**Network Security Performance Analysis of Mobile Voice Over Ip Application (mVoIP): Kakao Talk, WhatsApp, Telegram and Facebook Messenger**

**Nur Khairani Kamarudin<sup>1</sup>\*, Nur Syafiqa Bismi<sup>2</sup>, Nurul Hidayah Ahmad Zukri<sup>3</sup>, Mohd Faris Mohd Fuzi<sup>4</sup>, Rashidah Ramle<sup>5</sup>**

*Faculty of Computer and Mathematical Sciences, Universiti Teknologi MARA, Perlis Branch, Arau, Campus, 02600 Arau, Perlis, Malaysia*

*Corresponding author: \*nurkhairani@uitm.edu.my*

ABSTRACT

*VoIP application usage has increased from time to time and makes our daily life more convenient. VoIP application has features to make a phone call, send a text message and share the file through the apps for free. However, most of the users did not seem aware of VoIP security features such as authentication ability, password encryption ability, or voice or audio and text communication encryption ability. It is essential to ensure the VoIP used is secure from password decrypter and eavesdrops the user conversation. Thus, the first objective of this research was to study and investigate VoIP application consist of Kakao Talk, Telegram, Facebook Messenger and WhatsApp for both Android and web application. The second objective was to evaluate the four VoIP application identified based on authentication requirement, password encryption, voice or audio encryption communication, and text encryption communication. There were two mobile phones used. One acts as a client and a personal computer act as an attacker. Wireshark and packet capture were run in personal computer and mobile phone to monitoring and scanning the network traffic while both devices connected in the same WLAN. The experiment implements MITM, interception, and sniffing attacks. This research project has identified Facebook Messenger and WhatsApp web application do not provide secure password ability.*

***Keywords:** VoIP application, authentication, password, encryption*

**INTRODUCTION**

**Voice over internet protocol (VoIP) is a software that allows the user to send text and have a voice calls over the internet protocol (IP). Mobile VoIP applications (mVoIP) become popular among the user since this application provides voice and video communication that is free or very low-cost calls (Azfar, Choo, & Liu, 2014). VoIP application could be on any data network that uses IP, like internet, intranet and local area network (LAN). mVoIP applications have gained attention from mobile device users such as Android devices. The example of widely used mVoIP application is WhatsApp, Kakao talk, telegram and Facebook messenger.**

**Besides, there are a few things user need to see on the criteria for a secure mobile application. Such as the authentication level of mobile applications, network performance, and encrypted communication. This will become an issue on the security of mVoIP when there are various ways to intercept VoIP communication (Azfar, Choo, & Liu, 2014). For example, interception. It can take place at the client devices when the conversation is being initiated or during the established communication session. So, it is essential to analyze the intercepted communication to determine whether the communication is encrypted or not.**

**The aims for this research project are to study and investigate VoIP application consist of Kakao Talk, Telegram, Facebook Messenger and WhatsApp for both Android and web application. Next, to evaluate the four VoIP application identified based on authentication requirement, password encryption, voice or audio encryption communication, and text encryption communication: Kakao Talk, WhatsApp, telegram and Facebook messenger.**

**DESIGN AND DEVELOPMENT**

**This section discuss on the process involved in designing and developing the testbed architecture. As shown in Figure 1.0, two mobile phones were used which act as client A and client B. One personal computer was used as an attacker. Wireshark and packet capture were run in personal computer and mobile phone to monitoring and scanning the network traffic while both devices connected in the same WLAN. The VoIP applications identified were installed at both clients (Client A and Client B) and Wireshark was installed at the attacker laptop while network analyzer was installed at one of client phone.**

> ![](136-12-366-1-2-20200818_media/media/image1.png)
> 
> Figure 1.0 Testbed architecture

**EXPERIMENTATION**

**After a pilot study was conducted to make sure all the hardware and software installed as in the testbed is running properly, four experiments have been conducted using four different VoIP application identified (Kakao Talk, Facebook Messenger, Telegram and Whatsapp). For each experiment, the steps involved are described in detail in Table 1.0. The test criteria tested on experimentation phase are as below.**

**Table 1.0:** Experimentation

<table>
<thead>
<tr class="header">
<th><strong>EXPERIMENT</strong></th>
<th><strong>ITEM</strong></th>
<th><strong>DESCRIPTION</strong></th>
</tr>
</thead>
<tbody>
<tr class="odd">
<td>1</td>
<td>Kakao talk</td>
<td><p>Conducted one experiment at a time. For each test, the steps involved were:</p>
<ol type="1">
<li><p>Installed the VoIP application on both client devices and installed Wireshark on attacker laptop.</p></li>
<li><p>Started the experiment using one VoIP application installed at a time.</p></li>
<li><p>The client A, B and attacker has been connected to one access point and established the connection. The VoIP application has been evaluated on the following criteria:</p></li>
</ol>
<blockquote>
<p>● Authentication </p>
<p>● password encryption </p>
<p>● text communication encryption</p>
<p>● voice/audio communication encryption</p>
</blockquote>
<ol start="4" type="1">
<li><p>Repeat steps 2 to 3 using other VoIP application identified during the information-gathering phase. Client A established a connection with client B. The attacker will run Wireshark for website application and Packet Capture for android application.</p></li>
<li><p>Repeat the testing of VoIP application with the test criteria.</p></li>
</ol></td>
</tr>
<tr class="even">
<td>2</td>
<td>Facebook messenger</td>
<td></td>
</tr>
<tr class="odd">
<td>3</td>
<td>Telegram</td>
<td></td>
</tr>
<tr class="even">
<td>4</td>
<td>WhatsApp</td>
<td></td>
</tr>
</tbody>
</table>

**RESULT AND DISCUSSION**

**The analysis and discussion is based on the observation while running the experiment involving four VoIP application which is Kakao talk, telegram, WhatsApp and messenger. The VoIP applications were tested based on four criteria, which is authentication requirement, password encryption, voice or audio communication encryption and text communication encryption.**

***Experimental Result***

**This research project has identified some differences between all VoIP applications tested. It was observed that WhatsApp, telegram, Facebook messenger and Kakao talk have many things in common either a website or android application, which include authentication, password encryption, voice/audio communication encryption and text communication encryption, and all the data collected is summarized in Table 2.0.**

**  
****Table 2.0 Experimental Result**

<table>
<thead>
<tr class="header">
<th><strong>VoIP APPLICATION</strong></th>
<th><strong>NETWORK SECURITY PERFORMANCE</strong></th>
<th></th>
<th></th>
<th></th>
<th></th>
</tr>
</thead>
<tbody>
<tr class="odd">
<td></td>
<td><p><strong>Required authentication?</strong></p>
<p><strong>(yes/no)</strong></p></td>
<td><p><strong>Encrypted password?</strong></p>
<p><strong>(yes/no)</strong></p></td>
<td><p><strong>Encrypted voice/audio communication?</strong></p>
<p><strong>(yes/no)</strong></p></td>
<td><p><strong>Encrypted text communication?</strong></p>
<p><strong>(yes/no)</strong></p></td>
<td></td>
</tr>
<tr class="even">
<td><strong>Kakao Talk</strong></td>
<td><strong>Web</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
</tr>
<tr class="odd">
<td></td>
<td><strong>Android</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
</tr>
<tr class="even">
<td><strong>Telegram</strong></td>
<td><strong>Web</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
</tr>
<tr class="odd">
<td></td>
<td><strong>Android</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
</tr>
<tr class="even">
<td><strong>Facebook Messenger</strong></td>
<td><strong>Web</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
</tr>
<tr class="odd">
<td></td>
<td><strong>Android</strong></td>
<td><strong>Yes</strong></td>
<td><strong>No</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
</tr>
<tr class="even">
<td><strong>WhatsApp</strong></td>
<td><strong>Web</strong></td>
<td><strong>Yes</strong></td>
<td><strong>No</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
</tr>
<tr class="odd">
<td></td>
<td><strong>Android</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
<td><strong>Yes</strong></td>
</tr>
</tbody>
</table>

**Table 2.0 shows the captured session for Kakao Talk and Telegram in android and web version, provide encrypted password and encrypted or secure communication, no plain text password or message was visible from the captured session for Kakao Talk and Telegram conversation packets.**

**Facebook messenger for android version and WhatsApp web do not provide password encryption ability since the user password can be read easily. The captured session from Packet captured for Facebook Messenger was found a plain text password visible from the captured Facebook Messenger conversation packets (Figure 2.0). WhatsApp web was not offered password encryption to the user since but it used QR code utility for user to log in the applications. But, QR code can be manipulated by the attacker. By using QRL Jacker, the attacker can obtain the same sessions as the user when the user scans QR code from the WhatsApp website.**

![](136-12-366-1-2-20200818_media/media/image2.png)

**Figure 2.0 Password encryption ability result for Facebook Messenger**

***Discussion***

**This subtopic discusses in which situations that VoIP application tested are suitable to implement.**

**Authentication requirement**

**Authentication is a process to ensure a user’s identity. User needs to enter username and password before they can log in to their account. In this research project, authentication is to ensure only the right user can log in to the account.**

**Based on the experimental result, all four android application such as Kakao talk, telegram, Facebook messenger and WhatsApp has authentication ability which is to identify the right use of the account. Kakao talk and Facebook messenger provide email or phone number and password utility to authenticate the user.**

**Compared to WhatsApp and telegram provide phone number utility to authenticate the user by verifying the user phone number. It will send verification code to users’ telephone number via SMS. SMS is the best alternative and more secure compared to the password entered.**

**Next, website application which is Kakao talk, telegram and Facebook messenger, was tested using Wireshark. From the result, Kakao talk and Facebook messenger provide email or phone number and password utility to authenticate user same as an android application. Next, WhatsApp web provides QR code which only the owner of the account can open their session by scanning the QR code.**

**As a result, all four application for android and website was proven it had provided authentication ability since authentication is the first layer security for applications. Authentication can be verified by email, username, phone number, password and verification code.**

**Password encryption**

**Encryption is the conversion of plain text into ciphertext, which cannot easily understand by unauthorized people. In this research project, encryption ability was evaluated based on the password provided by each VoIP application tested. It is important to have an encryption connection to ensure the security of the confidential password. Thus, a strong password is needed to avoid the third party to guess the password, which can be harmful to the user.**

**Based on the experimental result, for Kakao talk and telegram applications, both applications have provided password-encryption ability because Kakao talk application required a combination of 8-23 upper** **or lower case letters, numbers and special characters to strengthen the password. These criteria were tested using Wireshark for website application and Packet Capture for android application. Next, telegram application does not provide password entered, but it required verification code sent via SMS to verify the user. Verification code for telegram applications much secure since only the owner of the account can get verification code via SMS.**

**However, Facebook messenger and WhatsApp do not provide password encryption ability since the user password can be read easily. Facebook Messenger applications were using the same password for Facebook account. The application password requirement required a minimum of six characters and need to mix of letters, numbers and punctuation marks in the same password. Facebook password is case sensitive, and it means if the caps lock is turned on, it will be considered as a different letter than lowercase. It shows that Facebook messenger has a strong password, but the password is failed to meet the requirement of criteria tested since the password can be read easily when the attacker run packet capture in the background. Furthermore, WhatsApp applications were using the same method as a telegram. Meanwhile, WhatsApp web were using QR code to enable user opened their account. From the findings, the WhatsApp web was not offered password encryption to the user since the QR code can be manipulated by the attacker. By using QRL Jacker, the attacker can obtain the same sessions as the user when the user scans QR code from the WhatsApp website.**

**Voice or audio communication encryption**

**Encryption is the conversion of plain text into ciphertext, which cannot easily understand by unauthorized people. In this research project, encryption ability was evaluated based on voice or audio communication for each VoIP application. It is important to have an encryption connection to ensure the security and integrity of data, especially while exchanging confidential data through voice or audio medium.**

**Voice or audio communication was tested using Wireshark for website application and Packet Capture for android application. As a result, all application has encrypted communication since the pcap file contains cipher data which cannot decrypt by using online decrypt tools.**

