Build your professional network on facebook via our app Go to app
 
<< Prev  12 of 15 in Topic  Next >>
Topic : VoIP network integration
  Rate : 
Posted in Community :

Internet Telephony

Industry : Internet Functional Area : New Technologies
Activity:  1 comments  325 views  last activity : 07 06 2010 20:18:04 +0000
 Refer 10
Share
 
 
 


Unencrypted VoIP poses security threat
Posted by Stephen Pritchard at 12:49PM, Wednesday 28th March 2007

Technology firms argue that rush to embrace IP telephony is taking place without due care and security considerations.

Businesses are switching to Internet telephony without thinking about security, a leading voice over IP (VoIP) manufacturer has warned.

Snom, the German-based provider of IP phones, argues that too few IT managers realise that the data packets that make up voice over IP calls are not encrypted.

"If you are simply making calls using IP over your LAN then there might not be a security issue," said Ahmar Ghaftar, senior software engineer at Snom. But calls over the public internet, including calls between an office VoIP connection and a VoIP service provider, remain vulnerable.

At CeBIT, Snom unveiled a range of VoIP handsets based around the SIP (Session Initiation Protocol) standard and using the SRTP system for encryption. SRTP is based around the AES encryption model so, Ghaftar says, it imposes relatively little in the way of a processing overhead on the phone itself.

Other VoIP vendors, including Cisco and Avaya, as well as a growing number of voice over IP services providers, support SRTP. However, the protocol has yet to receive official approval from the Internet Engineering Task Force (IETF). Some manufacturers are backing alternative standards, such as Mikey.

"We expect SRTP to be a standard, and most service providers, as well as a growing number of firewall manufacturers, support it," Ghaftar explained. As yet, however, few companies selling wireless VoIP handsets or VoIP-ready mobiles have implemented SRTP.

In the meantime, however, security experts strongly recommend that companies look at the security measures they have in place for their VoIP systems.

"The thing that surprises me is that the primary focus of VoIP has been around quality of service, with security playing second fiddle," cautioned Greg Day, security analyst for EMEA at McAfee. "People are not taking security as seriously as they could. They are mostly worried about making the quality of VoIP as good as it is on their analogue phones. If you mention security, their first reaction is to worry about reduced performance."

According to Day, consumer-focused Internet telephony technologies such as Skype actually have a greater level of security, including encryption and port randomisation, than some professional solutions.

McAfee recommends that companies implementing VoIP need to consider three issues: the possible impact of an attack on the company's network on both voice and data traffic; potential vulnerabilities in VoIP software, or equipment such as switches and routers, and finally the possibility of electronic eavesdropping on the calls themselves.

"The fact that we have converging services - where telephony is overlaid on data services and they are sharing bandwidth - means that if there is a data attack it could damage the IP infrastructure enough to stop both voice and data services running," Day warned.

 
TrackBack URL:
1 comments on "Unencrypted VoIP poses security threat"
  Commented by  Dipak Mawale, Senior Executive, Harbinger Knowledge Products    | 06 11 2008 12:23:55 +0000
Thanks..good article :)
Add your comment on "Unencrypted VoIP poses security threat"

Rate:
Submit
Leading Recruitment Firm
  • Create a confidential Career Profile and Resume/C.V. online
  • Get advice for planning their career and for marketing of experience and skills
  • Maximize awareness of and access to the best career opportunities
Viewers also viewed
If, as the old expression goes, imitation is the sincerest form of flattery then the top brass...
 
661 referals 11 votes, 1590 views
in my view the aviation security,particularly airport security,should be funded from from the...
 
28 referals 4 comments, 31 views
welcome ur views,,,
 
302 referals 9 arguments, 166 views
more...  
Recent Knowledge (71)
Hi All, Came across a nice artical, thought beneficial for all HR professionals : What else does...
 
30 referals 26 comments, 1802 views
  A day after he resigned, Santosh Sarode (31), a software engineer, allegedly strangled his...
1600 referals 32 comments, 1538 views
Let me share a few issues for TS members. Demarcation of the boundary was initially made with...
 
293 referals 3 comments, 33 views
more...  
More From Author
  Google's Gmail service was knocked offline Tuesday in an outage that the company said affected a 'majority' of its millions of e-mail users, including consumers who get Gmail for free and businesses that pay for a version for their employees....
I completely agree with what Mr. Gordon has said and there is no way that Bing is a competition for Google interms of search, the numbers increased in Bing is just because there was curiosity around the Microsoft and yahoo deal and this made people...
Hi, In this situation try to remind your customers that you want to solve the problem and it can be only done when the language is appropriate and demands are reasonable. Other way to handle this situation is by transferring the call, tell you...
more...