Nharembozha dzeAmerica dzichakwikwidza nefoni spam

MuUS, tekinoroji yekusimbisa tekinoroji iri kuwedzera - iyo SHAKEN / STIR protocol. Ngatitaurei pamusoro pemisimboti yekushanda kwayo uye zvinogona kuita matambudziko.

Nharembozha dzeAmerica dzichakwikwidza nefoni spam
/flickr/ Mark Fischer / CC BY-SA

Dambudziko nekufona

Kusina kukumbirwa robo kufona ndicho chikonzero chakajairika chekunyunyuta kwevatengi kuUS Federal Trade Commission. Muna 2016 sangano akarekodha mamiriyoni mashanu hits, gore gare gare iyi nhamba yakapfuura mamiriyoni manomwe.

Aya maSpam mafoni haangotore nguva yevanhu. Masevhisi ekufona otomatiki anoshandiswa kubira mari. Sekureva kwaYouMail, munaGunyana gore rapfuura, makumi mana muzana emabhiriyoni mana ekufona zvakaitwa nevatsotsi. Munguva yezhizha ra2018, New Yorkers yakarasikirwa nemadhora mazana matatu emadhora mukuchinjisa kune matsotsi akavadaidza akamiririra zviremera uye nechisimba mari.

Dambudziko rakaunzwa kuUS Federal Communications Commission (FCC). Vamiriri vesangano yakabudisa chirevo, iyo yaida makambani ekufambisa mashoko kuti ashandise mhinduro yekurwisana nefoni spam. Mhinduro iyi yaive SHAKEN/STIR protocol. Muna March, kuedza pamwe chete kupedza AT&T uye Comcast.

Iyo SHAKEN/STIR protocol inoshanda sei

Telecom vanoshanda vachashanda nezvitupa zvedhijitari (izvo zvakavakwa pahwaro hweruzhinji kiyi cryptography) iyo inobvumira kuoneswa kwevanofona.

Nzira yekuongorora ichaenderera mberi sezvinotevera. Kutanga, mushandisi wemunhu ari kufona anogamuchira chikumbiro sveta KOKA kuti utange kubatanidza. Sevhisi yehuchokwadi yemupi inotarisisa ruzivo nezve kufona - nzvimbo, sangano, ruzivo rwemudziyo weanofona. Zvichienderana nemhedzisiro yecheki, kufona kunopihwa chimwe chezvikamu zvitatu: A - ruzivo rwese nezve akafona rwunozivikanwa, B - sangano nenzvimbo zvinozivikanwa, uye C - chete geographic nzvimbo yeanonyorera inozivikanwa.

Mushure meizvozvo, mushandisi anowedzera meseji ine chitambi chenguva, chikamu chekufona uye chinongedzo kune chitupa chemagetsi kune INVITE yekukumbira musoro. Heino muenzaniso wemharidzo yakadaro kubva kuGitHub repository imwe yeAmerican telecoms:

{
	"alg": "ES256",
        "ppt": "shaken",
        "typ": "passport",
        "x5u": "https://cert-auth.poc.sys.net/example.cer"
}

{
        "attest": "A",
        "dest": {
          "tn": [
            "1215345567"
          ]
        },
        "iat": 1504282247,
        "orig": {
          "tn": "12154567894"
        },
        "origid": "1db966a6-8f30-11e7-bc77-fa163e70349d"
}

Uyezve, chikumbiro chinoenda kune mupi weanodanwa munyoreri. Wechipiri anoshanda anodzima meseji achishandisa kiyi yeruzhinji, anofananidza zvirimo neSIP INVITE, uye anosimbisa huchokwadi hwechitupa. Chete mushure meizvozvo kubatana kunotangwa pakati pevanyoresa, uye bato "rinogamuchira" rinogamuchira chiziviso chekuti ndiani ari kumufonera.

Iyo yese yekusimbisa maitiro inogona kumiririrwa nedhiyagiramu:

Nharembozha dzeAmerica dzichakwikwidza nefoni spam

Maererano nenyanzvi, kufona kwekuongorora achatora kwete kupfuura 100 milliseconds.

Posts

sei noted musangano reUSTelecom, SHAKEN/STIR ichapa vanhu kutonga kwakawanda pamusoro penhare dzavanogamuchira, zvichiita kuti zvive nyore kwavari kusarudza kuti votora foni here kana kuti kwete.

Verenga pane yedu blog:

Asi pane maonero muindasitiri kuti protocol haizove "silver bullet". Nyanzvi dzinoti scammers vanongoshandisa workaround. Spammers vachakwanisa kunyoresa "dummy" PBX mune network yemushandisi muzita resangano uye kuita mafoni ese kuburikidza nayo. Kana PBX ichivharira, zvinokwanisika kungonyoresa zvakare.

By maererano mumiriri weimwe yenharembozha, kuonesa kuri nyore kwemunyoreri achishandisa zvitupa hakuna kukwana. Kuti umise scammers uye spammers, unofanirwa kubvumira maISPs kuti avhare otomatiki mafoni akadai. Asi nekuda kweizvi, Komisheni yezvekufambiswa kwemashoko ichafanirwa kugadzira bumbiro idzva remitemo rinozotonga hurongwa uhu. Uye FCC inogona kubata nenyaya iyi munguva pfupi iri kutevera.

Kubva kutanga kwegore, congressmen vari kufunga bhiri idzva rinozomanikidza Komisheni kugadzira nzira dzekuchengetedza vagari kubva kunhare-nhare uye kuongorora kuitwa kweSHAKEN / STIR standard.

Nharembozha dzeAmerica dzichakwikwidza nefoni spam
/flickr/ Jack Sem / CC BY

Zvinofanira kucherechedzwa kuti SHAKEN/STIR itwa muT-Mobile - kune mamwe mamodeli e-smartphone uye kuronga kuwedzera huwandu hwemidziyo inotsigirwa - uye Verizon - vatengi vevashandisi vayo vanogona kudhawunirodha yakakosha application iyo inonyevera nezve mafoni kubva kunhamba dzinofungidzirwa. Vamwe vatakuri veUS vachiri kuyedza tekinoroji. Vanotarisirwa kupedzisa bvunzo panopera 2019.

Chii chimwe chekuverenga mune yedu blog paHabrΓ©:

Source: www.habr.com

Voeg