目前基于实时流协议RTSP(Real Time Streaming Protocol)的流媒体应用日益受到重视,在Internet上传输流媒体的相关技术已成为热点,但是围绕RTSP的研究主要集中在其应用上,对其安全性的研究没有引起人们的重视。随着RTSP的迅速发展,其安全性问题将成为其继续发展的瓶颈。具体分析针对RTSP协议存在的诸如恶意监听、修改、结束流媒体会话攻击以及服务器伪装攻击等安全性问题,提出了RTSP双向认证模型。该模型可以有效抵御多种针对RTSP的攻击。
Currently, the technology of transmitting streaming media over internet has become a hot research topic along with the growing attention on the application of RTSP based streaming media. However the studies with regard to the RTSP are mainly focused on its applica- tions, its security issues have not attracted enough attentions. With the rapid development of RTSP, the security issues will become a bottleneck to its further development. In this paper, detailed analysis has been made on the attacks against RTSP, such as malicious eavesdropping/modify/end streaming media session and server masking attack, etc. A mutual digest authentication model is proposed to effectively resist the attacks azainst RTSP.