SYSTEMS AND METHODS FOR PROVIDING SECURITY FOR SIP AND PBX COMMUNICATIONS
The present application is directed to systems and methods for providing security for session initiation protocol (SIP) services via a single device providing an SIP proxy and video conference bridge. A device deployed as a proxy between a first client and a second client receives an SIP request of the first client to establish a real-time communication with the second client. The device determines, based on application of a policy to the first SIP request, to deny the SIP request. The device receives a real-time communication protocol request, originated by the first client, to establish a real-time communication channel with the second client. The device identifies that the first client originating the real-time communication protocol request corresponds to the first client of the denied SIP request, and discards the real-time communication protocol request, at a transport layer of a network stack of the device, responsive to the identification.
1 . A method for providing security for session initiation protocol (SIP) services via an Ethernet device providing an SIP proxy and video conference bridge, the method comprising:
receiving, by a device installed as an Ethernet adapter on a computing device and deployed as a proxy between a first client and a second client, a first session initiation protocol (SIP) request of the first client to establish a real-time communication with the second client;
determining, by a firewall of the device based on application of a policy to the first SIP request, to deny the first SIP request;
receiving, by the device, a real-time communication protocol request, originated by the first client, to establish a real-time communication channel with the second client;
identifying, by the firewall, that the first client originating the real-time communication protocol request corresponds to the first client of the denied first SIP request; and
discarding the real-time communication protocol request, by the firewall at or below a transport layer of a network stack of the computing device, responsive to the identification.
2 . The method of claim 1 , wherein determining to deny the first SIP request comprises determining, based on applying an access control list policy to a source IP address of the first SIP request, to deny the first SIP request.
3 . The method of claim 1 , wherein determining to deny the first SIP request comprises determining the first SIP request comprises an invalid session request.
4 . The method of claim 1 , wherein determining to deny the first SIP request comprises determining that a user of the first client has not been authenticated or lacks authorization.
5 . The method of claim 1 , wherein determining to deny the first SIP request comprises determining to deny the first SIP request, responsive to receiving a predetermined number of additional SIP requests from the first client in a predetermined period.
6 . The method of claim 1 , further comprising adding a source IP address of the first SIP request to a block list of an access control list, responsive to determining to deny the first SIP request.
7 . The method of claim 1 , wherein receiving a real-time communication protocol request to establish a real-time communication channel with the second client comprises receiving a real-time communication protocol request to initiate a video conference via a video conference bridge of the device with the second client.
8 . The method of claim 1 , wherein identifying that the first client originating the real-time communication protocol request corresponds to the first client of the denied first SIP request comprises determining that the source IP of the real-time communication protocol request corresponds to the source IP of the denied first SIP request.
9 . The method of claim 1 , wherein discarding the real-time communication protocol request comprises discarding the real-time communication protocol request prior to inspecting the real-time communication protocol request at a layer of the network stack above the transport layer.
10 . A system for providing security for session initiation protocol (SIP) services via an Ethernet device providing an SIP proxy and video conference bridge, the system comprising:
a device installed as an Ethernet adapter on a computing device and deployed as a proxy between a first client and a second client, the device comprising:
an Ethernet interface configured to:
receive a first session initiation protocol (SIP) request of the first client to establish a real-time communication with the second client, and
receive a real-time communication protocol request, originated by the first client, to establish a real-time communication channel with the second client; and
a firewall configured to:
determine, based on application of a policy to the first SIP request, to deny the first SIP request,
identify that the first client originating the real-time communication protocol request corresponds to the first client of the denied first SIP request, and
discard the real-time communication protocol request, at or below a transport layer of a network stack of the computing device, responsive to the identification.
11 . The system of claim 10 , wherein the firewall is configured to determine, based on applying an access control list policy to a source IP address of the first SIP request, to deny the first SIP request.
12 . The system of claim 10 , wherein the firewall is configured to determine the first SIP request comprises an invalid session request.
13 . The system of claim 10 , wherein the firewall is configured to determine that a user of the first client has not been authenticated or lacks authorization.
14 . The system of claim 10 , wherein the firewall is configured to determine to deny the first SIP request, responsive to receiving a predetermined number of additional SIP requests from the first client in a predetermined period.
15 . The system of claim 10 , wherein the firewall is configured to add a source IP address of the first SIP request to a block list of an access control list, responsive to determining to deny the first SIP request.
16 . The system of claim 10 , wherein the device further comprises a video conference bridge, and the Ethernet interface is configured to receive a real-time communication protocol request to initiate a video conference via the video conference bridge with the second client.
17 . The system of claim 10 , wherein the firewall is configured to determine that the source IP of the real-time communication protocol request corresponds to the source IP of the denied first SIP request.
18 . The system of claim 10 , wherein the firewall is configured to discard the real-time communication protocol request prior to inspecting the real-time communication protocol request at a layer of the network stack above the transport layer.
19 . The system of claim 10 , wherein the device comprises a SIP proxy and SIP registrar.
20 . The system of claim 10 , wherein the firewall is in communication with the SIP proxy and SIP registrar.