Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Six burning VoIP questions

By Phil Hochmuth , Network World , 07/05/2007
  • Share/Email
  • Tweet This
  • Comment
  • Print

Page 5 of 12

3. Is VoIP safe?

VoIP safety is a broad question that touches on many aspects of how IP telephony systems operate, and the various parts of the network VoIP touches, but according to one survey one thing is clear, VoIP technology isn't safe enough for many businesses.

Only half of the IT executives polled recently in a CompTIA study said they think security technology built into corporate VoIP products and services is solid. The survey (of 350 companies with 500 employees or fewer) showed that even wireless technology — often maligned for its security weakness — was held in higher regard than VoIP in terms of security. (Sixty percent of respondents said they trusted security in Wi-Fi gear.)

With VoIP, security concerns among the respondents in the CompTIA survey were not relating just to potential attacks on VoIP gear and software, but the affect a general worm or virus outbreak could have on the quality of IP voice calls. Worms and viruses that flood corporate networks with traffic may cause e-mail delivery to be delayed, slow application response times. But the latency introduced can simply kill an IP telephony conversation.

As for VoIP products, vulnerabilities are popping up more in IP telephony gear and software. Cisco, for instance, over the last 18 months issued nine major vulnerability advisories on products ranging from IP phones and IP PBXs, to routers that perform VoIP processes and functions. These nine warnings — serious enough for the vendor to issue software patches — compares with the two VoIP-related vulnerabilities Cisco had issued in the 18 months prior (July 2005 to January 2006).

Many vendor's IP call processing and messaging products run on top of Linux, Windows, Sun or other server operating systems. Softphones generally run on Windows desktops, while applications such as VoIP-based call center platforms can touch a wide array of other applications. Taking all this into account, Avaya had 25 product security advisories relating either directly to its VoIP products, or affecting underlying software products on which Avaya's technology runs, according to security research Web site Secunia. The Internet Security Systems X-Force vulnerability database has more than 100 entries over the past five years relating to vulnerability reports in VoIP products, applications and underlying protocols.

Some security researchers say the basic technology of some VoIP protocols is by nature hackable or susceptible to denial-of-service or call-interception attacks.

Sheran Gunasekera, a researcher with Scanit, wrote in a report that VoIP call interception can be simple, if targeted against equipment and traffic using non-encrypted, standards-based protocols. Scanit says tests it conducted used standard SIP signaling protocol and Real Time Protocol (RTP) for media transmission.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (11)
Login
Forgot your account info?

RE: Six burning VoIP questionsBy mikeg on July 5, 2007, 3:36 pmWhat do you think about our article?

Reply | Read entire comment

VoIP doesn't provide life line...By Anonymous on July 5, 2007, 4:37 pmWhen the network craps out or there is a massive power outage most of the VoIP implementation leave users without any means of contacting emergency services. Those...

Reply | Read entire comment

VoIP vs TraditionalBy Anonymous on July 6, 2007, 12:33 pmWell not to pick at anyone - VoIP is not the problem - Lack of Planning and Design is the problem. The planning and design go hand in hand with the ability to contact...

Reply | Read entire comment

VoIPBy Bill LePage on July 7, 2007, 7:10 amI agree that if the network is down and/or the power is out to the VoIP system, you will have no service and your users are screwed. BUT, this would be the result...

Reply | Read entire comment

Power failures, network down...who cares?By Bryan Matheny on July 9, 2007, 9:10 pmI agree that it's all about the planning. We have developed our system using Asterisk, and our SMB clients have had NO issues. In fact, they prefer our simple solution:...

Reply | Read entire comment

Not only VoIP, but VoIP & some wired / mobileBy Anonymous on July 10, 2007, 7:53 amIt's true that VoIP doesn't provide life line. Not yet. Or not when poorly designed. Or not as a replacement for ANY other telephony. It is, at least for the moment,...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed