SIPConfusion: Exploiting SIP Semantic Ambiguities for Caller ID and SMS Spoofing
Qi Wang, Jianjun Chen, Jingcheng Yang, Jiahe Zhang, Yaru Yang, Haixin Duan
Abstract
—Session Initiation Protocol (SIP) is a cornerstone of modern real-time communication systems, powering voice calls, text messaging, and multimedia sessions across services such as VoIP, VoLTE, and RCS. While SIP provides mechanisms for authentication and identity assertion, its inherent flexibility poses the risk of semantic ambiguity among implementations that can be exploited by attackers. In this paper, we present S IP C HIMERA , a novel black-box fuzzing framework designed to systematically identify ambiguity-based identity spoofing vulnerabilities across SIP implementations. We evaluated S IP C HIMERA against six widely used open-source SIP servers—including Asterisk and OpenSIPS—and nine popular user agents, uncovering that attackers could spoof their identity via manipulating identity headers and circumvent authentication. We demonstrate the real-world impact of these vulnerabilities by evaluating five VoIP devices, seven commercial SIP deployments, and three carrier-grade RCS-based SMS platforms. Our experiments show that attackers can exploit these vulnerabilities to perform caller ID spoofing in VoIP calls and send spoofed SMS messages over RCS, impersonating arbitrary users or services. We have responsibly disclosed our findings to affected vendors and received positive acknowledgments. We finally propose remedies to mitigate those issues.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext af94a3fe-bdc1-4011-bdf6-20dd3b6d952aBuilds on16
- SoK: Everyone Hates Robocalls: A Survey of Techniques Against Telephone SpamHuahong Tu, Adam Doupé, Ziming Zhao, Gail-Joon AhnS&P 2016 · 90 citations
- New Security Threats Caused by IMS-based SMS Service in 4G LTE NetworksGuan-Hua Tu, Chi-Yu Li, Chunyi Peng, Yuanjie Li et al.CCS 2016 · 60 citations
- Host of Troubles: Multiple Host Ambiguities in HTTP ImplementationsJianjun Chen, Jian Jiang, Hai-Xin Duan, Nicholas Weaver et al.CCS 2016 · 49 citations
- Forwarding-Loop Attacks in Content Delivery NetworksJianjun Chen, Xiaofeng Zheng, Hai-Xin Duan, Jinjin Liang et al.NDSS 2016 · 44 citations
- AuthentiCall: Efficient Identity and Content Authentication for Phone CallsBradley Reaves, Logan Blue, Hadi Abdullah, Luis Vargas et al.USENIX Security 2017 · 39 citations
Related papers
- STIR/SHAKEN: A Cocktail of Cryptographic ClumsinessJoshua Brown, Paul Grubbs, Matthew HardemanS&P 2026 · 1 citation
- SIMurai: Slicing Through the Complexity of SIM Card Security ResearchTomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang, Marius MuenchUSENIX Security 2024 · 10 citations
- SemFuzz: A Semantics-Aware Fuzzing Framework for Network Protocol ImplementationsYanbang Sun, Quan Luo, Yuelin Wang, Qian Chen et al.WWW 2026
- Identifying Logical Vulnerabilities in QUIC ImplementationsKaihua Wang, Jianjun Chen, Pinji Chen, Jianwei Zhuge et al.NDSS 2026 · 1 citation
- Analysis of DTLS Implementations Using Protocol State FuzzingPaul Fiterau-Brostean, Bengt Jonsson, Robert Merget, Joeri de Ruiter et al.USENIX Security 2020
