RSA: Network security is the key to keeping VoIP secure
Network World -
Despite warnings that VoIP is vulnerable to a new breed of attacks, the biggest threat to it remains weaknesses in general network security, according to a vendor presentation at the RSA Security Conference 2006.
Experts are aware of possible attacks that could be made against VoIP protocols, but worms, viruses and other exploits that take down servers or congest networks in general are the exploits that hurt VoIP in practice, said David Endler, chairman of the VoIP Security Alliance (VoIPSA) and director of security research for 3Com Corp.'s TippingPoint division.
Analysis of IP voice components is key to keeping VoIP networks secure, he said. For instance, some IP PBXs are based on Windows, so any security flaws in Windows are security flaws in the voice network.
Users should check the management platforms of IP voice gear as well, Endler said. For instance, some management uses TFTP protocol, which requires no authentication, so hackers could glean information about the VoIP network that could be valuable in itself or provide information for future attacks, he said.
Some VoIP phones include packet capture features that are useful in tracing packets to analyze network performance. But in the wrong hands a network of phones with this feature could be used to sniff networks for sensitive traffic such as passwords, he said. "This could be problem especially if the phones are connected to a hub," where they could view all traffic passing through.
Logically segmenting VoIP traffic on its own VLAN can help keep it clear of attacks against data traffic, he said.
To protect VoIP networks, Endler recommends:
-- Patching gear regularly against known threats.
-- Changing default passwords on all gear.
-- Following vendors' check lists for securing gear when installed.
-- Using intrusion prevention gear.
-- Using VoIP aware firewalls to protect IP PBXs.
Attacks against VoIP in particular are coming and probably soon, Endler said, but no one can be sure when. One likely form of attack will be fuzzing, the practice of sending malformed packets within VoIP protocols. For example, putting a string of integers in a packet when the protocol expects letters might cause IP PBXs to shut down. Methodical testing of VoIP protocols with such malformed packets at Finland's University of Oulu have already revealed some such vulnerabilities, he said.
Reprinted with permission from
Story copyright 2009 Network World, Inc. All rights reserved.
Additional Resources


White Papers & Webcasts
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
IDC White Paper: CCM for IT Compliance and Risk Management
Learn from industry analysts how IT organizations are using configuration management to meet compliance requirements and instill best practices. Find out how these...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Keep it Clean: Maintaining the Integrity of your CMDB through Change Detection
Learn how configuration drift can challenge configuration management database (CMDB) integrity and how a configuration audit tool and an effective change management process...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
HIPAA requires businesses that handle personal health information (PHI) to set up strong controls to ensure the security and integrity of that information....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Configuration Assessment: Choosing the Right Solution
Configuration assessment lets businesses proactively secure their IT infrastructure and achieve compliance with important industry standards and regulations. Learn why configuration assessment is...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
