Methodology for Studying the Level of Network Security of an IP PBX Server
Abstract
1. Introduction
- VoIP and the standard corporate LAN use the same network because both technologies use the IP technology. This means that maintenance costs are lower because only one network needs to be maintained instead of two different networks.
- The costs for technical support staff are reduced. Instead of employing separate staff to maintain the digital telephone network (phones and the telephone exchange) and additional technical staff to maintain the IP network and its end devices, a single technical team will be used to maintain only the IP network.
- Calls can be made from a computer, smartphone, tablet, or IP phone.
- VoIP allows regular analogue phones to be connected to a VoIP system using adapters (analog telephone adapters, ATAs). Therefore, the company can save money by reducing the need to buy physical IP phones during the initial launch of the VoIP system.
- VoIP technology offers many more services and features than standard digital telephone exchanges. One example is Follow Me (or Find Me/Follow Me). This is an advanced call-forwarding feature that “follows” the user by forwarding their incoming calls to different devices (mobile, home, IP phone) either in a predefined order or all at once. This means that they do not miss important customer calls, regardless of location, and allows employees to work flexibly from anywhere.
- There are many more other advantages and services that are offered only with VoIP technology.
2. Related Works
3. Research Methodology, Topology of the Experimental Network, and Tools Used
3.1. Research Methodology
3.2. Topology of the Experimental Network
3.3. Used Tools
- Network protocol analyzer—Wireshark [31] was used for the purposes of this study. It captured all packets exchanged between the VoIP server and its subscribers. Its main advantage, which led to the use of this tool, is its built-in capabilities for analyzing VoIP streams;
- hping3—This is a tool built into Kali Linux. It is used to create custom TCP/UDP packets. These packets are used to launch various TCP/UDP DoS attacks [32]. In this study, hping3 was used to implement different DoS attacks;
- Nmap—This tool is also part of the Kali Linux toolkit. It is used to scan ports, identify different network vulnerabilities, and more [33]. In this study, the analysis functionality of Nmap was used, which is based on specialized scripts. These scripts are used to analyze a particular network device for various network vulnerabilities;
- Network analyzer: Colasoft Capsa 11 free [34] was used for this work. It is used to monitor the entering/leaving traffic of the studied VoIP platform. This tool was used to determine how the VoIP platform responds to the penetration tests.
4. Developed Methodology
5. Results
5.1. Results for VitalPBX
5.1.1. Identifying Network Vulnerabilities
5.1.2. Penetration Tests During Audio Calls Only
Normal Operation Mode
TCP DoS Attack
UDP DoS Attack
5.1.3. Penetration Tests During Video Calls Only
Normal Operation Mode
TCP DoS Attack
UDP DoS Attack
5.2. Results for Issabel
5.2.1. Finding out Network Vulnerabilities
5.2.2. Penetration Tests During Audio Call Only
Normal Operation Mode
TCP DoS Attack
UDP DoS Attack
6. Analysis and Recommendations
- Network segmentation by creating VLANs and using hardware firewalls.
- Load balancing—distributing traffic across multiple servers.
- Blocking traffic from known or suspected IP addresses that have been associated with DoS attacks in the past or present.
- Limiting traffic speed, thus preventing server overload from a DoS attack.
- Using Content Delivery Networks (CDNs)—this distributes the content of the website across several locations, preventing a DoS attack from bringing down the entire site.
