NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Policy
Slice by Program

Six quizzical VoIP issues

By: Phil Hochmuth, Network World (U.S.)(07-04-2007)

Previous pages: Can I trust Microsoft with VoIP?

Reliability: Microsoft and the fifth 9

What really happens when I dial 911?

3. Is VoIP safe?

VoIP security is a broad question that touches on many aspects of how IP telephony systems operate, and the various parts of the network that VoIP touches. But according to one survey, one thing is clear: VoIP technology isn't safe enough for many businesses.

Only half of the IT executives polled recently in a CompTIA study said they think security technology built into corporate VoIP products and services is solid. The survey (of 350 companies with 500 employees or fewer) showed that even wireless technology - often maligned for its security weakness - was held in higher regard than VoIP in terms of security.

With VoIP, security concerns among the respondents in the CompTIA survey were not relating to potential attacks on only VoIP gear and software, but the affect a general worm or virus outbreakk could have on the quality of IP voice calls.

Worms and viruses that flood corporate networks with traffic may cause e-mail delivery to be delayed, with other slow application response times. But the latency introduced can simply kill an IP telephony conversation.

As for VoIP products, vulnerabilities are popping up more in IP telephony gear and software. Cisco, for instance, over the last 18 months issued nine major vulnerability advisories on products ranging from IP phones and IP PBXs to routers that perform VoIP processes and functions. These nine warnings - serious enough for the vendor to issue software patches - compare to only two VoIP-related vulnerabilities Cisco had issued in the previous 18 months.

Many vendors' IP call processing and messaging products run on top of Linux, Windows, Sun or other server operating systems. Softphones generally run on Windows desktops, while applications such as VoIP-based call centre platforms can touch a wide array of other applications.

Taking all this into account, Avaya had 25 product security advisories relating either directly to its VoIP products, or affecting underlying software products on which Avaya's technology runs, according to research by Secunia.

The Internet Security Systems X-Force vulnerability database has more than 100 entries over the past five years relating to vulnerability reports in VoIP products, applications and underlying protocols.

Some security researchers say the basic technology of some VoIP protocols is by nature hackable or susceptible to denial-of-service or call-interception attacks.

Sheran Gunasekera, a researcher with Scanit, wrote in a report that VoIP call interception can be simple, if targeted against equipment and traffic using non-encrypted, standards-based protocols. Against SIP-based VoIP conversations, "signalling attacks can be used to eavesdrop on conversations and re-route or hijack calls," says Gunasekera.

Other new VoIP threats on the horizon include the emergence of maliciously designed VoIP audio codecs. Theoretically, these so-called "evil codecs" are a VoIP audio stream designed specifically to crash a VoIP endpoint or server.

Lawrence Orans, a researcher with Gartner, says eavesdropping is one example of an overhyped threat. "Sure, it's technically possible to execute a man-in-the-middle attack and capture packets. The reason that we hear so much about eavesdropping is that it really does illicit this visceral reaction. The main thing is to focus on the greater threats, for example attacking an IP PBX server itself."

But it is possible to have a secure VoIP deployment if you follow best practices, saysB David Endler, chairman and founder of the VoIP Security Alliance. "All of these systems are securable, but they do take some knowledge to get them to that point."

Using encryption on VoIP signaling (SIP and H.323) and payload streams (RTP and UDP, typically) are some approaches. Ensuring IP PBX servers are patched and configured properly, and restricting the types of traffic that can contact IP endpoints are other measures.

Continued: Do I need a $1,000 IP phone?

Skip to: Will SIP ever be ready for the desktop?

How do I run my business on Skype?

Related content:

Abolishing service blues

Modern architectures show designs on citizens

Better service worth the cost, Mississauga says

Industry Canada trials intrusion prevention for VoIP

VoIP performance: more than a bandwidth issue

Putting a PAL to work

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada