The dos and don'ts of VoIP security

Although there is precious little evidence of VoIP security attacks, organisations cannot afford to be complacent. Make no mistake, VoIP is an attractive target for hackers and malware writers.

To demonstrate the potential danger that enterprises with unsecured VoIP systems face, the Voice over IP Security Association (Voipsa) has published a list of publicly available tools that target VoIP applications. There are signs hackers are now turning their attention to voice over IP and most security commentators believe the first major attacks will occur over the next six to 12 months.

This means all enterprises need to ensure their VoIP infrastructure is protected, although this needn't be an onerous undertaking.

The simple fact that VoIP now typically comes under the aegis of the IT department should in fact help security. Although running proprietary operating systems, PBXs were in fact open to a large range of security attacks. It was generally just a little harder to access and required specialised knowledge.

While VoIP has increased the number of people able to exploit a corporate phone system, the tools and expertise to protect the technology have also been improved.

VLANs
The first step for VoIP security is to follow data networking best practice. Ovum analyst Graham Titterington says: "Most security in VoIP is a question of good network security and housekeeping."

Enterprises should deploy the voice traffic on a separate virtual LAN, or VLAN, from the data traffic. This helps protect the voice service if there is a denial of service attack on the data network.

Chris Whitwood, network manager at University College Falmouth, which has deployed IP telephony, says: "Denial of service is a particular problem for VoIP as it can completely destroy your telephony service. To protect against this, enterprises need to use security such as intrusion prevention systems and have a well-segmented network using VLANs."

VLANs need to be properly architected to prevent packets jumping from one VLAN to the other. However, even if they are, hacking tools are available that can make packets do just that. Additional tools that will help networks in case of any attack are intrusion detection and prevention systems, which scan for rogue incoming packets, and straightforward antivirus software which can help prevent any known threats from disrupting the network.

Another best practice that needs to be extended to voice is changing the default passwords of all of the components of the system. Phones, for example, can become vulnerable if their passwords are not changed as they offer many points of entry for hackers. In addition, companies should remove all unnecessary applications from VoIP systems such as telnet and web servers. Many IP phones have web servers installed, so that configuration can be managed from a PC screen, however this leaves them exposed to the Internet.

Patching is another key security chore. Because VoIP is now just another application that runs on a commercial operating system, it needs to be patched regularly along with the rest of the IT estate. Ken Munro, managing director of penetration testing company SecureTest, says: "Enterprises need to make sure that all of the firmware of the VoIP system is up-to-date. They need to have a rigorous patching regime as new vulnerabilities are found in VoIP systems every few days."

Encryption
While there is some debate about the threat level that eavesdropping poses to VoIP, companies should consider using encryption to secure their VoIP calls. Encryption should definitely be used where there is any risk of eavesdropping such as wireless networks or remote users. Some security experts even suggest encryption is used throughout the network.

Dan York, director of IP technology at PBX manufacturer Mitel and director at Voipsa, says: "The best encryption for VoIP is secureRTP, which does not have much of a processing overhead. It is a lightweight encryption method and would be ideal in smaller businesses with fewer than 1,000 users." SecureRTP uses high-strength encryption and is used by a number of VoIP application vendors.

Remote users require an additional layer of security as they will need to traverse the firewall. One approach is to use an IPSec (Internet Protocol security) VPN but the processing overhead can impact on the quality of the voice service. Alternatively it's possible to use SSL technology to help tunnel through the firewall and access the VoIP system - an option that has much less impact on the call quality.

University College Falmouth's Whitwood says: "There are always concerns that conversations of remote workers could be intercepted. To prevent this we create a VPN tunnel between the user and the VoIP servers. For users to gain access to the telephony system they would need to use this VPN because it is not accessible from the outside world."

Finally, in order to make sure all the good work in securing the network does not go to waste, organisations need to enforce a user-security policy that encompasses voice over IP. This needs to spell out in clear terms what responsibilities users have - for example, in keeping their passwords secret - and what applications they can download.

Adhering to a clear security policy should help prevent users from falling victim to phishing scams and other social engineering that can bypass all of the security measures enterprises put in place.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

シャネル バッグ : http://www.bagssalejp.org/ Chanel trap,chanel shekels,gucci bags,direct purse,poor recent Louis Vuitton keep...

1 hour ago by bybrinkLync on Reservoir blogs: Fan fakes Tarantino diary

I guess but in both cases, dead body!

11 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

12 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

12 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

13 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

13 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

13 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

13 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

13 hours ago by Beta on Regional review highlights NBN, mobile

michael kors outlet http://www.michael-kors-discount.com/#5923

14 hours ago by michael kors bag on Best iPhone travel apps

Hey butterflyeffecs and lex, Sorry you're not fans of this piece. But you're dead right in that it is the thoughts and experience of a se...

14 hours ago by LHopewell on Android fragmentation steers Vic Health

teen cams
http://www.aloe-vera.cz handjob

14 hours ago by MyncWenry on Fusion-io ioDrive (80GB)

We have fashional replica bags designer .Replica luxury bags sale here are perfect compromise of quality and price. The replica handbags ...

14 hours ago by Machelle on Telecom NZ CEO Paul Reynolds to leave

It's not a question of whether anyone at HSU would know how to do this, but whether they would have connections with people who could. T...

14 hours ago by meski on CT, phone clone

Fred, I can tell you what the difference between FTTN and FTTH is. FTTH means we will be developing technology and services that we sell ...

14 hours ago by andye on NBN FUD: will Abbott ever learn?

You are 100% right – Abbott is a paragon of tenacity. Now if he could only try that hard to get Malcolm Turnbull's phone number, we co...

14 hours ago by braue on NBN FUD: will Abbott ever learn?

Very interesting to hear Ben and thanks for providing some real-world examples. I suspect the NBN has actually improved things for a grea...

14 hours ago by braue on NBN FUD: will Abbott ever learn?

Hi Geoff, my opening paragraph simply suggests that the leader of the opposition party would rightfully be turning to his communications ...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

Very good point Richard – perhaps one of the most interesting things about this whole debate is how extensively it feeds the collective...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

Yes. I also wonder how much of this intentional subterfuge is actually playing out as part of Turnbull's master plan. Given the rough ri...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

This story has been voted 12000 times in the last 24 hours!

17 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar