Telco technical

& business courses

available worldwide

VoIP Security and Vulnerability

security, fraud, engineers
available worldwide
Ask for offer

Who Should Attend?

This course is aimed at managers, engineers, and operation teams who need deep knowledge about Voice-over IP technologies, attacks, vulnerabilities, and auditing methods. Participants will learn about the current threat environment (in terms of VoIP abuse and fraud) and the trends in securing VoIP services.

 

Course Scope

  1. VoIP Introduction.
  2. VoIP Benefits.
  3. VoIP Technologies.
  4. Root of VoIP Technology.
  5. VoIP Security Architecture.
  6. VoIP Specific Protocols Study.
    • SIP IETF.
    • H323.
    • IAX.
    • RTP.
    • SDP.
  7. View of Telecom Specific Evolution of SIP.
    • SIP-I.
    • SIP-T.
  8. VoIP Network Elements Overview, Security Roles, and Functions.
    • SBC.
    • SIPAS.
    • PCRF.
  9. Security of Different VoIP Planes.
    • Control.
    • Media.
  10. VoIP Communication Security.
  11. Open-source VoIP Tools.
    • Asterisk.
    • OpenSER, OpenSIPS, and Kamailio.
  12. Open Source Audit Tools.
    • SIP Vicious.
    • ISME.
  13. Network Taps for VoIP Attack.
  14. Impact of Routers, Switches, VLAN and Routing in VoIP Security.
  15. VoIP Network Element Fingerprinting.
  16. Typical Attacks on VoIP Infrastructure.
  17. Threat Environments.
    • Central American Gangs.
    • Romanian Fraud Rings.
  18. Role of Legacy in VoIP Security.
    • Interconnection with SS7 Signalling Network Element.
    • H248.
  19. Vulnerabilities of some Voice-over-IP Protocols:
    • SIP-I.
    • SIP-T.
    • H323.
  20. Generic VoIP Network Element Vulnerabilities.
  21. Practical Attack of a VoIP network in a Lab-based Environment.
    • InformationGathering Information.
    • Scanning.
    • Cracking.
    • Abuse.
    • Privacy attacks.
    • Eavesdropping.
  22. Scenario of VoIP Network Attack.
  23. Using Backtrack for VoIP auditing.
    • The Next steps to becoming a VoIP network auditor.

 

Prerequisites

  • Basic knowledge of Telecom and network principles:
    • What is 2G, 3G, 4G.
    • OSI network layers.
    • Basic knowledge of Telecom technologies.
  • Good knowledge and usage of Wireshark.
  • Basic skills and usage of Linux for reverse engineering (strings, knowledge of tools in a Backtrack for reverse engineering).
  • Laptop with Linux installed either in a VM or native, Backtrack or Ubuntu with reverse engineering and hacking tools recommended.
  • Legal IDA Pro license recommended.

 

Training Structure

Two-day training divided into logical sessions.

 

Methodology

Instructor-led training.

Trainer is open for comments and discussion.

Ms. Natalya Nerubenko, Life Ukraine

I can proudly recommend these courses for others as well.

Mr. Tarvo Jammer, Elisa Estonia

Experienced trainer. Excellent descriptions.

Mr. Ahmad Doar, Mobily, KSA

I feel like the trainer is the best professor and mentor one can have.

Ms. Ledia Meici, AMC Albania

The trainer is capable of answering all my questions.

Ms. Ana Gheorghe, Vodafone RO

Trainer understands local market experience.

Mr. Andrew Sweetman, Wataniya

This course will be very useful in my daily work.

Mr. Leopoldino Ferreira, Unitel Angola

Trainer adapted to the expectations of the audience.

Mr. Antoine Blanchet, Monaco Telecom

The whole course was very valuable.

Mr. Sayyid Ali, Dhiraagu Maldives

Overwhelming knowledge and expertise. Interactive and enjoyable learning.

