loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: N. Mcinnes and G. Wills

Affiliation: Department of Electronics and Computer Science, Faculty of Engineering and Physical Sciences, University of Southampton, U.K.

Keyword(s): VoIP, SIP, PBX Hacking, IRSF, Toll Fraud, APT, Next Generation Networks.

Abstract: PBX hacking is a multi-billion dollar per year criminal and terrorism funding source. This paper follows on from a previous 10-day Honeypot experiment, to run a VoIP PBX Honeypot for a longer period of 103-day to not only validate any similarities, but to also analyse non-VoIP methods hackers use in an attempt to gain access to a VoIP System. Over the 103-day data collection period, the Honeypot recorded over 100 million SIP messages. Different techniques were used (including SQL injections in Invites) and hackers of the same IP subnet also attempted using web vulnerabilities in different telephony phone systems to gain access. Of specific interest, over the Christmas period of 2018, attack intensity decreased significantly. To validate these findings, the Honeypot experiment was also conducted for a short period over the Christmas period of 2019 which found that unlike Christmas 2018, attacks increased. The sophistication, scale and complexity of the fraud would suggest an Advance P ersistent Threat exists with an aim to infiltrate a VoIP system (including a PBX) to conduct Toll Fraud and where possible to also add that system to a botnet of infected voice systems. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.145.64.241

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Mcinnes, N. and Wills, G. (2021). The VoIP PBX Honeypot Advance Persistent Threat Analysis. In Proceedings of the 6th International Conference on Internet of Things, Big Data and Security - IoTBDS; ISBN 978-989-758-504-3; ISSN 2184-4976, SciTePress, pages 70-80. DOI: 10.5220/0010443500700080

@conference{iotbds21,
author={N. Mcinnes. and G. Wills.},
title={The VoIP PBX Honeypot Advance Persistent Threat Analysis},
booktitle={Proceedings of the 6th International Conference on Internet of Things, Big Data and Security - IoTBDS},
year={2021},
pages={70-80},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010443500700080},
isbn={978-989-758-504-3},
issn={2184-4976},
}

TY - CONF

JO - Proceedings of the 6th International Conference on Internet of Things, Big Data and Security - IoTBDS
TI - The VoIP PBX Honeypot Advance Persistent Threat Analysis
SN - 978-989-758-504-3
IS - 2184-4976
AU - Mcinnes, N.
AU - Wills, G.
PY - 2021
SP - 70
EP - 80
DO - 10.5220/0010443500700080
PB - SciTePress