Skip Links

Network World

Masters of Unified Communications: Sponsored by Avaya

UC security concerns: VPN is key

Encryption is key to securing communications

By Johna Till Johnson on Mon, 06/29/09 - 7:26am.
Newsletter Signup

Unified communications (UC) adoption is increasing and correspondingly, so too are concerns over security. Sixty percent (60%) of organizations are implementing a UC architecture in 2009, up from 47% in 2008, according to participants in Nemertes UC research.

VoIP continues to be the dominant application in a UC architecture. To date, most security has been the creation of virtual islands: isolating VoIP traffic from the rest of enterprise LAN traffic. But the scope of UC is expanding rapidly to include unified messaging (the integration of e-mail, voice mail and fax), presence, instant messaging, conferencing and social-computing apps (internal blog and wiki apps, Yammer, Facebook, YouTube, Twitter, etc.).

At the same time, the scale of UC also is expanding rapidly as UC connects business partners, customers, mobile workers, and virtual workers; all outside the corporate security boundary, rendering VoIP isolation obsolete.

The bottom-line is UC security also must expand in scope and scale. In this column I'm focusing on issues of scale. Scope will be next week's topic.

Protecting VoIP communications for mobile and virtual workers is one of the greatest challenges. This includes the confidentiality and integrity of the VoIP traffic, but also the protection of availability – something we can assume is table stakes for communications. Anyone plugging into a switch span port may listen to and record VoIP conversations.

Of course, voice snooping is not new (think of tapping the phone lines). Still, telecom and network managers tell us that executives express greater concern over VoIP snooping than analog voice snooping for good reason. The concern is greatest regarding VOIP's susceptibility to eavesdropping on the public Internet: Vulnerability of VoIP is much greater than voice vulnerability on the public switched telephone network (PSTN).

Encryption is the only way to guarantee confidentiality for internal and external VoIP traffic. But the challenge with encryption is, well, everything is encrypted! Recording for archival purposes, scanning for potential wrong-doing and monitoring are all impossible with encrypted VoIP. On the other hand, multiple conversions can negatively affect voice quality; another major concern of corporate executives.

What's needed is encryption outside the firewall and cleartext VoIP inside the firewall. I'll come back to this in a second.

Authentication is the validation that it's really Johna (or someone who has stolen Johna's identity) on the phone. We need at least two out of the three of: Something you have (a valid VoIP phone or computer), something you know (password or PIN) and something you are (biometric). Historically, voice and VoIP authentication has been mostly implicit. If Johna is using Johna's VoIP phone at Johna's desk, it's most likely …. Johna. But, what if Johna is a teleworker, virtual worker or traveling worker? The location is now meaningless and since Johna is out of the office, she's probably using a VoIP softphone, like about 10% of VoIP phone deployments.

The good news is VPNs can address both issues. A VPN agent on the remote PC/laptop will authenticate the user. This may involve authenticating the computer as part of connection establishment or requiring the user to carry a secure token such as an RSA SecurID. Then, the VPN establishes an encrypted tunnel (IPSec or SSL) to protect the confidentiality of the communications. De-encryption occurs at the corporate VPN gateway, alleviating the issues raised above.

Of course, this still leaves us with the challenge of convincing corporate executives that the benefits of unencrypted VoIP and UC traffic on the corporate network outweigh the risks. A topic for another day.

VPN and UC

0

UC over an MPLS network with IP sec VPN tunnnels back into the cloud works just great.
I am a Sprint employee and that is exectly what we are using to great effect.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • You can use BBCode tags in the text.
  • Lines and paragraphs break automatically.
  • Allowed HTML tags: <p> <strong> <i> <br /> <br> <ul> <ol> <li> <dl> <dt> <dd> <blockquote>

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Welcome, visitor. Register Log in
About Masters of Unified Communication

Johna leads the Nemertes team of analysts, who regularly benchmark organizational, technology, and business trends of all sizes of businesses.

The unique methodology includes detailed, structured conversations between Nemertes analysts and IT practitioners. From each conversation, Nemertes gathers about 200 data points, which are entered into SPSS, a statistical database. Analysts then conduct correlation analysis for all sizes of organizations, understanding the differences in technology adoption, spending, and priorities between SMBs and larger enterprises.

Analysts use that research data, combined with real-world experience and knowledge, to advise SMBs and enterprise organizations on their IT strategies with targeted service offerings specifically for each segment.

Finally, Johna and her team have spoken at hundreds of events where they interact with IT practitioners from all sizes of companies. These conversations also provide perspective on the unique challenges facing SMBs, as well as those facing enterprises.

Blog Roll
Andreas's Blog
http://www.nemertes.com/blog/andreas_m_antonopoulos
Irwin Lazar's Real-Time Blog
http://www.irwinlazar.com/
Nemertes
http://www.nemertes.com
Eye on the Carriers
http://www.networkworld.com/columnists/eye.html
VoIP Watch
http://andyabramson.blogs.com/voipwatch/
GigaOM
http://gigaom.com/
Telepocalypse
http://www.telepocalypse.net/
Unified Communications
http://www.realtime-unifiedcommunications.com/
Blue Box: The VoIP Security Podcast
http://www.blueboxpodcast.com/

Resources