• musoro_banner_03
  • musoro_banner_02

VoIP Security

• Chii chinonzi Session Border Controller(SBC)

A Session Border Controller(SBC) chinhu chetiweki chakaiswa kuchengetedza SIP yakavakirwa izwi pamusoro peInternet Protocol(VoIP) network.SBC yave iyo de-facto chiyero chefoni uye multimedia masevhisi eNGN / IMS.

Session Border Controller
Kukurukurirana pakati pemapato maviri.Iyi ingave meseji yekufona, odhiyo, vhidhiyo, kana imwe data pamwe neruzivo rwehuwandu hwekufona uye mhando. Nzvimbo yekupatsanura pakati pechimwe chikamu che
network uye imwe.
Iko kurudziro inoitwa nevanodzora muganhu panzizi dzedhata dzinosanganisira zvikamu sedziviriro, kuyerwa, kutonga kwekupinda, nzira, zano, kusaina, midhiya, QoS uye data rekushandura nzvimbo dzemafoni avanotonga.
Application Topology Function
sbc-p1

• Sei uchida SBC

Matambudziko eIP Telephony

Nyaya dzeConnectivity

Kugarisana Nyaya

Security Issues

Hapana izwi / imwe nzira izwi rinokonzerwa neNAT pakati peakasiyana sub-network.

Kudyidzana pakati pezvigadzirwa zveSIP zvevatengesi vakasiyana zvinosuwisa kuti hazvisi nguva dzose zvinovimbiswa.

Kupindira kwemasevhisi, kuteerera, kurambwa kwekurwiswa kwesevhisi, kutorwa kwedata, hutsotsi hwemutero, SIP isina kurongeka mapaketi zvingakonzera kurasikirwa kukuru pauri.

sbc-p2
sbc-p3
sbc-p4

Nyaya dzeConnectivity
NAT gadzirisa yakavanzika IP kune yekunze IP asi haigone kugadzirisa application layer IP.Kwekuenda IP kero haina kunaka, saka haigone kutaurirana nemagumo.

sbc-p5

NAT Transversal
NAT gadzirisa yakavanzika IP kune yekunze IP asi haigone kugadzirisa application layer IP.SBC inogona kuona NAT, gadzirisa IP kero yeSDP.Saka tora chaiyo IP kero uye RTP inogona kusvika kumagumo.

sbc-图片-06

Session Border Controller inoshanda semumiriri weVoIP traffics

sbc-图片-07

Security Issues

sbc-p8

Attack Protection

sbc-p9

Mubvunzo: Sei Session Border Controller ichidikanwa pakurwisa kweVoIP?

A: Maitiro ese ekurwiswa kweVoIP anoenderana neprotocol, asi maitiro haana kunaka.Semuenzaniso, kana iyo frequency yekufona yakawandisa, inokonzeresa kukuvadzwa kune yako VoIP zvivako.SBCs inogona kuongorora iyo application layer uye kuona maitiro emushandisi.

Overload Dziviriro

sbc-p10
sbc-p11

Q: Chii chinokonzera kuwandisa kwemotokari?

A: Zviitiko zvinopisa ndizvo zvinonyanya kukonzeresa, senge kaviri 11 kutenga muChina (seBlack Friday muU.SA), zviitiko zvakawanda, kana kurwiswa kunokonzerwa nenhau dzisina kunaka.Kungoerekana kwawedzera kunyoreswa kunokonzerwa nedata center simba kutadza, network kukundikana zvakare yakajairika trigger sosi.
Q: SBC inodzivirira sei kuwandisa kwemotokari?

A: SBC inogona kuronga traffics zvine hungwaru zvichienderana nedanho remushandisi uye bhizinesi rekutanga, nekuremerwa kwekuremerwa: 3 nguva dzakawandisa, bhizinesi harizovhiringidzwa.Masevhisi senge traffic kuganhurira/kutonga, dynamic list, kunyoresa/call rate kudzikisira etc. aripo.

Kugarisana Nyaya
Kudyidzana pakati pezvigadzirwa zveSIP hakusi nguva dzose kuvimbiswa.MaSBC anoita kuti kubatana kuve kusina musono.

sbc-p12
sbc-13

Mubvunzo: Sei nyaya dzekudyidzana dzichiitika kana zvishandiso zvese zvichitsigira SIP?
A: SIP chiyero chakavhurika, vatengesi vakasiyana vanowanzove nekududzirwa kwakasiyana uye kuita, izvo zvinogona kukonzera kubatana uye
/ kana nyaya dzekuteerera.

Mubvunzo: SBC inogadzirisa sei dambudziko iri?
A: SBCs inotsigira SIP normalization kuburikidza neSIP meseji uye musoro kunyengera.Kugara kutaura uye kurongeka kuwedzera/kudzima/kugadzirisa kunowanikwa muDinstar SBCs.

 

MaSBC anovimbisa Hunhu hweSevhisi (QoS)

sbc-p16
sbc-p17

Kutungamira kweakawanda masisitimu uye multimedia yakaoma.Normal routing
yakaoma kubata nemultimedia traffic, zvichikonzera kusangana.

Ongorora maodhiyo nemavhidhiyo mafoni, zvichienderana nemaitiro evashandisi.Call control
manejimendi: Yakangwara nzira yakavakirwa pane anofona, SIP paramita, nguva, QoS.

Kana IP network isina kugadzikana, kurasikirwa kwepaketi uye kunonoka kwejitter kunokonzeresa kunaka kwakashata
yebasa.

MaSBC anotarisisa kunaka kwekufona kwega kwega munguva chaiyo uye tora zviito nekukasika
kuve nechokwadi chekuti QoS.

Session Border Controller/Firewall/VPN

sbc-p16
sbc-p17