SIP Protect
Advanced protection for SIP systems
Bluehub SIP Protect defends your VoIP PBX against brute-force, DoS and SIP scanner attacks – automatically. Real-time detection, smart IP blocking and custom access controls keep your service running and your bills predictable. Built into every Bluehubcloud PBX, with geo-blocking, allow and deny lists, email alerts and a live attack log.
Included with Bluehubcloud PBX – no extra charge.
Real-time monitoring
Live SIP traffic, not logs
Auto IP blocking
Temporary, then permanent
Allow & blocklists
Plus country-level rules
Why it matters
Protect your VoIP network from costly attacks
SIP attacks can disrupt service, degrade call quality, and lead to significant financial loss through toll fraud. Bluehub SIP Protect is built into the Bluehubcloud PBX platform to defend against these threats – without slowing your team down.
- Stop toll fraud before it bills
- Maintain crystal-clear call quality
- Keep service available 24/7
- Preserve customer confidence
- Block whole countries you never trade with
- Get an email for every attack, or a daily summary
Real-time threat detection & response
SIP Protect monitors live SIP traffic, updates firewall rules automatically and blocks suspicious IP addresses before they can cause harm – blocking known SIP scanners by their user agent, rate-limiting INVITE floods, protecting TFTP auto-provisioning and shutting out whole countries when you choose.
- Stop toll fraud before it bills
- Maintain crystal-clear call quality
- Keep service available 24/7
- Preserve customer confidence
- Block whole countries you never trade with
- Get an email for every attack, or a daily summary
Capabilities
Everything you need to lock down SIP
Layered defences that detect, block and learn – so attackers don’t get a second chance.
Continuous SIP Traffic Monitoring
Keeps a close watch on all SIP activity to spot unusual patterns before they cause trouble. It works on live SIP traffic, so an attack is stopped as it happens rather than found in a log afterwards.
Register & Invite Protection
Blocks attempts to gain unauthorised access to your system and keeps your network secure. Too many failed registrations in a minute – ten by default – blocks the address, and INVITE floods are rate-limited the same way.
Smart IP Blocking
Automatically blocks attacking IPs and removes the block once the threat has stopped. Blocks lift on their own after the block time you set, so a mistyped password never locks a site out for good.
Custom Access Controls
Create your own allowlist and blocklist settings to match your security needs. The allowlist always wins, so your own sites and SIP trunks are never caught; lists import and export as CSV.
Automatic Permanent Blocking
Permanently bans IPs that show repeated malicious behaviour to stop future attacks. Three temporary blocks by default and the address goes on the denylist for good – for registration and INVITE attacks alike.
TFTP Brute-Force Defence
Stops attackers from redirecting auto-provisioning requests or altering configuration. Rate-limited, so your phones still provision while floods are dropped.
Threats blocked
The attacks SIP Protect stops
From opportunistic scanners to targeted fraud, SIP Protect covers the threat landscape facing modern VoIP systems.
Brute-force registration
Repeated login attempts to crack SIP credentials. Blocked after ten failures in a minute.
Denial of Service (DoS)
Floods of traffic that disrupt service and call quality. INVITE rate limits drop the flood.
SIP scanners
Automated probes hunting for exposed SIP endpoints. Known scanner user agents are blocked on sight.
OPTIONS probing
Reconnaissance requests mapping your system before an attack.
High-risk countries
Traffic from places you never trade with, blocked by country.
Auto-provisioning attacks
Hijacking TFTP setup requests to alter device configs.
Stronger defence against auto-provisioning attacks
Auto-provisioning can expose SIP systems to unwanted access if left unprotected. Bluehub SIP Protect adds an extra layer of safety with TFTP brute-force detection that stops attackers from redirecting setup requests or changing configuration details.
Full feature list
Every SIP Protect capability, in detail
Expand each category to explore what is included.
Detection and blocking
- Live traffic monitoring
- Watches the SIP traffic itself on the ports you nominate, over UDP, TCP or both, so attacks are caught as they happen.
- Registration rule
- A maximum number of failed registration attempts per minute – ten by default – before the address is blocked.
- Dynamic block time
- How long a blocked address stays blocked; the block lifts on its own afterwards.
- Permanent blocking
- After a set number of temporary blocks – three by default – the address goes on the denylist for good. Applies to registration attacks and, if enabled, INVITE attacks.
