Addressing an Amplification Vulnerability in Session Initiation Protocol Forking Proxies
RFC 5393, “Addressing an Amplification Vulnerability in Session Initiation Protocol Forking Proxies”, is a Proposed Standard document published in December 2008 by R. Sparks, S. Lawrence, A. Hawrylyshen, B. Campen. It updates RFC 3261. The canonical text is published by the RFC Editor.
Abstract
This document normatively updates RFC 3261, the Session Initiation Protocol (SIP), to address a security vulnerability identified in SIP proxy behavior. This vulnerability enables an attack against SIP networks where a small number of legitimate, even authorized, SIP requests can stimulate massive amounts of proxy-to-proxy traffic.
This document strengthens loop-detection requirements on SIP proxies when they fork requests (that is, forward a request to more than one destination). It also corrects and clarifies the description of the loop-detection algorithm such proxies are required to implement. Additionally, this document defines a Max-Breadth mechanism for limiting the number of concurrent branches pursued for any given request. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5393 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5394 Policy-Enabled Path Computation Framework
- RFC 5391 RTP Payload Format for ITU-T Recommendation G.711.1
- RFC 5395 Domain Name System IANA Considerations
- RFC 5390 Requirements for Management of Overload in the Session Initiation Protocol
- RFC 5396 Textual Representation of Autonomous System Numbers
- RFC 5389 Session Traversal Utilities for NAT
- RFC 5397 WebDAV Current Principal Extension
- RFC 5388 Information Model and XML Data Model for Traceroute Measurements