**Compared to WhatsApp web was tested using QRL Jacker and Wireshark. By using QRL Jacker user might lose their session to the attacker since the user session was opened from attacker devices. Meanwhile, Wireshark result for voice or audio communication was encrypted. WhatsApp application offer TLS protocol to encrypt their communication.**

**Text communication encryption**

**Encryption is the conversion of data into ciphertext, which cannot easily understand by unauthorized people. In this research project, encryption ability was evaluated based on text communication for each VoIP application. It is important to have an encryption connection to ensure the security and integrity of data transfer, especially while exchanging confidential data through text.**

**WhatsApp web was tested using QRL Jacker and Wireshark. By using QRL Jacker user might lose their session to the attacker since the user session was opened from attacker devices. So, all user conversation can be seen by the attacker.**

**In another way, text communication was tested using Wireshark for website application and Packet Capture for android application. Wireshark result for text communication was encrypted since the pcap file contains cipher data which cannot decrypt by using online decrypt tools. So, all text exchanged between client A and client B is encrypted, since all four application offer TLS protocol to encrypt their communication.**

**This research has identified from the experiment results that Messenger is failed to provide encrypted password to users in order to protect user privacy and WhatsApp web also failed to secure their QR code when user session can be hijacked by the attacker by creating fake website and placed fake QR code; which lead user session open at the attacker devices. However, Kakao talk and telegram has encrypted password and communication, which is more secure and relevant to users.**

**CONCLUSION AND RECOMMENDATION**

**From the data collected and observation on experiments, most of the VoIP applications tested have met the requirement in the criteria tested. But the Facebook messenger and WhatsApp web application failed to meet the requirement of the criteria. This is because there are many free software tools to intercept user communication, which available on the internet. As a result, this research has fulfilled the research objective to investigate various VoIP applications such as Kakao Talk, WhatsApp, Telegram and Facebook messenger and evaluate the network security performance of four popular VoIP applications based on authentication, password encryption, and encrypted communication. It can be concluded; this research project can be a guideline for another researcher for depth understanding for an unauthorized interception in VoIP applications. Future work includes decoding the captured unencrypted sessions and analyzing more VoIP applications.**

**References**

Azfar, A., Choo, K. K. R., & Liu, L. (2014). A study of ten popular Android mobile VoIP applications: Are the communications encrypted? *Proceedings of the Annual Hawaii International Conference on System Sciences*, 4858–4867. <https://doi.org/10.1109/HICSS.2014.596>

Babkin, S., & Epishkina, A. (2019). *Authenticatiоn Prоtоcоls Based оn Оne-Time Passwоrds*. 1794–1798.

Carvajal, L., Chen, L., Varol, C., & Rawat, D. (2016). Detecting unprotected SIP-based Voice over IP traffic. 4th International Symposium on Digital Forensics and Security, ISDFS 2016 - Proceeding, 44–48. <https://doi.org/10.1109/ISDFS.2016.7473515>

Chakraborty, T., Misra, I. S., & Prasad, R. (2019). VoIP Protocol Fundamentals. 25–47. <https://doi.org/10.1007/978-3-319-95594-0_2>

Rohini, S., & Bairagi, V. (2010). Lossless Medical Image Security. International Journal of Applied Engineering Research, 1(3), 536–541.

Supervision, B. (2012). How Strong Is Strong User Authentication ?5. Retrieved from <https://www.isaca.org/Journal/archives/2012/Volume-5/Pages/How-Strong-is-Strong-User-Authentication.aspx>

Telegram. (2014). *MTProto Mobile Protocol*. 1–6. Retrieved from https://core.telegram.org/mtproto

Trabelsi, Z. (2005). Switched network sniffers detection technique based on IP packet routing. Information Systems Security, 14(4), 51–60. <https://doi.org/10.1201/1086.1065898X/45528.14.4.20050901/90089.7>

WhatsApp. (2019). Frequently Asked Questions KAINOS + Frequently Asked Questions. (1099), 1–3. Retrieved from <https://faq.whatsapp.com/>

Wireshark. (2019). Learn Knowledge is Power Go Beyond With SharkFest Sponsors About Wireshark. 1–9. Retrieved from https://www.wireshark.org/index.html\#aboutWS
