{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T23:39:35Z","timestamp":1761953975788,"version":"build-2065373602"},"reference-count":51,"publisher":"Elsevier BV","issue":"12","license":[{"start":{"date-parts":[[2008,8,1]],"date-time":"2008-08-01T00:00:00Z","timestamp":1217548800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2008,8]]},"DOI":"10.1016\/j.comnet.2008.05.001","type":"journal-article","created":{"date-parts":[[2008,5,9]],"date-time":"2008-05-09T10:10:23Z","timestamp":1210327823000},"page":"2432-2446","source":"Crossref","is-referenced-by-count":17,"title":["Assessing the risk of intercepting VoIP calls"],"prefix":"10.1016","volume":"52","author":[{"given":"M.","family":"Benini","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S.","family":"Sicari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"unstructured":"S. Garfinkel, VoIP and Skype security, March 2005. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/tacticaltech.org\/skype_security>.","key":"10.1016\/j.comnet.2008.05.001_bib1"},{"doi-asserted-by":"crossref","unstructured":"A. Godber, P. Dasgupta, Secure wireless gateway, in: Proceedings of the Third ACM Workshop on Wireless Security, ACM Press, New York, NY, USA, 2002, pp. 41\u201346.","key":"10.1016\/j.comnet.2008.05.001_bib2","DOI":"10.1145\/570681.570686"},{"doi-asserted-by":"crossref","unstructured":"E. Barrantes, D. Ackley, T. Palmer, D. Stefanovic, D.D. Zovi, Randomized instruction set emulation to disrupt binary code injection attacks, in: Proceedings of the 10th ACM Conference on Computer and Communications Security, ACM Press, New York, NY, USA, 2003, pp. 281\u2013289.","key":"10.1016\/j.comnet.2008.05.001_bib3","DOI":"10.1145\/948109.948147"},{"issue":"3","key":"10.1016\/j.comnet.2008.05.001_bib4","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1002\/nem.433","article-title":"Identifying enterprise network vulnerabilities","volume":"12","author":"Myerson","year":"2002","journal-title":"International Journal of Network Management"},{"issue":"3","key":"10.1016\/j.comnet.2008.05.001_bib5","doi-asserted-by":"crossref","first-page":"44","DOI":"10.1109\/MSP.2005.62","article-title":"Challenges in securing voice over IP","volume":"3","author":"Walsh","year":"2005","journal-title":"IEEE Security and Privacy"},{"issue":"5","key":"10.1016\/j.comnet.2008.05.001_bib6","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1109\/MSP.2005.122","article-title":"Finding faults","volume":"3","author":"Naccache","year":"2005","journal-title":"IEEE Security and Privacy"},{"issue":"6","key":"10.1016\/j.comnet.2008.05.001_bib7","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/MSP.2005.158","article-title":"Security, wiretapping, and the internet","volume":"3","author":"Landau","year":"2005","journal-title":"IEEE Security and Privacy"},{"unstructured":"K. Fiveash, VoIP \u2013 open season for hackers, November 2006. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.theregister.co.uk\/2006\/11\/29\/voip_hack_calls>.","key":"10.1016\/j.comnet.2008.05.001_bib8"},{"unstructured":"Inchiesta Telecom, altri due arresti, Corriere della Sera, January 2007. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.corriere.it\/Primo_Piano\/Cronache\/2007\/01_Gennaio\/31\/arresti_telecom.shtml>.","key":"10.1016\/j.comnet.2008.05.001_bib9"},{"unstructured":"E. Galli Della Loggia, L\u2019Idra italiana, Corriere della Sera, September 2006. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.corriere.it\/Primo_Piano\/Editoriali\/2006\/09_Settembre\/27\/dellaloggia.shtml>.","key":"10.1016\/j.comnet.2008.05.001_bib10"},{"unstructured":"M. Benini, S. Sicari, Risk assessment: intercepting VoIP calls, in: Proceedings of the VIPSI-2007 Venice Conference, International Conferences on Advances in the Internet, Processing, Systems, and Interdisciplinary Research, Venice, Italy, 2007, pp. 1\u201310.","key":"10.1016\/j.comnet.2008.05.001_bib11"},{"doi-asserted-by":"crossref","unstructured":"D. Balzarotti, M. Monga, S. Sicari, Assessing the risk of using vulnerable components, in: D. Gollmann, F. Massacci, A. Yautsiukhin (Eds.), Quality of Protection \u2013 Security Measurements and Metrics, vol. 23 of Advances in Information Security, Springer, New York, NY, USA, 2006, pp. 65\u201378.","key":"10.1016\/j.comnet.2008.05.001_bib12","DOI":"10.1007\/978-0-387-36584-8_6"},{"issue":"3","key":"10.1016\/j.comnet.2008.05.001_bib13","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1002\/nem.472","article-title":"Development of security policies for private networks","volume":"13","author":"Bakry","year":"2003","journal-title":"International Journal of Network Management"},{"issue":"11","key":"10.1016\/j.comnet.2008.05.001_bib14","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1145\/1167838.1167839","article-title":"New architecture for intra-domain network security issues","volume":"49","author":"Huang","year":"2006","journal-title":"Communications of the ACM"},{"unstructured":"M. Benini, S. Sicari, A mathematical framework for risk assessment, in: Proceedings of the First NTMS International Conference, 2007.","key":"10.1016\/j.comnet.2008.05.001_bib15"},{"year":"2003","author":"Howard","series-title":"Writing Secure Code","key":"10.1016\/j.comnet.2008.05.001_bib16"},{"issue":"12","key":"10.1016\/j.comnet.2008.05.001_bib17","first-page":"21","article-title":"Attack trees","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr. Dobb\u2019s Journal"},{"doi-asserted-by":"crossref","unstructured":"J. Rosenberg, H. Schulzrinne, G. Camarillo, A. Johnston, J. Peterson, R. Sparks, M. Handley, E. Schooler, RFC 3261: SIP: Session initiation protocol, Junuary 2002. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.ietf.org\/rfc\/rfc3261.txt>.","key":"10.1016\/j.comnet.2008.05.001_bib18","DOI":"10.17487\/rfc3261"},{"unstructured":"J. Postel, RFC 791: Internet protocol, September 1981. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.rfc-editor.org\/rfc\/rfc791.txt>.","key":"10.1016\/j.comnet.2008.05.001_bib19"},{"year":"2003","author":"Hardy","series-title":"VoIP Service Quality: Measuring and Evaluating Packet-Switched Voice","key":"10.1016\/j.comnet.2008.05.001_bib20"},{"unstructured":"P. Mehta, S. Udani, Overview of voice over IP, Technical report MS-CIS-01-31, Department of Computer and Information Science, University of Pennsylvania, February 2001.","key":"10.1016\/j.comnet.2008.05.001_bib21"},{"issue":"9","key":"10.1016\/j.comnet.2008.05.001_bib22","doi-asserted-by":"crossref","first-page":"1495","DOI":"10.1109\/JPROC.2002.802005","article-title":"Voice over internet protocol (VoIP)","volume":"90","author":"Goode","year":"2002","journal-title":"Proceedings of the IEEE"},{"issue":"11","key":"10.1016\/j.comnet.2008.05.001_bib23","doi-asserted-by":"crossref","first-page":"1992","DOI":"10.1016\/j.comcom.2005.12.013","article-title":"Assessed quality of service and voice and data integration: a case study","volume":"29","author":"La Corte","year":"2006","journal-title":"Computer Communications"},{"issue":"1","key":"10.1016\/j.comnet.2008.05.001_bib24","doi-asserted-by":"crossref","first-page":"89","DOI":"10.1145\/502269.502271","article-title":"Voice over IP","volume":"45","author":"Varshney","year":"2002","journal-title":"Communications of the ACM"},{"key":"10.1016\/j.comnet.2008.05.001_bib25","first-page":"26","article-title":"Voice by the packet?","volume":"6","author":"Decina","year":"1983","journal-title":"IEEE Journal on Selected Areas in Communications SAC-1"},{"doi-asserted-by":"crossref","unstructured":"D. Kuhn, T. Walsh, S. Fries, Security considerations of voice over IP Systems, National Institute of Standards and Technology (NIST), Gaithersburs, MD, USA, Computer Security Division, Special Publication 800-58, January 2005.","key":"10.1016\/j.comnet.2008.05.001_bib26","DOI":"10.6028\/NIST.SP.800-58"},{"unstructured":"The voice over IP security alliance. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.voipsa.org\/>.","key":"10.1016\/j.comnet.2008.05.001_bib27"},{"unstructured":"M. Tanase, Voice over IP security, Security Focus (Mar. 2004). URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.securityfocus.com\/infocus\/1767>.","key":"10.1016\/j.comnet.2008.05.001_bib28"},{"doi-asserted-by":"crossref","unstructured":"R. Barbieri, D. Bruschi, E. Rosti, Voice over IPSec: Analysis and solutions, in: Proceedings of the 18th Annual Computer Security Applications Conference, IEEE Computer Society, Washington, DC, USA, 2002, pp. 261\u2013270.","key":"10.1016\/j.comnet.2008.05.001_bib29","DOI":"10.1109\/CSAC.2002.1176297"},{"unstructured":"J. Halpern, IP Telephony Security in Depth, Cisco Systems Inc., White paper, 2002.","key":"10.1016\/j.comnet.2008.05.001_bib30"},{"unstructured":"M. Marjalaakso, Security requirements and constraints of VoIP, Tech. Rep., Department of Electrical Engineering and Telecommunications, Helsinki University of Technology, 2000. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.tml.tkk.fi\/Opinnot\/Tik-110.501\/2000\/papers\/marjalaakso\/voip.html>.","key":"10.1016\/j.comnet.2008.05.001_bib31"},{"unstructured":"J. Larson, T. Dawson, M. Evans, J. Straley, Defending VoIP networks from distributed DoS (DDoS) attacks, in: Proceedings of the Voice over IP Workshop, IEEE Global Telecommunications Conference, 2004.","key":"10.1016\/j.comnet.2008.05.001_bib32"},{"doi-asserted-by":"crossref","unstructured":"W. Rippon, Threat assessment of IP based voice systems., in: Proceedings of the 1st IEEE Workshop on VoIP Management and Security, Vancouver, Canada, 2006, pp. 19\u201328.","key":"10.1016\/j.comnet.2008.05.001_bib33","DOI":"10.1109\/VOIPMS.2006.1638118"},{"unstructured":"P. Hochmuth, T. Greene, Firewall limits vex VoIP users, Network World, July 2002. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.networkworld.com\/news\/2002\/0708voip.html>.","key":"10.1016\/j.comnet.2008.05.001_bib34"},{"doi-asserted-by":"crossref","unstructured":"X. Wang, S. Chen, S. Jajodia, Tracking anonymous peer-to-peer VoIP calls on the Internet, in: Proceedings of the 12th ACM Conference on Computer and Communications Security, ACM Press, New York, NY, USA, 2005, pp. 81\u201391.","key":"10.1016\/j.comnet.2008.05.001_bib35","DOI":"10.1145\/1102120.1102133"},{"issue":"1","key":"10.1016\/j.comnet.2008.05.001_bib36","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1216370.1216373","article-title":"Survey of network-based defense mechanisms countering the DoS and DDoS problems","volume":"39","author":"Peng","year":"2007","journal-title":"ACM Computing Surveys"},{"issue":"4","key":"10.1016\/j.comnet.2008.05.001_bib37","doi-asserted-by":"crossref","first-page":"375","DOI":"10.1145\/162124.162127","article-title":"Information system security design methods: implications for information systems development","volume":"25","author":"Baskerville","year":"1993","journal-title":"ACM Computing Survey"},{"doi-asserted-by":"crossref","unstructured":"C. Salter, O. Saydjari, B. Schneier, J. Wallner, Toward a secure system engineering methodology, in: Proceedings of the 1998 Workshop on New Security Paradigms, ACM Press, New York, NY, USA, 1998, pp. 2\u201310.","key":"10.1016\/j.comnet.2008.05.001_bib38","DOI":"10.1145\/310889.310900"},{"doi-asserted-by":"crossref","unstructured":"H. Abdelnur, V. Cridlig, R. State, O. Festor, VoIP security assessment: Method and tools, in: Proceedings of the 1st IEEE Workshop on VoIP Management and Security, Vancouver, Canada, 2006, pp. 29\u201334.","key":"10.1016\/j.comnet.2008.05.001_bib39","DOI":"10.1109\/VOIPMS.2006.1638119"},{"doi-asserted-by":"crossref","unstructured":"H.Schulzrinne, S. Casner, R. Frederick, V. Jacobson, RFC 3550: RTP: A transport protocol for real-time applications, July 2003. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.ietf.org\/rfc\/rfc3550.txt>.","key":"10.1016\/j.comnet.2008.05.001_bib40","DOI":"10.17487\/rfc3550"},{"doi-asserted-by":"crossref","unstructured":"I. Moskowitz, M. Kang, An insecurity flow model, in: Proceedings of the 1997 Workshop on New Security Paradigms, ACM Press, New York, NY, USA, 1997, pp. 61\u201374.","key":"10.1016\/j.comnet.2008.05.001_bib41","DOI":"10.1145\/283699.283741"},{"doi-asserted-by":"crossref","unstructured":"C. Alberts, A. Dorofee, J. Stevens, C. Woody, Introduction to the Octave approach, October 2003. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.cert.org\/octave\/approach_intro.pdf>.","key":"10.1016\/j.comnet.2008.05.001_bib42","DOI":"10.21236\/ADA634134"},{"unstructured":"B. Jenkins, Risk analysis helps establish a good security posture; risk management keeps it that way. White Paper, 1998. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.nr.no\/~abie\/RiskAnalysis.htm>.","key":"10.1016\/j.comnet.2008.05.001_bib43"},{"unstructured":"T. Siu, Risk-eye for the IT security guy, February 2004. URL <https:\/\/2.zoppoz.workers.dev:443\/http\/www.giac.org\/certified_professionals\/practicals\/gsec\/3752.php>.","key":"10.1016\/j.comnet.2008.05.001_bib44"},{"doi-asserted-by":"crossref","unstructured":"G. Sharp, P. Enslow, S. Navathe, F. Farahmand, Managing vulnerabilities of information system to security incidents, in: Proceedings of the 5th International Conference on Electronic Commerce, ACM Press, New York, NY, USA, 2003, pp. 348\u2013354.","key":"10.1016\/j.comnet.2008.05.001_bib45","DOI":"10.1145\/948005.948050"},{"issue":"7","key":"10.1016\/j.comnet.2008.05.001_bib46","doi-asserted-by":"crossref","first-page":"307","DOI":"10.1016\/S0950-7051(00)00071-X","article-title":"Making decisions: Bayesian nets and MCDA","volume":"14","author":"Fenton","year":"2001","journal-title":"Knowledge-Based Systems"},{"key":"10.1016\/j.comnet.2008.05.001_bib47","series-title":"UML and the Unified Process","first-page":"332","article-title":"The CORAS methodology: model-based risk management using UML and UP","author":"den Braber","year":"2003"},{"unstructured":"Y. Stamatiou, E. Skipenes, E. Henriksen, N. Stathiakis, A. Sikianakis, E. Charalambous, N. Antonakis, K. St\u00f8len, F. den Braber, M. Soldal Lund, K. Papadaki, G. Valvis, The CORAS approach for model-based risk management applied to a telemedicine service, in: Proceedings of Medical Informatics Europe, IOS Press, 2003, pp. 206\u2013211.","key":"10.1016\/j.comnet.2008.05.001_bib48"},{"doi-asserted-by":"crossref","unstructured":"N. Stathiakis, C. Chronaki, E. Skipenes, E. Henriksen, E. Charalambous, A. Sykianakis, G. Vrouchos, N. Antonakis, M. Tsiknakis, S. Orphanoudakis, Risk assessment of a cardiology eHealth service in HYGEIAnet, in: Proceedings of Computers in Cardiology, IEEE, 2003, pp. 201\u2013204.","key":"10.1016\/j.comnet.2008.05.001_bib49","DOI":"10.1109\/CIC.2003.1291125"},{"doi-asserted-by":"crossref","unstructured":"G. Biswas, K. Debelak, K. Kawamura, Application of qualitative modelling to knowledge-based risk assessment studies, in: Second International Conference on Industrial Engineering Applications of Artificial Intelligence Expert Systems, ACM Press, New York, NY, USA, 1989, pp. 92\u2013101.","key":"10.1016\/j.comnet.2008.05.001_bib50","DOI":"10.1145\/66617.66630"},{"issue":"3","key":"10.1016\/j.comnet.2008.05.001_bib51","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/MSP.2005.81","article-title":"Security meter: a practical decision-tree model to quantify risk","volume":"3","author":"Sahinoglu","year":"2005","journal-title":"IEEE Security and Privacy"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S1389128608001448?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S1389128608001448?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,1,30]],"date-time":"2025-01-30T05:12:50Z","timestamp":1738213970000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128608001448"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,8]]},"references-count":51,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2008,8]]}},"alternative-id":["S1389128608001448"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.comnet.2008.05.001","relation":{},"ISSN":["1389-1286"],"issn-type":[{"type":"print","value":"1389-1286"}],"subject":[],"published":{"date-parts":[[2008,8]]}}}