7. Conclusions
Funding
Data Availability Statement
Conflicts of Interest
References
- Mahato, R.K. Enhancing VoIP Mobility: Dynamic Call Transfer Across 5G, 4G, and Wi-Fi Networks Using Asterisk PBX. In Proceedings of the 2024 IEEE International Black Sea Conference on Communications and Networking (BlackSeaCom), Tbilisi, Georgia, 24–27 June 2024; pp. 390–393. [Google Scholar]
- Nalla, N.R.; Sakthivel, S.; Shankar, R. Low Cost VOIP System Incorporation with Raspberry Pi. In Proceedings of the 6th International Conference on Intelligent Computing and Control Systems (ICICCS), Madurai, India, 25–27 May 2022; pp. 94–99. [Google Scholar]
- Vylezich, Z.; Vrsecka, M.; Platenka, V. Extending the Capabilities of Private 5G Networks for VoIP Purposes. In Proceedings of the 2025 International Conference on Military Technologies (ICMT), Brno, Czech Republic, 27–30 May 2025; pp. 1–6. [Google Scholar]
- El-Amine, O.M.; Sall, M.; Basse, A.; Bouallegue, R. A WebRTC—VoIP Communication Platform. In Proceedings of the 10th International Conference on Internet of Everything, Microwave Engineering, Communication and Networks (IEMECON), Jaipur, India, 1–2 December 2021; pp. 1–4. [Google Scholar]
- Vichev, V.; Georgieva, T. IP Network Performance Analysis in VoIP Environment. In Proceedings of the International Conference Automatics and Informatics (ICAI), Varna, Bulgaria, 10–12 October 2024; pp. 158–163. [Google Scholar]
- Cristian, S.; Gabriel, M.E.; Gabriel, P.; Denisa, C.L.; Nicoleta, A.; Constantin, P.D. VoIP system for Wi-Fi Networks and Smart Terminals. In Proceedings of the 15th International Conference on Electronics, Computers and Artificial Intelligence (ECAI), Bucharest, Romania, 29–30 June 2023; pp. 1–6. [Google Scholar]
- Oliveira, L.P.; Nascimento, G.A.D. A Systematic Literature Review on Asterisk: Teach More than VoIP Communication. In Proceedings of the 29th International Conference on Telecommunications (ICT), Toba, Indonesia, 8–9 November 2023; pp. 1–6. [Google Scholar]
- Ahlawat, A.; Du, W. TruzCall: Secure VoIP Calling on Android using ARM TrustZone. In Proceedings of the Sixth International Conference on Mobile And Secure Services (MobiSecServ), Miami Beach, FL, USA, 22–23 February 2020; pp. 1–12. [Google Scholar]
- Grushko, S.A.; Pshenichnikov, A.P.; Malikova, E.E.; Malikov, A.Y. Virtual Asterisk IP-PBX Operation Studying and Exploring at the University. In Proceedings of the 2022 Systems of Signals Generating and Processing in the Field of on Board Communications, Moscow, Russia, 15–17 March 2022; pp. 1–5. [Google Scholar]
- Yakubova, M.; Alipbayev, K.; Manankova, O. Research on Voice Traffic Transmitted Over an IP Network Based on IP PBX Asterisk under the Use of Various Codecs and Cryptosystems. In Proceedings of the 8th International Conference on Cryptography, Security and Privacy (CSP), Osaka, Japan, 20–22 April 2024; pp. 106–111. [Google Scholar]
- Suthar, D.; Rughani, P.H. A Comprehensive Study of VoIP Security. In Proceedings of the 2nd International Conference on Advances in Computing, Communication Control and Networking (ICACCCN), Greater Noida, India, 18–19 December 2020; pp. 812–817. [Google Scholar]
- Khan, H.M.A.; Inayat, U.; Zia, M.F.; Ali, F.; Jabeen, T.; Ali, S.M. Voice Over Internet Protocol: Vulnerabilities and Assessments. In Proceedings of the 2021 International Conference on Innovative Computing (ICIC), Lahore, Pakistan, 9–10 November 2021; pp. 1–6. [Google Scholar]
- Sanlioz, G.; Kara, M.; Aydin, M.A. Security and Performance Evaluation in Peer- To-Peer VoIP Communication. In Proceedings of the 2024 IEEE International Black Sea Conference on Communications and Networking (BlackSeaCom), Tbilisi, Georgia, 24–27 June 2024; pp. 340–343. [Google Scholar]
- Biondi, P.; Bognanni, S.; Bella, G. VoIP Can Still Be Exploited—Badly. In Proceedings of the Fifth International Conference on Fog and Mobile Edge Computing (FMEC), Paris, France, 20–23 April 2020; pp. 237–243. [Google Scholar]
- Neacşu, E.; Şchiopu, P. An Analysis of Security Threats in VoIP Communication Systems. In Proceedings of the 12th International Conference on Electronics, Computers and Artificial Intelligence (ECAI), Bucharest, Romania, 25–27 June 2020; pp. 1–6. [Google Scholar]
- Feng, Y.; Xiong, F.; Huang, W.; Xiong, Y. Security Analysis of Session Initiation Protocol Digest Access Authentication Scheme. In Proceedings of the 7th International Conference on Big Data Computing and Communications (BigCom), Deqing, China, 13–15 August 2021; pp. 129–135. [Google Scholar]
- Khalid, Z.; Iqbal, F.; Kamoun, F.; Hussain, M.; Khan, L.A. Forensic Analysis of the Cisco WebEx Application. In Proceedings of the 5th Cyber Security in Networking Conference (CSNet), Abu Dhabi, United Arab Emirates, 12–14 October 2021; pp. 90–97. [Google Scholar]
- Moffitt, K.; Karabiyik, U.; Hutchinson, S.; Yoon, Y.H. Discord Forensics: The Logs Keep Growing. In Proceedings of the 11th Annual Computing and Communication Workshop and Conference (CCWC), Virtual, 27–30 January 2021; pp. 0993–0999. [Google Scholar]
- Kishkin, K.; Kanchev, H.; Arnaudov, D. Modeling the Influences of Cells Characteristics in Battery Bank. In Proceedings of the 22nd International Symposium on Electrical Apparatus and Technologies (SIELA), Bourgas, Bulgaria, 1–4 June 2022; pp. 1–5. [Google Scholar]
- Tashev, T.D.; Marinov, M.B.; Arnaudov, D.D.; Monov, V.V. Computer simulations for determining of the upper bound of throughput of LPF-algorithm for crossbar switch. In Proceedings of the 47th International Conference “Applications of Mathematics in Engineering and Economics”, Sofia, Bulgaria, 7–13 June 2021; Volume 2505, p. 080030. [Google Scholar]
- Amaudov, D. Influence of asymmetry in multiphase resonant converters for energy storage systems. In Proceedings of the XXVI International Scientific Conference Electronics (ET), Sozopol, Bulgaria, 13–15 September 2017; pp. 1–4. [Google Scholar]
- Sapundzhi, F.; Chikalov, A.; Georgiev, S.; Georgiev, I. Predictive Modeling of Photovoltaic Energy Yield Using an ARIMA Approach. Appl. Sci. 2024, 14, 11192. [Google Scholar] [CrossRef]
- Sapundzhi, F.I.; Popstoilov, M.S. Maximum-Flow Problem in Networking. Bulg. Chem. Commun. 2020, 52, 192–196. [Google Scholar]
- Kravets, O.J.; Aksenov, I.A.; Redkin, Y.V.; Rahman, P.A.; Kochegarov, M.V.; Gorshkov, A.V.; Sorokin, S.A. Modeling of neural network monitoring agent to predict traffic spikes and agent training. Int. J. Inf. Technol. Secur. 2024, 16, 49–56. [Google Scholar] [CrossRef]
- Zelmanov, S.S.; Krylov, V.V. Computer simulation of strength testing of an object based on signal shaped resources. Int. J. Inf. Technol. Secur. 2023, 15, 59–68. [Google Scholar] [CrossRef]
- Ivanova, Y. Simulation modelling of artificial neural networks for the purpose of steganalysis. Int. J. Inf. Technol. Secur. 2022, 14, 99–110. [Google Scholar]
- Ganev, B.; Marinov, M.B.; Kralov, I.; Ivanov, A. Modeling and Validation of a Spring-Coupled Two-Pendulum System Under Large Free Nonlinear Oscillations. Machines 2025, 13, 660. [Google Scholar] [CrossRef]
- Hensel, S.; Marinov, M.B.; Koch, M.; Arnaudov, D. Evaluation of Deep Learning-Based Neural Network Methods for Cloud Detection and Segmentation. Energies 2021, 14, 6156. [Google Scholar] [CrossRef]
- Tashev, T.D.; Alexandrov, A.K.; Arnaudov, D.D.; Tasheva, R.P. Large-Scale Computer Simulation of the Performance of the Generalized Nets Model of the LPF-algorithm. In Large-Scale Scientific Computing; Lirkov, I., Margenov, S., Eds.; LSSC 2021; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2022; Volume 13127. [Google Scholar] [CrossRef]
- Getting Started with GNS3. Available online: https://docs.gns3.com/docs/ (accessed on 30 December 2025).
- Wireshark User’s Guide. Available online: https://www.wireshark.org/docs/wsug_html_chunked/ (accessed on 30 December 2025).
- hping3 Tool Documentation. Available online: https://www.kali.org/tools/hping3/ (accessed on 30 December 2025).
- Nmap Reference Guide. Available online: https://nmap.org/book/man.html (accessed on 30 December 2025).
- Colasoft Capsa Free. Available online: https://www.colasoft.com/capsa-free/ (accessed on 30 December 2025).
- VitalPBX Features. Available online: https://vitalpbx.com/pbx-features/ (accessed on 30 December 2025).
- Script Http-Slowloris-Check, Script Summary. Available online: https://nmap.org/nsedoc/scripts/http-slowloris-check.html (accessed on 30 December 2025).
- Script Http-Slowloris, Script Summary. Available online: https://nmap.org/nsedoc/scripts/http-slowloris.html (accessed on 30 December 2025).
- Script Ssl-Enum-Ciphers, Script Summary. Available online: https://nmap.org/nsedoc/scripts/ssl-enum-ciphers.html (accessed on 30 December 2025).
- Script Vulners, Script Summary. Available online: https://nmap.org/nsedoc/scripts/vulners.html (accessed on 30 December 2025).
- Tim, S.; Christina, H. End-to-End QoS Network Design: Quality of Service in LANs, WANs, and VPNs. In Part of the Networking Technology Series; Cisco Press: Indianapolis, IN, USA, 2004; ISBN 1-58705-176-1. [Google Scholar]
- Cisco-Understanding Delay in Packet Voice Networks, White Paper. Available online: https://www.cisco.com/c/en/us/support/docs/voice/voice-quality/5125-delay-details.html (accessed on 30 December 2025).
- Issabela PBX. Available online: https://www.issabel.com/en/issabel-in-detail/ (accessed on 30 December 2025).
- Dimitrov, W.; Jekov, B.; Hristov, P. Analysis of the Cybersecurity Weaknesses of DLT Ecosystem. In Software Engineering and Algorithms; Silhavy, R., Ed.; CSOC 2021; Lecture Notes in Networks and Systems; Springer: Cham, Switzerland, 2021; Volume 230. [Google Scholar]
- Dimitrov, W.; Syarova, S. Analysis of the Functionalities of a Shared ICS Security Operations Center. In Proceedings of the 2019 Big Data, Knowledge and Control Systems Engineering (BdKCSE), Sofia, Bulgaria, 21–22 November 2019; pp. 1–6. [Google Scholar]
- Dimitrov, W.; Dimitrov, G.; Spassov, K.; Petkova, L. Vulnerabilities Space and the Superiority of Hackers. In Proceedings of the 2021 International Conference Automatics and Informatics (ICAI), Varna, Bulgaria, 30 September–2 October 2021; pp. 433–436. [Google Scholar]
- Roubi, A.; Amin, M.M. Real-time traffic-based detection of XSS vulnerabilities via bidirectional HTTP traffic analysis. Int. J. Inf. Technol. Secur. 2025, 17, 69–78. [Google Scholar] [CrossRef]
- Rakesh, V.S.; Vasanthakumar, G.U. Evaluation of supervised classification approach for DDoS threat detection in Software Defined Networks. Int. J. Inf. Technol. Secur. 2024, 16, 95–103. [Google Scholar] [CrossRef]
- Ivanova, Y. Integrating a DNS monitoring module into a cybersecurity architecture to enhance protection against spoofing and phishing attacks. Int. J. Inf. Technol. Secur. 2025, 17, 111–122. [Google Scholar] [CrossRef]
- Deshpande, S.N.; Gore, D.V.; Chavan, A.S.; Nelli, A. MOD-XGBOOST: An adaptive machine learning model for internet of things environment to detect spoofing and dos attacks. Int. J. Inf. Technol. Secur. 2025, 17, 79–90. [Google Scholar]
- Stoykova, A. Security policy in digital transformation and dynamics of economic digitalization in EU countries. Int. J. Inf. Technol. Secur. 2025, 17, 117–128. [Google Scholar] [CrossRef]
- Alshammari, A.S. DNA-based cryptosystem integrating Wichmann-Hill and mixed congruence algorithms for enhanced data security. Int. J. Inf. Technol. Secur. 2025, 17, 69–78. [Google Scholar] [CrossRef]
- Chain, K. The security analysis on the rabbit stream cipher. Int. J. Inf. Technol. Secur. 2024, 16, 91–102. [Google Scholar] [CrossRef]

























































Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Nedyalkov, I. Methodology for Studying the Level of Network Security of an IP PBX Server. Telecom 2026, 7, 22. https://doi.org/10.3390/telecom7010022
Nedyalkov I. Methodology for Studying the Level of Network Security of an IP PBX Server. Telecom. 2026; 7(1):22. https://doi.org/10.3390/telecom7010022
Chicago/Turabian StyleNedyalkov, Ivan. 2026. "Methodology for Studying the Level of Network Security of an IP PBX Server" Telecom 7, no. 1: 22. https://doi.org/10.3390/telecom7010022
APA StyleNedyalkov, I. (2026). Methodology for Studying the Level of Network Security of an IP PBX Server. Telecom, 7(1), 22. https://doi.org/10.3390/telecom7010022

