Zabezpečení IP telefonní infrastruktury s využitím pokročilých systémů IPS

Abstract

The aim of the diploma thesis was to test the Suricata tool in the mode of prevention of systems intrusion in the implementation of attacks on the Asterisk branch exchange, for which two software phones Jitsi and PhonerLite were configured. In testing the Suricata tool first worked in conjunction with the IPtables filter system and later with its newer successor, NFtables. SIPVicious, Inviteflood, and network scanning with the use of NMAP command were used to perform the testing. In my work I focused on creating rules for capturing anomalies in order to obtain results in terms of the success of blocking potential attacks with a focus on IP telephony.

Description

Subject(s)

Voice over IP, Intrusion Prevention System IPS, Suricata, IPtables, Nftables, NFqueues, PBX Asterisk

Citation