
Oracle SBC Security Guide
Figure 1: Net-SAFE Framework
The Net-SAFE Framework spans seven general functions:
1. Denial of Service (DoS) protection
Dynamic self-protection against malicious and non-malicious DoS attacks and overloads at
layer 3/4 (e.g. TCP, SYN, ICMP, fragments, etc.) and layer 5 (e.g. SIP signaling floods,
malformed messages, etc.)
Traffic management queues for control and throttling of signaling and media
2. Access control
Session-aware access control for signaling and media using static and dynamic permit/deny
ACLs at layers 3 and 5
3. Topology hiding and privacy
Complete infrastructure topology hiding at all protocol layers for confidentiality and attack
prevention as well as modification, removal or insertion of call signaling application headers
and fields
Confidentiality and integrity through use of industry-standard encryption methods such as
TLS/SRTP and IPSec
4. VPN separation
Support for Virtual Private Networks (VPNs) with full inter-VPN topology hiding and
separation
Ability to create separate signaling-only and media-only VPNs
Optional intra-VPN media hair-pinning to monitor calls within a VPN
5. Service infrastructure DoS prevention
Comentarios a estos manuales