🛡️ Güvenlik Sertleştirme & NEC CCIS Protokol Gateway 🛡️ Security Hardening & NEC CCIS Protocol Gateway 🛡️ Sicherheitshärtung & NEC CCIS Protokoll-Gateway
AiPBX; kurumsal VoIP ağlarının karşılaştığı SIP brute-force saldırılarını ve dinleme tehditlerini bertaraf eden çok katmanlı savunma mekanizmalarına sahiptir. Ayrıca tescilli NEC UNIVERGE CCIS protokolünü modern IP dünyasıyla birleştiren kurumsal ağ geçidi mimarisi sunar.
AiPBX incorporates multi-tier defense mechanisms against brute-force VoIP scanners and packet sniffers. It also features a protocol-level gateway for bridging legacy NEC UNIVERGE CCIS PBXs with Asterisk 22 WebRTC.
AiPBX bietet mehrschichtige Abwehrmechanismen gegen Brute-Force-Scans und Abhörversuche. Zudem integriert es ein Protokoll-Gateway zur Anbindung klassischer NEC UNIVERGE CCIS-Anlagen an Asterisk 22 WebRTC.
1. Çok Katmanlı Savunma Mimarisi (Defense-in-Depth) 1. Defense-in-Depth Architecture 1. Mehrstufige Sicherheitsarchitektur
| KatmanSecurity TierSicherheits-Ebene | Uygulanan Güvenlik PolitikasıEnforced PolicyAngewandte Richtlinie | Sağlanan KorumaMitigated ThreatSchutzwirkung |
|---|---|---|
| Edge L4 Stream | Nginx L4 Stream + ALPN Inspection | Gereksiz portları kapatır, rastgele port taramalarını boşa çıkarır. Minimizes attack surface by tunneling over port 443; drops unauthorized probes. Minimiert Angriffsfläche durch Bündelung auf Port 443. |
| Transport Encryption | TLS 1.3, DTLS-SRTP, SDES-SRTP, TURNS | Paket dinleme (Sniffing, Wireshark) saldırılarında sesin dinlenmesini önler. Prevents audio eavesdropping and credential sniffing across public networks. Verhindert Abhören von Sprachdaten und Zugangsdaten im Netzwerk. |
| Rate Limiting & Jails | Fail2ban PBX Jails + Nginx Leaky Bucket | SIP brute-force botlarını ve şifre deneyen tarayıcıları anında banlar. Instantly bans SIP brute-force bots and aggressive scanners (sipvicious). Sperrt SIP-Brute-Force-Bots und Scanner automatisch via iptables. |
2. Fail2ban PBX Jails & Otomatik Engelleme 2. Fail2ban PBX Jails & Automated Banning 2. Fail2ban PBX-Jails & Automatische Sperren
[asterisk-pjsip]
enabled = true
filter = asterisk-pjsip
action = iptables-allports[name=ASTERISK, protocol=all]
logpath = /var/log/asterisk/messages
maxretry = 5
findtime = 600
bantime = 86400
3. NEC UNIVERGE CCIS Protokolü & Gateway Rehberi 3. NEC UNIVERGE CCIS Protocol & Gateway Guide 3. NEC UNIVERGE CCIS Protokoll- & Gateway-Handbuch
CCIS (Common Channel Interoffice Signaling); NEC tarafından kurumsal santral ağlarında (SV8100, SV8300, SV8500, NEAX) santraller arası özellik şeffaflığı (feature transparency) sağlamak amacıyla ITU-T SS7 No.7 / ISUP ve ITU-T Q.931 (ISDN DSS1) standartları harmanlanarak geliştirilmiş özel bir hibrit protokoldür.
CCIS (Common Channel Interoffice Signaling) is NEC's proprietary inter-PBX signaling protocol (used on SV8100, SV8300, SV8500, NEAX). It blends ITU-T SS7 No.7 / ISUP and ITU-T Q.931 (ISDN DSS1) to achieve seamless feature transparency across multi-site enterprise topologies.
CCIS (Common Channel Interoffice Signaling) ist NECs proprietäres Vernetzungsprotokoll (eingesetzt in SV8100, SV8300, SV8500, NEAX). Es kombiniert ITU-T SS7 No.7 / ISUP mit ITU-T Q.931 (ISDN DSS1) für standortübergreifende Leistungstransparenz.
Byte 0 Byte 1 Byte 2 Byte 3 Byte 4 Byte 5..N
+-------------+-------------+-------------+-------------+-------------+---------------+
| SIO | DPC | OPC | CIC | Msg Type | Parameters |
| (Sub-Srv) | (Dest PC) | (Orig PC) | (Circuit ID)| (CSTS Code) | (Caller/Called|
+-------------+-------------+-------------+-------------+-------------+---------------+