SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Tools and Languages

VoIP security relies on interoperability

VoIP security relies on interoperability

By:  Nancy Gohring  On: 08 Jun 2006 For: IT World Canada Creator

Lack of equipment interoperability and confusion over security responsibility are to blame for the lack of security in voice over IP (VoIP), an issue that IT administrators say is a major concern for them, experts speaking at last month’s VON Europe conference said.

Lack of equipment interoperability and confusion over security responsibility are to blame for the lack of security in voice over IP (VoIP), an issue that IT administrators say is a major concern for them, experts speaking at last month’s VON Europe conference said.

The technology and standards that exist to secure VoIP are not the issue, said Tim Jasionowski, senior technologist for voice and rich media technologies at Nokia Corp. The problem is that most enterprises aren’t using many of the technologies.

That’s mainly because unless an enterprise uses a single vendor for every piece of equipment in their network, including phones, IP-PBX, firewall and all other components in between, then security technologies such as transport layer security (TLS) are unlikely to interoperate across multivendor equipment, he said. Even if an enterprise decided to standardize on a single vendor, it might have additional limits on the products it chooses.

That’s because not all major vendors are building support for security standards like TLS into their products and those that do don’t necessarily support it across their entire product range, said Cullen Jennings, distinguished engineer at Cisco Systems Inc.

Once enterprises decide to extend VoIP into mobile devices, they face additional problems, and once again, not because the standards and technology don’t exist. Ideally, an enterprise might want to run Wi-Fi protected access (WPA) to secure the Wi-Fi connection on a wireless device, an authentication mechanism for users that may attach to public hotspots, a virtual private network (VPN) for accessing the corporate network and possibly other security techniques.

Running all of those security applications requires processing and power — both features in short supply on mobile devices.

In addition, the market hasn’t fully worked out who exactly is responsible for security and for enforcing that security, said Ari Takanen, chief technology officer for Codenomicon Ltd. Currently, layers of security are offered by service providers and equipment makers and sometimes their efforts overlap. Without the clarity of claimed responsibility, no source is liable for security issues, he said.

Enterprises can improve their chances of boosting the security on their VoIP networks in a couple of ways, including carefully examining the type of tests that vendors say they run on their products to make sure they work, Takanen said.

Organizations like the Protos Project, a collaboration between the Finnish University of Oulu and VTT Electronics, can help buyers test products, he said.

In addition, firms are responsible for demanding that vendors interoperate, Jasionowski said. In the meantime, product managers are making decisions against interoperability and against the advice of their engineering staff in hopes of securing more business, he said.

QuickLink 064618


Sign up for our Newsletters
Tags: vendor












Print |  Views: 712   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Nancy Gohring Nancy Gohring Nancy Gohring is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in mo... more

Related Content

VoIP Security: The Basics
VoIP Security: The BasicsA provider of IP-voice solutions details six threats and how they can be faced. He also advises that enterprises should evaluate their business goals closely when considering new solutions
Getting to know you: The rise of roles-based IDs
Getting to know you: The rise of roles-based IDsRegulatory and compliance requirements are the big driver behind demand for technology that governs access to information based on user rights and restrictions. Let Telus, M-Tech and other Canadian firms bring you up to speed
Businesses increasing focus on the enemy within, says Cisco exec
Businesses increasing focus on the enemy within, says Cisco exec Large organizations are increasingly looking inwards to secure enterprise applications as threats from external virus attacks diminish, according to a top executive of a data centre technology provider.
Wireless LAN security vs. convenience - walking the tightrope
by joaquim p. menezes - “security vs. ease of use” – is a conundrum a lot of network managers face when it comes to wir

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.