Capture and Analysis of Malicious Traffic in VoIP Environments Using a Low Interaction Honeypot
Ivan Riboldi Jordao da Silva Vargas, João Henrique Kleinschmidt · IEEE Latin America Transactions · 2015
The number of users of VoIP services is increasing every year. Consequently, VoIP systems get more attractive for attackers. This paper describes the implementation of a low interaction honeypot for monitoring illegal activities in VoIP environments. The honeypot operated during 92 days and collected 3502 events related to the SIP protocol. The analysis of the results allows understanding the modus operandi of the attacks targeted to VoIP infrastructures. These results may be used to improve defense mechanisms such as firewalls and intrusion detection systems.