- INVITE rate limiting
- Caps the calls a single address can start per minute, with an allowed initial burst, so INVITE floods are dropped before they reach your PBX.
- Scanner blocking
- A list of known SIP scanner user agents blocked the moment they appear.
Access control
- Allowlist
- Addresses and networks with uninterrupted access. It always takes precedence over every other list, so your sites, trunks and providers are never locked out.
- Denylist
- Addresses and networks refused outright, plus everything permanent blocking adds.
- CSV import and export
- Move whole lists between systems or keep them in a spreadsheet; each entry carries a note, who added it and its country.
- Notes and audit
- Every list entry records why it was added and by whom.
Geo protection
- Deny by country
- Block every address range belonging to the countries you pick.
- Allow by country
- Or flip it: permit only the countries you choose and refuse the rest – with exceptions for the outside services your PBX needs, such as email.
- Country data
- Blocked and allowed entries show their country of origin, so patterns are easy to spot.
Visibility and alerts
- Dashboard
- Service health, attacks per endpoint, most-blocked countries and a heatmap, all filtered by date range and refreshed on a timer.
- Attack log
- Attacker IP, target, attack type, user agent and time for every event; search and filter by type, with explicitly blocked scanners shown in bold.
- Email alerts
- A daily attack summary, a notification for every attack (rate-limited to once an hour by default), or both, to the recipients you list.
Provisioning and platform
- TFTP protection
- Rate-limits auto-provisioning requests – ten a minute with a burst of a hundred by default – so brute-force attempts to hijack phone configuration are dropped while real phones still provision.
- Built in
- Part of the Bluehubcloud PBX platform – no appliance, no separate console; it is configured from the PBX admin portal.
- Managed for you
- Bluehub sets the rules; ask us to add your sites and providers to the allowlist or to block or allow specific countries.
Visibility
See every attack, and what stopped it
Everything SIP Protect blocks is on the record – in your PBX admin portal, and in your inbox if you want it.
Security dashboard
Attacks per endpoint, the most-blocked countries and a heatmap of where attacks come from – filtered by date, refreshed on a timer.
Attack log
Every blocked event with attacker IP, target, attack type, user agent and time – searchable, filterable, with blocked scanners flagged.
Real-time alerting
See threats as they happen. Tune policies and respond fast from a single console. Choose an email for every attack, a daily attack summary, or both.
Built into Bluehubcloud PBX
SIP Protect ships as part of the Bluehubcloud PBX platform – no extra appliances to deploy, no separate console to learn. Turn it on and let it work.
FAQ
SIP Protect questions answered
What is SIP Protect?
The attack protection built into Bluehubcloud PBX. It watches live SIP traffic, blocks addresses that fail registration too often or flood the system with calls, refuses known scanners and the countries you choose, and records every event – all without any extra hardware.
What does it protect against?
Brute-force registration attempts, INVITE floods and other denial-of-service traffic, SIP scanners probing for open systems, OPTIONS reconnaissance, traffic from countries you block, and brute-force attempts on TFTP auto-provisioning.
Does it cost extra?
No. SIP Protect is part of the Bluehubcloud PBX platform.
How quickly does it block an attack?
Immediately. It works on the live SIP traffic, not on a log read afterwards – once an address crosses the rule (ten failed registrations in a minute by default) the firewall is updated and the address is blocked.
Will it block our own phones or sites?
Not if they are on the allowlist, which always wins over every other rule. If a handset with a stale password is deleted without a factory reset it can trip the registration rule; we get an email when that happens, and the block lifts on its own after the block time – or ask us to allowlist the site.
Can we block whole countries?
Yes. Deny the countries you pick, or allow only the countries you choose and refuse everything else.
Can we see what has been blocked?
Yes – a dashboard of attacks by endpoint and country, and a searchable log with attacker IP, target, attack type, user agent and time. You can also have an email for every attack or a daily summary.
Who manages the rules?
We do, as part of your Bluehubcloud PBX. Tell us the sites, trunks and countries that matter and we set the allowlist, denylist and geo rules for you.
Protect your business with Bluehub SIP Protect
Keep your Bluehubcloud PBX safe from advanced attacks. Protect your system, avoid financial loss and keep customer confidence intact.