VoIP net’ protection
NetworkWorld.com, 05/16/06
Yes, more business users are replacing traditional telephone networks with VoIP. But one author warns users need to be aware of the security risks that go hand-in-hand with this change in a recent Network World story.
This is a topic that was brought up earlier this year by another Network World contributor Tom Nolle. For his take check out this opinion piece.
Experts say that many threats to VoIP networks are similar to the “impersonation-based attacks” made against traditional telephone and wireless networks.
The focus of a VoIP attack is often focused on a customer’s endpoints, says author David Piscitello.
Most VoIP gear deployed today is based on the IETF’s SIP and Real-time Transport Protocol (RTP). Piscitello says these technologies “do not provide adequate call-party authentication, end-to-end integrity protection and confidentiality measures.”
For more on threats check out the piece.
One of the first measures a customer should take is to harden their servers, Piscitello says in his piece. Hardening servers typically include:
-Maintaining patch currency for operating system and VoIP applications
-Deploying host intrusion detection
-Install and maintain server firewall, antimalware and antitampering measures to thwart denial of service attacks.
Have you thought about how solid your VoIP security is? If not chances are someone else, outside your company, already knows the answer to that question.
-Denise Pappalardo (denisep@nww.com)
TrackBack
Back to WAN Notes
Comments
Post a comment