My Photo

Search Blog

  • Search Blog
    Google

    WWW
    voipsecurityblog.typepad.com

Become a Fan

« Interview by Eric Krapf of NoJitter on FBI Report of Telephony Denial of Service (TDoS) Attacks | Main | Voice Over IP (VoIP) Telephony Denial of Service (TDoS) Attack Article Summary »

June 25, 2010

Comments

David Merrick

Thanks for posting this. There is an unsettling lack of information out there about the seriousness of the TDOS threat. Aside from the FBI's press release last month and coverage in Wired, nobody is talking about it. I'm looking forward to reading your follow-up about mitigation approaches!

Mark Collier

Thanks for the comment. We may be seeing more public information about more serious attacks. I will post some info on mitigation techniques next week.

M Zubair Rafique

I like the new name "Telephony DoS (TDoS)" given to this attack scenario. I would like to know how in real VoIP network IDs are spoofed? Isn't the VoIP service providers allows the authenticated users only to setup calls to the other legitimate users? Thanks for the post. Your efforts are really admirable in this regard.

Mark collier

Thanks for the comment. There is no active legislation that prohibits spoofing caller ID, either in VoIP or TDM networks. Even it there was, it wouldn't stop determined attackers. Service providers do not enforce caller ID authentication. And by the way, the caller ID for the TDoS calls I am aware of DID have spoofed caller ID.

Fffrrr.wordpress.com

Nice post, but what about the sip trunks? how they are affected?

Mark Collier

Thanks for the post. The attack is pretty much identical for SIP or TDM. It just appears as a flood of calls with some audio content. Most of the attacks we heard of are on TDM (because the vast majority of trunking in NA is TDM), but some occurred on SIP as well. Solutions to the problem are pretty much the same for TDM and SIP.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Toll Fraud