You are here: Home Community BreakingPoint Labs Blog

RFC-4475: SIP Torture Tests

As of the next upcoming StrikePack, the BPS product will now have test cases from RFC-4475, the SIP Torture Tests, in the form of strikes. The sections of the RFC that are covered by this StrikeSet are Section 3.1.2: Invalid Messages, Section 3.2: Transaction Layer Semantics, and Section 3.3: Application Layer Semantics. The remaining two sections containing test cases, Section 3.1.1: Valid Messages and Section 3.4: Backward Compatibility, are not covered as they are comprised of test cases which are valid SIP messages.

The strikes contained in this StrikeSet are intended to be used as part of a broader RFC-4475 test plan, and should not be used without full understanding of RFC-4475, the sections contained therein, and the individual test cases defined for each section. The strikes for Section 3.1.2: Invalid Messages are likely the only strikes from this test suite for which a pass/fail result in the UI will be valuable, as these are the only test cases from RFC-4475 which should be definitively blocked, rejected, dropped, or otherwise ignored by a SIP-aware Device Under Test (DUT) or a SIP endpoint. The remaining sections' individual test cases each define for themselves how a SIP-aware DUT or SIP endpoint should behave in response to that specific test case, and therefore will likely require external monitoring of either the network traffic or the device itself in order to determine a pass/fail verdict.

The strikes for the BPS RFC-4475 test suite will be available by searching for keyword "torture" in the BPS Attack Manager after applying the next upcoming StrikePack.

Posted by Dustin D. Trammell (2008-02-27 14:04:38)