SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Voice, Data, and IP >> Protocols and Standards

VoIP vulnerabilities

VoIP vulnerabilities

By:  Leon Erlanger  On: 02 Mar 2006 For: Network World Canada Creator

Is enterprise VoIP (voice over IP) due for a security wakeup call or are the threats mostly exaggerated? It depends on who’s talking.

Is enterprise VoIP (voice over IP) due for a security wakeup call or are the threats mostly exaggerated? It depends on who’s talking.

“The security aspects of enterprise VoIP have been overblown,” says Irwin Lazar, senior analyst at the Burton Group. “There’s a lot more attention being paid to the fear of attack than what is actually possible.”

Roger Farnsworth, manager of marketing for Secure IP Communications at Cisco, concurs: “VoIP systems can be at least as secure as traditional voice systems, and future IP technologies and voice applications will make them even more secure.”

But Mark Collier, CEO of SecureLogix, a vendor of voice management and security platforms for both traditional phone systems and VoIP, isn’t completely sold. “With IP at its foundation, it’s simply unrealistic to expect VoIP to be any more robust than e-mail, the Web, or DNS,” he says.

Hold the phone. E-mail? The Web? DNS? Who in their right mind would move from the rock-solid service of legacy enterprise telephony to a platform that’s no more secure than e-mail?

Just another app

In fact, enterprise VoIP is essentially just another application on the IP network. The principal elements of today’s typical enterprise IP telephony systems are call control servers, which usually run on an operating system such as Linux, Windows, or VxWorks; VoIP clients, which are either handsets or softphones; and VoIP gateways, which sit at the edge of the network and translate between VoIP and the PSTN.

They all use some relatively standard protocols — typically either the International Telecommunication Union’s H.323 series of protocols or the IETF’s SIP for the servers and clients and the MGCP (Media Gateway Control Protocol) or Megaco/H.248 protocols for gateways. And the vast majority share the data network, depend on the same routers and switches for voice packet transport, and, ideally, interface with other data applications, including messaging.

So, theoretically at least, VoIP systems are as vulnerable to attack as other data applications. The list of potential threats includes DoS attacks, viruses, worms, Trojans, packet sniffing, spam and phishing. Spam? If you remember the dark days before do-not-call lists, imagine the potential of SPIT (spam over Internet telephony).

“If I want to send 100 calls, I have to dial 100 times or use an autodialer,” says Andrew Graydon, vice-president of technology at BorderWare Technolgies. “But with an IP connection, I could upload a WAV file to a computer in the Bahamas, press a button, and send it to 2,000 employees instantly.” Phishing is accomplished simply by spoofing caller ID information to masquerade as a representative of a legitimate institution.

Nonetheless, vendors and analysts emphasize that IP PBXs run on a variety of operating systems, usually stripped down and hardened, and use a mix of still-evolving standards and more proprietary protocols, such as Cisco’s Skinny call control protocol, making VoIP apps more difficult to target than typical data applications.


Sign up for our Newsletters












Print |  Views: 654   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Leon Erlanger Leon Erlanger is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

6 things to consider when installing IP telephony
6 things to consider when installing IP telephonyA speaker at IT360 gave some tips on security, quality of service, power over Ethernet, staffing, data networks and redundancy. Find out what analyst Matthias Machowinski has to say and how the Phybridge Uniphyer works
1.3 million DNS servers still vulnerable to cache-poisoning
1.3 million DNS servers still vulnerable to cache-poisoning At least one in 10 servers is still susceptible to domain name systems attack despite fixes being made available more than four months ago
Six quizzical VoIP issues
Six quizzical VoIP issuesCanadian governments and other public sector agencies have identified VoIP as one of the most useful technologies to help them meet the high expectation for citizen service. VoIP may be hot, but all that heat can raise some issues. We resolve to answer some of the more pressing questions you might be facing.
Voice Mobility announces new migration tool for Avaya servers
vancouver-based unified communication solutions company voice mobility released a new migration tool today called virtual silver suitcase (vss). designed sp

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.