Mr. Ashish Shrestha, NCell Nepal

A good approach to a complex problem.

Ms. Horia Catrinoiu, Vodafone RO

Excellent course and instructor.

Mr. Nikolay Suetin, Beeline Russia

Great teacher with deep knowledge and experience.

Mr. Philippe Wrzecionek, TATA

The course exceeded my expectations. Hats off!

Mr. Adnan Syed, Mobily

The course covers all the impacted areas.

Ms. Gratia Scanteie, Vodafone, RO

Professional, high-quality trainer.

Mr. Gagik Shatveryan, Vivacell

A clear picture of GSM switching and signalling.

Ms. Anette Chale, mCel Mozambique

Training provides useful methods to analyze real protocols.

Mr. Seema Karn, NCell Nepal

Amazing, more than excellent, audience-oriented trainer.

Mr. Evgeniy Dmitriev, Astelit Ukraine

Perfect course.

Mr. Arseniy Mazanik, Beeline Russia

Deep and detailed topic analysis.

Mr. Mohamed Sabry, Vodafone Egypt

Training was above expectations!

Mr. Ariel Haxhiu, Eagle Mobile, AL

Unique training covering the most important areas of my work.

Mr. Eldar Mursaqulov, Azercell

Really practical and very fruitful training.

Mr. Niroj Raya, NCell Nepal

Very effective training methods.

Ms. Erjona Xhemali, AMC Albania

The training exceeded my expectations.

Ms. Irida Gjashta, AMC Albania

Excellent, knowledgeable trainer, open to communication.

Mr. Dmitrii Kropotov, Tele2 Russia

Very well organized training programmes.

Mr. Mihnea Teodorescu, Cosmote, RO

More than excellent course!

Ms. Inessa Mijiferjyan, Vivacell

The training is completely excellent.

Mr. Philipp Korostelev, Beeline Moscow

Regardless of technology I received theoretical and practical answers.

Mr. Kosta Pribić, T-Mobile Croatia

Highly professional trainer with lots of practical experience. Friendly and open.

Ms. Olga Rudnicka, Tele2 Latvia

Trainers have passion to teach & impart knowledge.

Mr. Kanchan Chitrakar, Ncell Nepal

Everyone gets individual attention from the trainer.

Ms. Inga Tomsone, Tele2 Latvia

The best training ever.

Mr. Timur Zagretdinov, MTT Russia

Good class notes and great examples.

Mr. Ghaffar Masood, Mobilink Pakistan

Trainer was able to answer practical questions.

Mr. Daniel Krolikowski, Play Poland

Seminar entirely for Telecommunication operators. A lot of issues covered.

Ms. Pinelopi Tragoudara, Vodafone GR

I received a lot of useful information which I use in my work every day.

Ms. Viktoriya Gusarova, Beeline RU

Course covers all important issues and presents relevant examples.

Mr. Mohamed Kamel, Vodafone Egypt

Good logical structure of the course and explanation.

Ms. Elena Shevtsova, Beeline, KZ

Trainer understands local market experience.

Mr. Andrew Sweetman, Wataniya

Many different people from different operators can share their problems and ideas.

Mr. Omar El-Fiky, Vodafone Egypt

Experienced trainer. Real cases with references to recommendations.

Mr. David Curkan, T-Mobile Croatia

Good direct connection between course material and real problems.

Mr. Alex Konstantopoulos, Cosmote, GR

Excellent knowledge from the trainer.

Ms. Catherine Barman, Swisscom

Very clear explanations.

Ms. Tatyana Krasyuk, Life Ukraine

I am very impressed with the trainer's knowledge and experience.

Mr. Mouin Al Saghir, Vivacell

A lot of useful materials and knowledge.

Mr. Shukhrat Khaydar, UCell

Excellent exercises!

Mr. Muhammad Ali, Mobilink Pakistan

Excellent methodology of teaching. Simple and easy to understand training.