IEEE 802.11 is the basic task of Wi-Fi. The new IEEE 802.11 equipment has already boomed on grounds of demand in the market. In order to allow expansion in its present market and the future, it is up to the technical task group in a Wi-Fi project.

VPN: Virtual Private Network Seminar Report

Use of virtual private network (VPN) and virtual LAN (VLAN) to protect voice traffic and minimise the risks:

Virtual private Network (VPN) is very useful in providing the links between the sites and safeguards the data passing through the unsecured network. On the other hand, virtual LANs are useful in prioritizing the network traffic by separating voice and data traffic to achieve lower latency and good quality of voice. Situations where the IP phones use the same cable connection with PCs must hold the IEEE 802.1Q standard and where the IP phones and PCs exist on different networks; separation could be done by using Voice-aware firewalls (Jensen, W., 2006).

Creation of policy-based safety zones:

The concept of safety zones is brought by Juniper products by allowing flexibility not only in defining but also in creating virtual zones. VoIP network managers have the capacity to control these security zones in separating IP network devices and sometimes virtually separate IP networking segments (Bulk, F., 2008). These provide/facilitate extra grade of security for voice /IP components, stops threats and thus helps in guessing of, and rectification action against, the main problem.

Encryption and its application:

From the security point of view, it is better to know the importance of encryption to VoIP signaling and media streams etc. For example, if there is a problem of eavesdropping, then it is better to consider the use of encrypting phones. Even though this encryption is only for security purpose, but because of some potential performance issues, it should be approached with surgical view. IPSec is an encryption methods to transcode the calls over wide area network. However in the case of long-haul networks, most of the devices should be encryption-aware to guarantee good voice quality.

Safety measures in case of UDP Flooding:

UDP flooding could be understood as a threat over the network which occurs when UDP packets are sent with a view to slow down the total process to a point where it is not possible to hold valid connections. The safety measure for such a type of threat is to install a firewall that enables protection against UDP flooding.

Download VPN: Virtual Private Network Seminar Report

Intrusion Detection and Prevention System PPT

Application of IDP (Intrusion detection and prevention) system:

This is the new Intrusion Detection and Prevention System technology which helps in protecting both the application and network layers from existing and future threats. Intrusion detection and prevention system makes in-depth scrutiny of all the packets in communication traffic to identify different types of doubtful activities and lawful threats/risks at both the layers (Anonymous, 2006). This technique helps a lot in recognizing, Back-door detection, Regular expression pattern matching and Attack signatures etc.

When compared to other traditional firewalls that are very prone to false signals, low efficiency, high cost and incapacity to face threats/risks. On the other hand, this system can also be useful to destroy certain risks and certain flag, doubtful items. In addition to these, the IDP system in Juniper networks came out with a new technology to maintain high level of security and control.

Installation of Gateways (Application Level Gateways- ALGs):

Application Level Gateways helps in maintaining the security by putting on and off of the firewall pinholes. These gateways are designed in such a manner to prevent unexpected attacks either on VoIP or other IP network. In addition to the above benefits, these gateways are capable enough to read and interpret messages and then act as appropriate. Because of these facilities, ALGs are used to see the set-up messages to decide between legal and piracy ones (P.67). Normally, these ALGs will be embedded into the security devices like firewalls to upgrade their performance and capacity for applications. With regard to VoIP, H323, SIP, MGCP are some of the protocols.

Implementation of SIP in terms of Authorisation, Authentication and IPSec:

SIP could be understood as a vital part in relation to VoIP in terms of providing call transfer, call set-up, call ID, call transmission, call processing, call waiting, and so many advance features. For the beginners, Hypertext Transfer Protocol (HTTP) and simple Mail TRANSFER Protocol (SMPT) are the two other protocols in use which allows SIP to easily monitor or spoof (Griffith, D.,2004). Now-a-days, network managers are coming across different types of threats such as SPIT, unauthorised call transfers and access to information etc. All the above threats can overcome by strong and valid authentication, authorisation and IPSec.

Download Intrusion Detection and Prevention System PPT

Security Considerations for Voice Over IP Systems

Security Considerations for Voice Over IP Systems: In this world of technology, Voice over Internet Protocol gives rise to different types of risks. First, because of their intricacy and immatureness, Voice Over IP brings a lot of new threats to the active IP networks. Secondly, being a same platform for both voice and data applications, latest risks make the whole network open to new ways. However there are so many measures for the network manager to keep the threats at a minimum level which includes setting-up of different  devices at main interfaces, executing of planned safety requirements on weak Voice Over IP devices, and the initial formulation and enforcement of benchmark actions to bound disclosure of the IP network to attacks. The following are some of the policies and procedures to be applied to maintain security over IP networks:

Maintain current PATCHES levels:

This is the basic level where in insufficient software bits make to network to give exposed to needless risks. These network attacks seem so clever in targeting software to achieve definite aim instead of simply making random trouble. So it is very important to make a prudential approach in viewing and installing patch releases to keep the network applications and the total investment away from risks (Computer society, 2008).

Antivirus system (Installation and its up gradation):

From the VoIP point of view, this anti-virus system helps in protecting the components of voice from those that are very weak to attacks. For example, Juniper Networks Net screen firewalls incorporate anti-virus software in Voice Over IP installation and it’s up gradation along with all other aspects/ elements.

SMBR: A novel NAT traversal mechanism for structured Peer-to-Peer communications

NAT TRANSVERSAL MECHANISM AND ITS SECURITY IMPLEMENTATION:

Previously details of the importance of router usage in infrastructure were provided based on case studies. However by inserting the flow of transport protocols or by translation, other entities called the middle boxes affected the quality of voice packets. IP tunnel, endpoints, markets, proxies, caches, transport relays, etc are widely used to types of middle boxes. (HIP Research group, 2006).This is generally known to public as stumbling blocks to an efficient VoIP communication. The more common terminology for the middle boxes is the VoIP across Network Address Translators,(HIP Research Group,2006) will be discussed next.

Below are certain recommendations made for SMBR: A novel NAT traversal mechanism for structured Peer-to-Peer communications with regards to the security activities that are intrinsic to traversal of NAT mechanisms (HIP Research group, 2006):

To create NAT bindings that are highly sensitive with reference to security actions and opening pinholes in firewalls (i.e., as mentioned earlier regarding firewall rules, allowing packets to traverse).

Using UDP encapsulation to correlate outgoing and incoming signal values reduces complexity of the overall protocol.

NAT extension utility.

END USER AND HOP BY HOP AUTHENTICATION TECHNIQUES:

The report will include a few successful techniques utilized by the end user and hop by hop authentication techniques (Computer Society, 2006).

“Longer IP addresses, 128 bits compared to 32bits: There has been a growth of over 4billion and will continue to grow up to 9billion by 2050, not to include the cross-layered architectural functions which could be sole cause of such increase.

New Support options and data integrity extensions to regulate the traffic flow labeling of packets is a useful option, known as flow labeling capacity. Processing power increases if the headers are simplified. Plug and play automatic configurations are auctioned for a faster VoIP transfer known as a automatic configuration.

The technique that carries information to be processed on each and every node along with a packet traversal path is known as Hop-by-Hop.

voice over internet protocol voip technology

SESSION BORDER PROTCOL AND CARRIER PEERING:

Important security issues for voice over internet protocol voip technology transactions are carrier peering and Session Border Control. Hence before we proceed, it is necessary to clarify the concepts of the above two issues. The ability to interconnect networks is known as the Carrier Peering (Handley, M.1998 p.2). Interconnecting their switching nodes directly is a possibility however found vague and such interconnections do not provide the required control. Hence the utilization of interconnects or peer points to control the traffic. Digital manipulation, parameter interpretation, screening, route prioritization are found to be complex to be processed by Peering. The primary role of peering device is to secure the carrier’s networks and adapt to the specific requirement and protocol changes that are based on the peering point and its location in the network topology. The role is based on SIP protocol which is standard for VoIP communications.

