Network World
Saturday, November 22, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Considering Convergence

Navigation

Securing the Line Part 5 - Media Encryption

As discussed earlier, VLANs, ACLs, and firewall policies are extremely important components to any converged network security architecture. However, what these methods do not secure is the content within each call or conversation.

The industry is moving towards securing each media path used for voice, video, and data communication. Even internally, there are many threats that may potentially compromise the content within the packets transmitted over an IP network.

So, if this problem is known and widespread, then why isn't there an industry-standard encryption algorithm or method for securing voice/video media? It isn't so much about "what, or when" it can be done, but more of a "who" (as vendors) will accept it. This is simply turning into a business-case problem.

Especially in the telecom world, the vendors and developers of hardware and software dictate new development and feature releases. Except for open-source platforms such as Asterisk, which utilizes a "pluggable module" architecture, the users of proprietary platforms are locked into what is provided to them.

Given this, and especially in reference to heterogeneous architectures where multiple platforms and vendors are involved, it is best to use VPNs as a way to encrypt media passing from one location to another. Since the encryption method isn't switch or platform centric, proprietary methods can fall by the wayside.

Otherwise, TLS and IPSec (natively, without VPNs) and SRTP are excellent ways of securing media across a LAN. Of course, the platform, endpoints (clients), and any proxies or gateways in between must support the same methods, or you're left with a unsecure media path, or a multi-vendor multi-implementation nightmare.

What are you doing to internally and externally protect and encrypt voice media paths?

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

About Matthew Nickasch

Nickasch has been very involved in IT since he was just 13. His current and previous consulting experience includes systems architecture, virtualization, and converged networks for the financial, education, and healthcare industries. Matthew currently attends the University of Wisconsin-Platteville, where he also works as a network management assistant. While his interests include directory services and routing protocols, Nickasch's focus is on converged networks and voice over IP.

RSS feed XML feed

Nickasch's archive.

The opinions expressed in this Weblog are those of the writer and may not represent the opinions of Network World.

Advertisement: