In many VoIP systems, Voice Activity Detection (VAD) is often used on VoIP traffic to suppress packets of silence in order to reduce the bandwidth consumption of phone calls. Unfortunately, although VoIP traffic is fully encrypted and secured, traffic analysis of this suppression can reveal identifying information about calls made to customer service automated phone systems. Because different customer service phone systems have distinct, but fixed (pre-recorded) automated voice messages sent to customers, VAD silence suppression used in VoIP will enable an eavesdropper to profile and identify these automated voice messages. In this paper, we will use a popular enterprise VoIP system (Cisco CallManager), running the default Session Initiation Protocol (SIP) protocol, to demonstrate that an attacker can reliably use the silence suppression to profile calls to such VoIP systems. Our real-world experiments demonstrate that this side-channel profiling attack can be used to accurately identify not only what customer service phone number a customer calls, but also what following options are subsequently chosen by the caller in the phone conversation.
翻译:在许多VoIP系统中,语音活动检测(VAD)常被用于抑制静音数据包,以减少通话带宽消耗。然而,尽管VoIP流量经过完全加密和安全保护,对这种抑制行为的流量分析仍可能泄露拨打到客服自动化电话系统的通话识别信息。由于不同客服电话系统向用户发送的自动化语音消息具有独特但固定的(预录制)特征,VoIP中使用的VAD静音抑制将使窃听者能够识别并分类这些自动化语音消息。本文采用企业级VoIP系统(Cisco CallManager)及默认会话发起协议(SIP),证明攻击者可利用静音抑制可靠地识别对VoIP系统的呼叫。真实环境实验表明,该侧信道识别攻击不仅能准确判别用户拨打的客服电话号码,还能进一步识别通话者在后续语音菜单中选取的选项。