Below are certain factors are a necessity on the functionalities of Carrier peering:

An intrinsic ritual that raises call costs and degrades performance that bundles data into packets according to a specific protocol, causes delay and back to back conversions through a pair of media gateways. Internetworking problems are solved when signals are converted from SIP to H.323 that is widely used in VoIP protocols.

With reference to VoIP and mobile communications, Security Carrier Peering functions as:

Billing: To generate billing records when the service is used to make calls

Routing: when ring tones, announcements are used on a mobile network.

Going to Session Border Controls, commonly also termed as Session Awareness Firewalls, like any security firewall, the device is designed to primarily secure the network. Issues such as Denial of Service and unauthorized interference by illegal users can be eliminated when the SBC performs its functions.  All medium and signaling passes when SBC provides a single or a range of IP addresses. Other functions of SBC are similar to the Carrier Peering, for example- billing and routing devices, traffic flow management.

Sonus and Juniper are 2 such companies that provide the above mentioned services; both these companies are based in California, USA. Session Border Control Solutions is a comprehensive package that includes guarantee in service, hosts NAT traversal mechanism, managed enterprise IP telephony, and most importantly legal formalities.

Effect of security architecture on cross-layer signaling in network centric systems

CROSS-LAYERED SECURITY ARCHITECTURE:

Important values are given to the mobile communications using wireless technology with VoIP. Mobile communications suffer from severe performance unlike infrastructure based networks due to their dynamism. Usage of energy can be a limiting factor for sensor nodes, while routes become unstable and shared media is prone to interference (Leyden, J. et al p.1). Cross-layer architecture are widely used today for minimizing such mentioned barriers, impact of such barriers on the performance, increases the measurability and reliance of networks in mobile communications( Leyden, J. et al, p.1). Layered architecture is advantageous in cases of design complexities which were highlighted earlier in the enterprise and carrier layer architecture.

  This increases modularity, better maintenance when compared to monolithic stacks. Explaining further on modularity, permits the combination of various protocols, improves the overall performance of the network stack as the errors are now easily traceable given the flexibility. Hollow errors causing bit errors, collisions, delays, lowered thorough put, are certain problems caused by the simple layered architecture.

Mainly due to the fact that application is shared. To distinguish from simple layer, the cross layering offers the unique comfort in these parameters, algorithms can be contributed by giving inputs by sharing information over different layers. The method of sharing information is synchronized and structured, the enrichment of the layered architecture is sustained, and architecture longevity guaranteed.

Cross-Layered architecture

For an enterprise to maintain a network-wide, global view of a multiple metrics such as load balance, battery status and routing destinations, a cross layered architecture can be used. One must consider both the global and local view to examine the simple designs of the cross layered architecture. To use local optimization such as load balance, refer to local view that contains very specific nodes, while the tendency to propagate data by collecting number of samples of data from specified local nodes refers to the global view. Common data security architecture is frequently used to by many mobile communication companies to ingrain the cross layered objectives.

voip project in java

A known example related to the Skype, security breach can now easily tracked the infrastructure provided (Source: Leyden, J “Say Hello to the Skype Trojan”. published on Oct 18, 2005).

Problem Description: The detection and rectification of the security breach in the windows Skype users have been completed.

Chances of an incorrect file transfers can exist if the Skype URL malfunctions due to break in required parameters, either by the system’s vulnerability or by an attack on the original source code of the web page. This could also occur due to the end user error. Impact on the Skype software before 2.5 can be effective based on the attack that could be fatal. Hence it’s always preferred that the Skype is directly installed from the Skype URL which will help ensuring there are regular updates and monitoring (p.456-498). In case of a windows xp or professional operating system, certification is signed and authenticated by “VeriSign class 3 codes Signing 2009 CA”.

Along with the installation of the software, the end user will also receive a bulletin for security purposes, helps in removing a possible breach. Given below are arrays of base vectors that have a correct reflection, pre-assigned by VeriSign:

Access Vector (AV) Remote
Access Complexity (AC) Low
Authentication(Au) Not Applicable
Confidentiality Impact (C) Partial
Integrity(I) None
Availability Impact(A) None
Impact Bias(B) Confidentiality