RFC 5393: Addressing an Amplification Vulnerability in Session Initiation Protocol (SIP) Forking Proxies
In plain English — editorial summary, not part of the RFC
This document normatively updates RFC 3261, the Session Initiation Protocol (SIP), to address a security vulnerability identified in SIP proxy behavior. This vulnerability enables an attack against SIP networks where a small number of legitimate, even authorized, SIP requests can stimulate massive amounts of proxy-to-proxy traffic. This document strengthens loop-detection requirements on SIP proxies when they fork requests (that is, forward a request to more than one destination). It also corrects and clarifies the description of the loop-detection algorithm such proxies are required to implement. Additionally, this document defines a Max-Breadth mechanism for limiting the number of concurrent branches pursued for any given request. [STANDARDS-TRACK]
Document record
- Document ID
- RFC5393
- Published
- December 2008
- Authors
- R. Sparks; S. Lawrence; A. Hawrylyshen; B. Campen
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- rai
- Pages
- 20
- Also known as
- —
- Updates:
- RFC 3261
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 3853S/MIME Advanced Encryption Standard (AES) Requirement for the Session Initiation Protocol (SIP)Current
July 2004
- RFC 2543SIP: Session Initiation ProtocolObsoleted
March 1999
- RFC 4916Connected Identity in the Session Initiation Protocol (SIP)Current
June 2007
- RFC 3265Session Initiation Protocol (SIP)-Specific Event NotificationObsoleted
July 2002
- RFC 3263Session Initiation Protocol (SIP): Locating SIP ServersUpdated
July 2002
- RFC 3262Reliability of Provisional Responses in Session Initiation Protocol (SIP)Current
July 2002
- RFC 3264An Offer/Answer Model with Session Description Protocol (SDP)Updated
July 2002
- RFC 4629RTP Payload Format for ITU-T Rec. H.263 VideoCurrent
January 2007
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?