Monday November 24, 2008 5:33 AM AEST
Latest Comments
"xcbvxc"
by sarfsda | Nov 24, 2008 4:41 AM
 
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM

VoIP security for everyone

  • Email a Friend
  • Print Page
VoIP security for everyone
VoIP can also help companies economise through managing only one converged data network instead of separate voice and data lines and it can also bring multimedia services to the desktop, in some cases improving customer service.

However, VoIP technology can also expose companies’ voice systems to all of the hazards that now plague data networks such as worms, viruses, spam over Internet telephony (SPIT), eavesdropping and fraud.

It is therefore very important that organisations understand the security risks before they start implementation and by planning and deploying a secure architecture, the majority of the risks inherent in any VoIP solution can be eliminated.

It is a common misconception that data firewalls will protect a VoIP system. They won’t. Voice encryption, authentication, VoIP-specific firewalls and the separation of voice and data traffic all need to be considered. Traditional private branch exchange (PBX) phone systems have their own vulnerabilities, and in the past hackers have broken into large phone and voice mail networks. But VoIP expands vulnerability, offering more opportunities for hackers to gain access.

Security risks that VoIP systems can bring can be classified into three types: Service availability, Confidentiality, System integrity.

Firstly, service availability can be restricted because voice systems are network enabled and usually provide remote management and access tools, providing intruders and attackers with a host of access points and denial of service mechanisms.

Similarly, in a VoIP environment, a ‘packet capturer’ or ‘protocol analyser’ connected to a shared network could allow the interception and recording of voice traffic so confidentiality is compromised.

Lastly, integrity threats cover anything in which system functions or data may be modified. Once an attacker has compromised the system configuration they can modify, delete or disclose information.

Article by Mario Vecchio, ANZ Siemens Enterprise Networks, General Manager, ANZ

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Messaging Whitepapers