Original title:
Bezpečnostní hrozby OpenSource PBX
Translated title:
OpenSource PBX’s security threats
Authors:
Vyplel, Kryštof ; Číž, Radim (referee) ; Šilhavý, Pavel (advisor) Document type: Bachelor's theses
Year:
2026
Language:
cze Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[cze][eng]
Tato bakalářská práce se zabývá bezpečnostními hrozbami open-source PBX ústředen se zaměřením na PBX Asterisk. Cílem práce je analyzovat bezpečnostně významné síťově dostupné části PBX Asterisk, navrhnout postup bezpečnostního testování VoIP ústředny a realizovat vybrané laboratorní scénáře v izolovaném prostředí. Teoretická část vymezuje bezpečnostní aspekty VoIP a PBX systémů, zejména z pohledu důvěrnosti, integrity a dostupnosti. Dále popisuje síťově dostupné části Asterisku, význam protokolů SIP/PJSIP a IAX2, roli dialplanu, konfigurace, endpointů a správcovských rozhraní. Praktická část se zaměřuje na návrh laboratorního prostředí, výběr nástrojů, průzkum dostupných služeb, analýzu databáze zranitelností a realizaci pěti scénářů souvisejících s dostupností služby, řízením přístupu, podvržením identity a zpracováním nestandardních vstupů. Výsledkem práce je prakticky orientovaný postup bezpečnostního ověření PBX Asterisk, kategorizace zranitelností na základě jejich dopadů a způsobů realizace a návrh jedné laboratorní úlohy složené z pěti scénářů využitelných při výuce kybernetické bezpečnosti a počítačových sítí.
This bachelor thesis deals with security threats in open-source PBX systems, with a focus on PBX Asterisk. The aim of the thesis is to analyse security-relevant network-accessible parts of PBX Asterisk, propose a procedure for security testing of a VoIP PBX, and implement selected laboratory scenarios in an isolated environment. The theoretical part defines the security aspects of VoIP and PBX systems, especially from the perspective of confidentiality, integrity, and availability. It also describes the network-accessible parts of Asterisk, the importance of SIP/PJSIP and IAX2 protocols, and the role of the dialplan, configuration, endpoints, and management interfaces. The practical part focuses on the design of a laboratory environment, the selection of suitable tools, the reconnaissance of available services, the analysis of a vulnerability database, and the implementation of five scenarios related to service availability, access control, identity spoofing, and the processing of non-standard inputs. The result of the thesis is a practically oriented procedure for security verification of PBX Asterisk, a categorisation of vulnerabilities based on their impacts and methods of exploitation, and a laboratory assignment composed of five scenarios suitable for teaching cybersecurity and computer networking.
Keywords:
IAX2; identity spoofing; laboratory scenarios; PBX Asterisk; penetration testing; security threats; service availability; SIP/PJSIP; VoIP; vulnerabilities; bezpečnostní hrozby; dostupnost služby; IAX2; laboratorní scénáře; PBX Asterisk; penetrační testování; podvržení identity; SIP/PJSIP; VoIP; zranitelnosti
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/258699