Session Initiation Protocol (SIP)

The signalling protocol (RFC 3261) that sets up, changes and ends voice, video and messaging sessions over IP. It negotiates calls but does not carry the media itself.

The Session Initiation Protocol (SIP), specified in RFC 3261, is the signalling protocol widely used for voice over IP and many video and conferencing systems. It is a text-based protocol similar in style to HTTP. Endpoints register their current location with a registrar, and a call starts when one party sends an INVITE that proxies route to the other. The two sides agree on the media they will use, then the audio or video flows separately over RTP. SIP later modifies or ends the session.

The key idea is that signalling and media are separate. Protecting SIP with TLS keeps call setup, registrations and any keys carried in the signalling away from eavesdroppers, but it does nothing for the conversation itself; that needs the Secure Real-time Transport Protocol. Threats against SIP include spoofing of caller identity, registration hijacking that redirects someone’s incoming calls, toll fraud through weakly protected accounts, and denial of service through floods of call requests. Strong registration authentication, TLS for signalling and a controlled border with outside carriers are the usual responses.

Exam relevance: a scenario about securing call setup or stopping forged registrations is likely to turn on SIP, while one about hearing the call content turns on the media stream. Candidates are expected to know that SIP signals the session and does not carry the voice.