Business isn't securing VoIP

Businesses are not doing enough to secure their VoIP networks, according to a veteran IP telephony engineer, and the main reason is lack of knowledge.

Eric Vyncke, author of LAN switch security: What hackers know about your switches and a distinguished engineer at Cisco, told an audience of security experts on Wednesday that insecure networks could fall victim to hijackers and hackers.

"Nearly nobody is deploying secure IP telephony," Vyncke said, speaking at the RSA Conference Europe 2007 in London. "Why? It's a lack of information."

Vyncke added that, five years ago, a lot of businesses had become deeply worried about securing IP telephony and, as a result, most had chosen not to deploy the technology.

"A lot of customers freaked out," Vyncke said. "They were only receiving one message -- that IP telephony is insecure."

At that time, IP telephones could not be authenticated and there was no way to check the integrity of a device. But the technology has since improved, Vyncke said.

The engineer recommended the use of certificates for each phone, but said that the IT department must be able to revoke them if the handset is stolen or returned to the manufacturer.

Vyncke also highlighted potential problems with firewalls blocking encrypted IP telephony traffic. To help prevent that, it is advisable that the signalling and media streams are prevented from diverging, he said.

Vyncke added that two techniques have been developed which could help to solve the problem: the Stun protocol (Simple Traversal of User Datagram Protocol through Network Address Translators) and ICE (Interactive Connectivity Establishment -- a wider framework developed by standards body the Internet Engineering Task Force, or IETF).

IT professionals should bear in mind that some IP telephony deployments which run over multiple domains can run into difficulties, said Vyncke. In 10 percent of cases, the firewall cannot see the signalling, he added.

"There are issues with IP telephony," Vyncke said. "But you can secure it."

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured