RFC 6404: Session PEERing for Multimedia INTerconnect (SPEERMINT) Security Threats and Suggested Countermeasures
In plain English — editorial summary, not part of the RFC
The Session PEERing for Multimedia INTerconnect (SPEERMINT) working group (WG) provides a peering framework that leverages the building blocks of existing IETF-defined protocols such as SIP and ENUM for the interconnection between SIP Service Providers (SSPs). The objective of this document is to identify and enumerate SPEERMINT- specific threat vectors and to give guidance for implementers on selecting appropriate countermeasures. Security requirements for SPEERMINT that have been derived from the threats detailed in this document can be found in RFC 6271; this document provides concrete countermeasures to meet those SPEERMINT security requirements. In this document, the different security threats related to SPEERMINT are classified into threats to the Lookup Function (LUF), the Location Routing Function (LRF), the Signaling Function (SF), and the Media Function (MF) of a specific SIP Service Provider. Various instances of the threats are briefly introduced inside the classification. Finally, existing security solutions for SIP and RTP/RTCP (Real-time Transport Control Protocol) are presented to describe countermeasures currently available for such threats. Each SSP may have connections to one or more remote SSPs through peering or transit contracts. A potentially compromised remote SSP that attacks other SSPs is out of the scope of this document; this document focuses on attacks on an SSP from outside the trust domain such an SSP may have with other SSPs. This document is not an Internet Standards Track specification; it is published for informational purposes.
Document record
- Document ID
- RFC6404
- Published
- November 2011
- Authors
- J. Seedorf; S. Niccolini; E. Chen; H. Scholz
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- rai
- Pages
- 22
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6849An Extension to the Session Description Protocol (SDP) and Real-time Transport Protocol (RTP) for Media LoopbackCurrent
February 2013
- RFC 8862Best Practices for Securing RTP Media Signaled with SIPCurrent
January 2021
- RFC 8866SDP: Session Description ProtocolCurrent
January 2021
- RFC 6035Session Initiation Protocol Event Package for Voice Quality ReportingCurrent
November 2010
- RFC 5393Addressing an Amplification Vulnerability in Session Initiation Protocol (SIP) Forking ProxiesCurrent
December 2008
- RFC 3853S/MIME Advanced Encryption Standard (AES) Requirement for the Session Initiation Protocol (SIP)Current
July 2004
- RFC 3556Session Description Protocol (SDP) Bandwidth Modifiers for RTP Control Protocol (RTCP) BandwidthCurrent
July 2003
- RFC 3550RTP: A Transport Protocol for Real-Time ApplicationsUpdated
July 2003
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?