An RTP Denial of Service Attack and its Prevention

Status: Individual Item, draft 0.
Date of last update: June 23, 2003
Authors: J. Rosenberg
Current Document: draft-rosenberg-mmusic-rtp-denialofservice-00 [.txt][.html]
Summary: The Real Time Transport Protocol (RTP) provides unreliable transport of real time media from a sender to one or more recipients. RTP sessions are typically set up through signaling protocols such as the Session Initiation Protocol (SIP) or the Real Time Streaming Protocol (RTSP). When RTP is set up with these protocols, a potential Denial of Service (DoS) attack is introduced. This attack allows an attacker to cause a flood of RTP packets to be sent towards a target. We describe this attack, and also show how it is effectively prevented using Interactive Connectivity Establishment (ICE), first introduced as a means of handling Network Address Translator (NAT) traversal.
Archive of older drafts:

Last modified: Tue Jul 08 02:26:56 Eastern Daylight Time 2003